A classic network bridge in Proxmox VE works fine as long as there are only a few networks and one administrator configures them by hand on each node. Once the number of clients or projects grows into the dozens, manually syncing configuration across all nodes becomes a source of mistakes. SDN moves the network description into the cluster configuration database and pushes it to every node automatically.
Why use SDN when bridges already exist
Software-Defined Networking in Proxmox VE adds a layer of abstraction on top of physical interfaces: an administrator describes zones and virtual networks once in the cluster web interface, and Proxmox generates the configuration for every node and applies it through ifreload. This is convenient for a hosting provider handing clients isolated VLANs without logging into every hypervisor over SSH.
What zone types are available in Proxmox VE
| Zone | Isolation | When to use |
|---|---|---|
| Simple | none, shared L3 segment | test setups, a single NAT network |
| VLAN | 802.1Q tagging | splitting a physical network between tenants |
| QinQ | double VLAN tag | a provider with hundreds of isolated clients |
| VXLAN | L2 encapsulation over L3 | a network with no shared switch between nodes |
For most VM hosting scenarios, a VLAN zone is enough — it is easier to troubleshoot than VXLAN and does not require multicast support on switches.
How to create a zone and a VNet
Zones and virtual networks are configured under Datacenter → SDN. The steps are:
- Create a VLAN zone and specify the physical uplink bridge, for example
vmbr0. - Add a VNet with an arbitrary name and a VLAN tag number, for example 120.
- Apply the changes with the Apply button — the configuration is pushed to every cluster node.
- Attach the VNet to the network interface of the target virtual machine instead of the regular bridge.
After applying, the configuration shows up in /etc/pve/sdn/vnets.cfg and in ip link output on every node as a separate VLAN interface on top of the uplink.
Configuring the VLAN trunk on the physical switch
On the switch side, the port connected to the Proxmox VE node must be set to trunk mode with the VLAN IDs used in the SDN zone allowed. If the switch only passes an access port, a VNet with a tag simply will not receive traffic — this is the most common reason a network "does not work" after setting up SDN.
ip link show vmbr0.120
bridge vlan show
The bridge vlan show command confirms that the required VLAN ID is actually up on the bridge interface of a given node.
How to check connectivity between virtual machines
After connecting two VMs to the same VNet, check connectivity with a plain ping and look at the ARP table on each side:
ping -c 4 10.20.0.2
ip neigh show
If the ping fails while the interfaces are up, check that the VLAN ID matches between the SDN zone and the switch port, and check the Proxmox VE firewall rules at the node and virtual machine level — it can block traffic between networks by default.
SDN and the cluster: what matters across nodes
SDN configuration is stored in the shared /etc/pve database and is identical across every node of the Proxmox VE cluster, but the physical uplink interface must have the same name on every node — otherwise applying the zone fails on nodes with a different bridge name. Before migrating a VM between nodes, make sure the VNet exists and is active on both.
Checklist for SDN rollout
- The zone and VNet are created, and the configuration applied without errors on every node.
- The switch port is set to trunk mode with the required VLAN IDs.
- Connectivity between VMs on the same VNet is confirmed with a ping and the ARP table.
- Firewall rules do not block traffic inside the new network without a real reason.