Proxmox VE is an open source virtualization platform that runs KVM virtual machines and LXC containers side by side, managed from a web interface on port 8006. Proxmox VE 9 is based on Debian 13 (Trixie), so besides the official ISO you can install it on top of an existing Debian 13 system, which is the usual approach on a dedicated server delivered with Debian. In this tutorial you will turn a Debian 13 server into a Proxmox VE 9 host, configure the package repositories, create a private NAT network for guests, and launch your first container and virtual machine.
Prerequisites
To follow this guide you need:
- A dedicated (bare-metal) server with a 64-bit CPU that supports hardware virtualization (Intel VT-x or AMD-V), for example a CubePath bare-metal server. A regular VPS only works if nested virtualization is enabled, and guest performance is limited.
- A minimal installation of Debian 13 (Trixie) amd64 with a static public IP. Do not install a desktop environment.
- At least 8 GB of RAM and enough disk for your guests.
- Root access, or a user who can become root with
sudo -i. Proxmox is administered asroot, so the commands in this guide are shown withoutsudo. - Access to an out-of-band console (IPMI, iDRAC or a KVM console). You will change the network configuration and reboot, and a mistake can cut SSH access.
Check that the CPU exposes virtualization extensions. Any number greater than zero is fine:
grep -cE 'vmx|svm' /proc/cpuinfo
32
Step 1 - Making the hostname resolve to the public IP
Proxmox requires that the node's hostname resolves to its main IP address, not to 127.0.1.1 as Debian sets by default. Find your IP and interface name:
ip -br addr
lo UNKNOWN 127.0.0.1/8 ::1/128
eno1 UP 203.0.113.10/24
Edit /etc/hosts. Replace 203.0.113.10 with your server's IP and pve1.your_domain with your hostname:
nano /etc/hosts
127.0.0.1 localhost
203.0.113.10 pve1.your_domain pve1
::1 localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters
Verify that the hostname now returns the public IP:
hostname --ip-address
203.0.113.10
Step 2 - Adding the Proxmox VE repository
Add the Proxmox VE pve-no-subscription repository in deb822 format. It is free to use and receives the same packages as the enterprise repository, only after a longer testing period:
cat > /etc/apt/sources.list.d/pve-install-repo.sources << EOF
Types: deb
URIs: http://download.proxmox.com/debian/pve
Suites: trixie
Components: pve-no-subscription
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg
EOF
Download the Proxmox archive key:
wget https://enterprise.proxmox.com/debian/proxmox-archive-keyring-trixie.gpg -O /usr/share/keyrings/proxmox-archive-keyring.gpg
Verify its checksum before trusting it:
sha256sum /usr/share/keyrings/proxmox-archive-keyring.gpg
136673be77aba35dcce385b28737689ad64fd785a797e57897589aed08db6e45 /usr/share/keyrings/proxmox-archive-keyring.gpg
If the hash is different, stop and compare it with the value published on the Proxmox wiki page "Install Proxmox VE on Debian 13 Trixie".
Refresh the package lists and upgrade the system:
apt update && apt full-upgrade
Step 3 - Installing the Proxmox kernel
Proxmox VE ships its own kernel with the features KVM, LXC and ZFS need. Install it first and reboot into it:
apt install proxmox-default-kernel
systemctl reboot
After the reboot, confirm that the running kernel ends in -pve:
uname -r
6.14.11-2-pve
The version on your system will be newer; what matters is the -pve suffix.
Step 4 - Installing the Proxmox VE packages
Install Proxmox VE together with Postfix (used to send system notifications), open-iscsi and chrony:
apt install proxmox-ve postfix open-iscsi chrony
When the Postfix configuration dialog appears, choose Local only unless you have a mail relay, and keep the suggested system mail name.
Remove the Debian kernel so that future updates do not boot the wrong one, then regenerate the GRUB configuration:
apt remove linux-image-amd64 'linux-image-6.12*'
update-grub
Also remove os-prober, which would otherwise add the disks of your virtual machines to the boot menu:
apt remove os-prober
Check that the Proxmox services are running:
systemctl status pveproxy --no-pager
pveversion
● pveproxy.service - PVE API Proxy Server
Active: active (running) since Thu 2026-09-25 12:21:04 UTC; 1min ago
pve-manager/9.0.10/deb1ca707ec72a89 (running kernel: 6.14.11-2-pve)
Step 5 - Logging in and configuring the repositories
Open https://your_server_ip:8006 in your browser and accept the self-signed certificate warning. Log in as root with the Linux PAM standard authentication realm and the root password of the server. A dialog warns that you have no valid subscription; you can close it.
Installing proxmox-ve added the enterprise repositories, which return 401 Unauthorized without a subscription. Fix the repository list from the web interface:
- Select your node, then Updates > Repositories.
- Select each entry that uses the
enterprise.proxmox.comURL (PVE and Ceph) and click Disable. - Click Add, choose No-Subscription and confirm. The web interface writes this entry to its own repository file.
The pve-no-subscription entry from Step 2 is now listed twice. Remove the installation file so only the entry managed by the web interface remains:
rm /etc/apt/sources.list.d/pve-install-repo.sources
Confirm that updates work without errors:
apt update
Hit:1 http://deb.debian.org/debian trixie InRelease
Hit:2 http://download.proxmox.com/debian/pve trixie InRelease
Reading package lists... Done
Step 6 - Configuring the network bridges
Guests connect to the network through Linux bridges. You will create two:
vmbr0: a bridge on the physical interface that carries the server's public IP. Guests attached to it need additional public IPs routed to your server.vmbr1: a private bridge with NAT, so guests with private addresses can reach the Internet through the host's single public IP.
This configuration assumes the classic /etc/network/interfaces file, which Proxmox manages with ifupdown2. Back it up first:
cp /etc/network/interfaces /etc/network/interfaces.bak
nano /etc/network/interfaces
Replace its content with the following, using your interface name, IP and gateway:
auto lo
iface lo inet loopback
iface eno1 inet manual
auto vmbr0
iface vmbr0 inet static
address 203.0.113.10/24
gateway 203.0.113.1
bridge-ports eno1
bridge-stp off
bridge-fd 0
auto vmbr1
iface vmbr1 inet static
address 10.10.10.1/24
bridge-ports none
bridge-stp off
bridge-fd 0
post-up echo 1 > /proc/sys/net/ipv4/ip_forward
post-up iptables -t nat -A POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE
post-down iptables -t nat -D POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE
Apply the configuration. Run this from the out-of-band console if possible, because SSH drops for a moment and does not come back if there is a typo:
ifreload -a
Verify both bridges and the NAT rule:
ip -br addr show vmbr0
ip -br addr show vmbr1
iptables -t nat -S POSTROUTING
vmbr0 UP 203.0.113.10/24
vmbr1 UNKNOWN 10.10.10.1/24
-P POSTROUTING ACCEPT
-A POSTROUTING -s 10.10.10.0/24 -o vmbr0 -j MASQUERADE
vmbr1 shows UNKNOWN until a guest is attached to it.
Step 7 - Enabling guest disks on the local storage
On an installation on top of Debian there is usually no LVM-thin pool, only the directory storage local in /var/lib/vz. Check which content types it accepts:
pvesm status
cat /etc/pve/storage.cfg
If the local entry does not include images and rootdir, allow virtual machine disks and container volumes on it:
pvesm set local --content iso,vztmpl,backup,images,rootdir
For production, a dedicated ZFS pool or LVM-thin volume on separate disks performs better and supports efficient snapshots. You can add one later under Datacenter > Storage.
Step 8 - Creating an LXC container
Containers share the host kernel and start in seconds, which makes them ideal for Linux services. Update the list of official templates and look for the latest Debian 13 template:
pveam update
pveam available --section system | grep debian-13
system debian-13-standard_13.1-2_amd64.tar.zst
Download it, using the exact name from your output:
pveam download local debian-13-standard_13.1-2_amd64.tar.zst
Create an unprivileged container with ID 101 on the NAT network. The command copies root's SSH public keys into the container so you do not need a password:
pct create 101 local:vztmpl/debian-13-standard_13.1-2_amd64.tar.zst \
--hostname ct101 \
--cores 1 --memory 1024 --swap 512 \
--rootfs local:8 \
--net0 name=eth0,bridge=vmbr1,ip=10.10.10.101/24,gw=10.10.10.1 \
--nameserver 1.1.1.1 \
--unprivileged 1 \
--ssh-public-keys /root/.ssh/authorized_keys
Start it and test its Internet access from inside:
pct start 101
pct exec 101 -- ping -c 3 debian.org
3 packets transmitted, 3 received, 0% packet loss, time 2003ms
Open a shell in the container with pct enter 101, and leave it with exit.
Step 9 - Creating a virtual machine
Virtual machines run their own kernel, so use them for other operating systems or workloads that need full isolation. Create one from the web interface:
- Select the
localstorage, then ISO Images > Download from URL. Paste the URL of the Ubuntu 24.04 server ISO fromubuntu.com/download/serverand click Query URL, then Download. - Click Create VM at the top right. Give it an ID (for example
102) and a name. - OS: select the ISO you just downloaded.
- System: keep the defaults and tick Qemu Agent.
- Disks: bus
SCSI, storagelocal, size 32 GB. Tick Discard if the underlying disks are SSDs. - CPU: 2 cores, type
hostif this VM will never be migrated to a node with a different CPU. - Memory: 2048 MB.
- Network: bridge
vmbr1, modelVirtIO (paravirtualized). - Confirm and start the VM, then open Console to run the Ubuntu installer. Give it a static address in
10.10.10.0/24, gateway10.10.10.1.
After installation, install the guest agent inside the VM so Proxmox can show its IP address and shut it down cleanly:
sudo apt install qemu-guest-agent
sudo systemctl start qemu-guest-agent
On the host, check that the agent responds:
qm agent 102 ping && echo "agent OK"
agent OK
Step 10 - Securing the web interface
Port 8006 gives full control of the host, so protect it:
- Enable two-factor authentication for
rootunder Datacenter > Permissions > Two Factor (TOTP). - Create a personal administrator account in the
Proxmox VE authentication serverrealm under Datacenter > Permissions > Users instead of sharing the root login. - Limit access to port 8006 to your own IP addresses. You can do this with the built-in firewall under Datacenter > Firewall: add rules that accept
8006and22from your IPs before enabling the firewall in Datacenter > Firewall > Options, or you will lock yourself out.
Step 11 - Joining more nodes into a cluster (optional)
A Proxmox cluster lets you manage several hosts from one interface and migrate guests between them. Use at least three nodes so the cluster keeps quorum when one fails, and connect them with a low-latency network. Every node must run the same Proxmox VE version, have a unique hostname and have no guests before joining.
On the first node, create the cluster:
pvecm create my-cluster
On each additional node, join it using the IP address of the first node. You are asked for the first node's root password:
pvecm add 203.0.113.10
Check the result on any node:
pvecm status
Votequorum information
----------------------
Expected votes: 3
Total votes: 3
Quorum: 2
Flags: Quorate
Troubleshooting
apt updatereturns401 Unauthorized: an enterprise repository is still enabled. Disable it under Updates > Repositories as in Step 5.pve-clusterfails to start after installation: the hostname does not resolve to the server's IP. Fix/etc/hostsas in Step 1 and runsystemctl restart pve-cluster pveproxy.- No network after
ifreload -a: log in through the out-of-band console, restore the backup withcp /etc/network/interfaces.bak /etc/network/interfacesand runifreload -aagain, then check the interface name and gateway. - "KVM virtualisation configured, but not available" when starting a VM: virtualization is disabled in the BIOS/UEFI, or the server is a VPS without nested virtualization.
Conclusion
You installed Proxmox VE 9 on Debian 13, switched to the no-subscription repository, created a NAT network for guests and launched both an LXC container and a KVM virtual machine. Next, configure scheduled backups under Datacenter > Backup (ideally to a Proxmox Backup Server), add a ZFS or LVM-thin storage for better disk performance, and replace the self-signed certificate under System > Certificates with a Let's Encrypt one using the built-in ACME client.
