New Home/New Network/New Proxmox?

::Place Holder:: Will attempt to update this with newer info as it comes up

1.) Proxmox V7.1 working on MSI B550 Mortar with Realtek 2.5G nic, and 3900xt (try to keep this one up-to-date with noticed changes to New Proxmox version (there are a few of note and I just started.))
Proxmox is using kernel 5.13 and ZFS 2.1.1 with new “dRAID” Vdev’s for large scale storage. (refrence: OpenZFS 2.1 is out—let’s talk about its brand-new dRAID vdevs | Ars Technica)

List of current packages with Proxmox base

2.) Windows 11- So far Rufus and Etcher non-functional, not impressed with changes so far… :confused: Also requires opting in with windows insider, and have to share metrics with Microsoft boo. :-1:

3.) New storage / cold storage scheme (same cloud/fire safe redundancies)

4.) Firewall and securing Proxmox via obscurity and other protections

5.) Automation and script learning

-probably more as I get settled

-I’m already looking at a non wireless router that would be good to use… if anyone has any suggestions…scratch that I’m planning on using OPNsense which I belive I can use as a router for the home.


Just use MS’s own media creation tool. Nothing beats that IMO. The only downside is that you have to download the image multiple times and the tool is so stupid that it doesn’t know how to use a cache, or at least ask you to point to an image if you already downloaded it and maybe check for a hash (if it’s really the same image as provided by MS or if it has been corrupted or tampered).

Yeah, windows 11 is up and running, just had to do the update. Running on a test pc now with 4650g apu… but neither tool is allowing me to make a usb for installing proxmox was the big hang up. Had to use another machine to do that. Just had to pull a pc up and get it running was all. Not sure why neither tool would complete successfully making a bootable usb image.

@HaaStyleCat you finally get your living situation figured out?


That’s the hope… as long as we hear back from the VA on approval of the loan we should be moved by the end of next week. And settling in hopefully by the new year completely :pray:… baring nothing unforseen in the deal going south… we may have to get an extension on closing if we don’t hear back soon. Wife’s freaking out about it, but I’m sure it’ll be fine.


Well I have set up Proxmox 7.1 successfully on the MSI B550 Mortar ,Ryzen 9 3900XT, 32GB 3200 Ripjaws, 2.5G realtech NIC (Only working at 1G now till I can test on a 10G switch at the new home) and MSI GamingX GTX 1650 Super.

Everything worked correctly setting up plex in a LXC container and then passing through the GTX 1650 Super as with previous version 6 of Proxmox with one MAJOR caveat… In the LXC config where you add the lines

lxc.cgroup.devices.allow: c 195:* rwm
lxc.cgroup.devices.allow: c 508:* rwm
lxc.mount.entry: /dev/nvidia1 dev/nvidia1 none bind,optional,create=file
lxc.mount.entry: /dev/nvidiactl dev/nvidiactl none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-uvm dev/nvidia-uvm none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-modeset dev/nvidia-modeset none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-uvm-tools dev/nvidia-uvm-tools none bind,optional,create=file

If you try to use this you get and error attempting to run nvidia-smi and it wont pick up transcode jobs on promoxs’ cli nvidia-smi. The coding for cgroup changed as I belive they are using a newer version from what I have read. IT HAS NOW CHANGED TO cgroup2!!!

The code above would look as follows when changed… you litterally need to add a 2 is all to lines with cgroup to cgroup2

lxc.cgroup2.devices.allow: c 195:* rwm
lxc.cgroup2.devices.allow: c 508:* rwm
lxc.mount.entry: /dev/nvidia1 dev/nvidia1 none bind,optional,create=file
lxc.mount.entry: /dev/nvidiactl dev/nvidiactl none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-uvm dev/nvidia-uvm none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-modeset dev/nvidia-modeset none bind,optional,create=file
lxc.mount.entry: /dev/nvidia-uvm-tools dev/nvidia-uvm-tools none bind,optional,create=file

Of course the numbers may change depending on where things are located in your system and how they are tagged by your system.

Just thought I should pass this along for anyone considering the switch to Proxmox 7. I have the all the steps documented and may publish them here for a GPU pass thru to LXC container if people need it.


Ran into another issue with Windows 11 and dual boot. I cant remember if bitlocker was needed or I tried it for the heck of it… but dual booting with bitlocker on the main drive I had to use the windows recovery code to boot windows after running my linux partition. Im going to see if I can disable bitlocker see if its still an issue and report back.

Yeah it wasn’t required, was just me being interested to try features.

Considering the Silverstone CS330 as a NAS replacement/possibly second Proxmox node or backup node.

I think the Dell T320 (converted to T420 dual CPU) may be too much for me. Don’t think I need dual power supplies redundant CPU’s etc… I may have gone a little overboard lol. If I get it up and running I may want to offer its processing power to a Linux project or other community project if I can find a good one to support.

Work in progress…

So here I will have two separate WiFi mesh systems (I found one while moving in my “tech pile”), one for my known devices with slightly different firewall rules, and one guest/IoT untrusted network as @ThatGuyB suggested.

I have two managed switches. So the hope was to send one cable between them and have the switch interpret the different VLANs and port destinations??? Is this how it works or am I wrong?

I hope this is somewhat what @ThatGuyB suggested in the thread Easy to follow Small Secured (dual stack) Network Firewall

I should be able to adjust signals and bands so they don’t interfere with each other (I may have to ask @PhaseLockedLoop as that is your wheelhouse from what I have seen when you dive into routers and AP’s [Access Points]). One is a AX wifi 6 and the other is only wifi 5. If all goes well I should be able to use wired backhaul on the wifi 6 router/AP to keep the speed up.

I should be able to keep mesh utility on both devices turning them over to AP mode, BUT I will have to see if the ethernet ports are still active or if I need a dumb switch at locations that need more connectivity such as livingroom, wifes office, etc.

I suggest you keep a separate guest and IoT / untrusted net, just my $0.02. Well, I have autism with regards to IoT and to guests, but I wouldn’t want them to infect each other with ransomeware or Chinese malware either, lol.

Guests can stay on a network with QoS (lower bandwidth allocation) and IoT in a network that has no access to the Internet, so Google and Samsung and whoever else can eat a d*** and not gather data (unless obviously they need internet to work in the first place, I wouldn’t be buying such devices though, but I guess something like an Alexa would stay on a guest network, rather than in untrusted with no internet access).

1 Like

I’m running dual boot Windows 11 Bitlocker and Ubuntu LUKS with Secure Boot enabled without any issues. But you’ll always get the recovery prompt if selecting Windows from grub. You’ll need to use your motherboard’s boot select menu for Bitlocker to work properly.

@SgtAwesomesauce gotta hats off the HaaStyle for his network diagramn. Thats awesome and easy to read. Did they teach you flow charts in the Gov Hass?

Sanity checks are easiest when you are forced to enter the information or write it down by hand. Definitely recommend the route just think it out. Consider the pros and cons of how you do stuff. Try to find the best mix of security and ease of maintenance or you will end up like me

Public DNS

forgets about DDos Mitigation

Spends regular parts of the week on audit and mitigation. Things you dont initially think about you know?

We will talk about that in a moment. For now whats your AP plan. Where are they being placed? How large is the coverage area. Any large interfers in the area? Do you live near an airport or military airbase? (DFS purposes). Do you have large chunks of metal in the house or foil back insulation that may hinder some rooms. (Usually this question isnt necessary because people dont mind running like 3 APs but I dont think you want to do so {and you dont need to})


@ThatGuyB yeah I’ll probably have a guest net. I’m don’t have autism (diagnosed) but I can be a bit picky till somethings perfect and I hate changes to my routine lol

@PhaseLockedLoop No, I was a mechanic for years and read a ton of tech manuals with wire diagrams so I used that knowledge, and I looked at a few on-line and then mashed it together on I try to do what makes sense. Doing visuals like this is fun for me. I may change some categories on the diffrent devices depending on what info is most useful to have.

Eventually I’ll have all the interfaces, IP addresses, and map out virtual end as well so I have a full grasp of my infrastructure and can implement MAC filtering like on my IoT net to limit access. I dunno if that’s worth while, but I’d be willing to put in the effort on such a small network if only to make it more agravating to attempt to penatrate my networks.

Eventually (way down the line) I’ll attempt pen testing.

@PhaseLockedLoop the AP’s should be totally fine. Only covering a 2700 sqft area. Placement should be easy. I have 3 AX tri-band nodes for wifi 6 and personal network (AX6100), and 2 of the Linksys Velop Mesh AC nodes dual band for IoT. They should both use wired backhaul.

Shouldn’t have any major interference near me. Airport, but its a ways off…nothing really out by us besides neighbors. I just know I can do a net scan for busyness on certain frequencies and set each network to use less populated one (probably more work than needed, but its fun to do).

Roger, probably what I did erroneously. I may mess with it again later. Thanks for the info though :slight_smile:

1 Like

the airport question was just for me to assess if the channels you should sit on are DFS or not is all. In which case the answer is yes you can sit on them but the tx power will be limited so test and see if thats an issue. (you have a radar nearby)

Or you can stay outside of those on 80 MHz lowers and uppers

A lot of people come to me and say reee my range is shit and im like what channel and they tell me one of the DFS channels and im like do you live near an airport and they are like yup some intl or regional and im like that why


So DFS channels are restricted / disuaded allowed near airports?

DFS channels transmit at a max of 250 mw. (23 dBm) If the router detects any call signs of radars or the type of signalling power will be reduced even further or the channels will hop around frequently (if on auto)


