Proxmox VE is an open source virtualization platform that runs KVM virtual machines and LXC containers side by side, managed from a web interface on port 8006. Proxmox VE 9 is based on Debian 13 (Trixie), so besides the official ISO you can install it on top of an existing Debian 13 system, which is the usual approach on a dedicated server delivered with Debian. In this tutorial you will turn a Debian 13 server into a Proxmox VE 9 host, configure the package repositories, create a private NAT network for guests, and launch your first container and virtual machine.

Prerequisites

To follow this guide you need:

  • A dedicated (bare-metal) server with a 64-bit CPU that supports hardware virtualization (Intel VT-x or AMD-V), for example a CubePath bare-metal server. A regular VPS only works if nested virtualization is enabled, and guest performance is limited.
  • A minimal installation of Debian 13 (Trixie) amd64 with a static public IP. Do not install a desktop environment.
  • At least 8 GB of RAM and enough disk for your guests.
  • Root access, or a user who can become root with sudo -i. Proxmox is administered as root, so the commands in this guide are shown without sudo.
  • Access to an out-of-band console (IPMI, iDRAC or a KVM console). You will change the network configuration and reboot, and a mistake can cut SSH access.

Check that the CPU exposes virtualization extensions. Any number greater than zero is fine:

grep -cE 'vmx|svm' /proc/cpuinfo
32

Step 1 - Making the hostname resolve to the public IP

Proxmox requires that the node's hostname resolves to its main IP address, not to 127.0.1.1 as Debian sets by default. Find your IP and interface name:

ip -br addr
lo               UNKNOWN        127.0.0.1/8 ::1/128
eno1             UP             203.0.113.10/24

Edit /etc/hosts. Replace 203.0.113.10 with your server's IP and pve1.your_domain with your hostname:

nano /etc/hosts
127.0.0.1       localhost
203.0.113.10    pve1.your_domain pve1

::1     localhost ip6-localhost ip6-loopback
ff02::1 ip6-allnodes
ff02::2 ip6-allrouters

Verify that the hostname now returns the public IP:

hostname --ip-address
203.0.113.10

Step 2 - Adding the Proxmox VE repository

Add the Proxmox VE pve-no-subscription repository in deb822 format. It is free to use and receives the same packages as the enterprise repository, only after a longer testing period:

cat > /etc/apt/sources.list.d/pve-install-repo.sources << EOF
Types: deb
URIs: http://download.proxmox.com/debian/pve
Suites: trixie
Components: pve-no-subscription
Signed-By: /usr/share/keyrings/proxmox-archive-keyring.gpg
EOF

Download the Proxmox archive key:

wget https://enterprise.proxmox.com/debian/proxmox-archive-keyring-trixie.gpg -O /usr/share/keyrings/proxmox-archive-keyring.gpg

Verify its checksum before trusting it:

sha256sum /usr/share/keyrings/proxmox-archive-keyring.gpg
136673be77aba35dcce385b28737689ad64fd785a797e57897589aed08db6e45  /usr/share/keyrings/proxmox-archive-keyring.gpg

If the hash is different, stop and compare it with the value published on the Proxmox wiki page "Install Proxmox VE on Debian 13 Trixie".

Refresh the package lists and upgrade the system:

apt update && apt full-upgrade

Step 3 - Installing the Proxmox kernel

Proxmox VE ships its own kernel with the features KVM, LXC and ZFS need. Install it first and reboot into it:

apt install proxmox-default-kernel
systemctl reboot

After the reboot, confirm that the running kernel ends in -pve:

uname -r
6.14.11-2-pve

The version on your system will be newer; what matters is the -pve suffix.

Step 4 - Installing the Proxmox VE packages

Install Proxmox VE together with Postfix (used to send system notifications), open-iscsi and chrony:

apt install proxmox-ve postfix open-iscsi chrony

When the Postfix configuration dialog appears, choose Local only unless you have a mail relay, and keep the suggested system mail name.

Remove the Debian kernel so that future updates do not boot the wrong one, then regenerate the GRUB configuration:

apt remove linux-image-amd64 'linux-image-6.12*'
update-grub

Also remove os-prober, which would otherwise add the disks of your virtual machines to the boot menu:

apt remove os-prober

Check that the Proxmox services are running:

systemctl status pveproxy --no-pager
pveversion
● pveproxy.service - PVE API Proxy Server
     Active: active (running) since Thu 2026-09-25 12:21:04 UTC; 1min ago
pve-manager/9.0.10/deb1ca707ec72a89 (running kernel: 6.14.11-2-pve)

Step 5 - Logging in and configuring the repositories

Open https://your_server_ip:8006 in your browser and accept the self-signed certificate warning. Log in as root with the Linux PAM standard authentication realm and the root password of the server. A dialog warns that you have no valid subscription; you can close it.

Installing proxmox-ve added the enterprise repositories, which return 401 Unauthorized without a subscription. Fix the repository list from the web interface:

  1. Select your node, then Updates > Repositories.
  2. Select each entry that uses the enterprise.proxmox.com URL (PVE and Ceph) and click Disable.
  3. Click Add, choose No-Subscription and confirm. The web interface writes this entry to its own repository file.

The pve-no-subscription entry from Step 2 is now listed twice. Remove the installation file so only the entry managed by the web interface remains:

rm /etc/apt/sources.list.d/pve-install-repo.sources

Confirm that updates work without errors:

apt update
Hit:1 http://deb.debian.org/debian trixie InRelease
Hit:2 http://download.proxmox.com/debian/pve trixie InRelease
Reading package lists... Done

Step 6 - Configuring the network bridges

Guests connect to the network through Linux bridges. You will create two:

  • vmbr0: a bridge on the physical interface that carries the server's public IP. Guests attached to it need additional public IPs routed to your server.
  • vmbr1: a private bridge with NAT, so guests with private addresses can reach the Internet through the host's single public IP.

This configuration assumes the classic /etc/network/interfaces file, which Proxmox manages with ifupdown2. Back it up first:

cp /etc/network/interfaces /etc/network/interfaces.bak
nano /etc/network/interfaces

Replace its content with the following, using your interface name, IP and gateway:

auto lo
iface lo inet loopback

iface eno1 inet manual

auto vmbr0
iface vmbr0 inet static
    address 203.0.113.10/24
    gateway 203.0.113.1
    bridge-ports eno1
    bridge-stp off
    bridge-fd 0

auto vmbr1
iface vmbr1 inet static
    address 10.10.10.1/24
    bridge-ports none
    bridge-stp off
    bridge-fd 0
    post-up   echo 1 > /proc/sys/net/ipv4/ip_forward
    post-up   iptables -t nat -A POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE
    post-down iptables -t nat -D POSTROUTING -s '10.10.10.0/24' -o vmbr0 -j MASQUERADE

Apply the configuration. Run this from the out-of-band console if possible, because SSH drops for a moment and does not come back if there is a typo:

ifreload -a

Verify both bridges and the NAT rule:

ip -br addr show vmbr0
ip -br addr show vmbr1
iptables -t nat -S POSTROUTING
vmbr0            UP             203.0.113.10/24
vmbr1            UNKNOWN        10.10.10.1/24
-P POSTROUTING ACCEPT
-A POSTROUTING -s 10.10.10.0/24 -o vmbr0 -j MASQUERADE

vmbr1 shows UNKNOWN until a guest is attached to it.

Step 7 - Enabling guest disks on the local storage

On an installation on top of Debian there is usually no LVM-thin pool, only the directory storage local in /var/lib/vz. Check which content types it accepts:

pvesm status
cat /etc/pve/storage.cfg

If the local entry does not include images and rootdir, allow virtual machine disks and container volumes on it:

pvesm set local --content iso,vztmpl,backup,images,rootdir

For production, a dedicated ZFS pool or LVM-thin volume on separate disks performs better and supports efficient snapshots. You can add one later under Datacenter > Storage.

Step 8 - Creating an LXC container

Containers share the host kernel and start in seconds, which makes them ideal for Linux services. Update the list of official templates and look for the latest Debian 13 template:

pveam update
pveam available --section system | grep debian-13
system          debian-13-standard_13.1-2_amd64.tar.zst

Download it, using the exact name from your output:

pveam download local debian-13-standard_13.1-2_amd64.tar.zst

Create an unprivileged container with ID 101 on the NAT network. The command copies root's SSH public keys into the container so you do not need a password:

pct create 101 local:vztmpl/debian-13-standard_13.1-2_amd64.tar.zst \
  --hostname ct101 \
  --cores 1 --memory 1024 --swap 512 \
  --rootfs local:8 \
  --net0 name=eth0,bridge=vmbr1,ip=10.10.10.101/24,gw=10.10.10.1 \
  --nameserver 1.1.1.1 \
  --unprivileged 1 \
  --ssh-public-keys /root/.ssh/authorized_keys

Start it and test its Internet access from inside:

pct start 101
pct exec 101 -- ping -c 3 debian.org
3 packets transmitted, 3 received, 0% packet loss, time 2003ms

Open a shell in the container with pct enter 101, and leave it with exit.

Step 9 - Creating a virtual machine

Virtual machines run their own kernel, so use them for other operating systems or workloads that need full isolation. Create one from the web interface:

  1. Select the local storage, then ISO Images > Download from URL. Paste the URL of the Ubuntu 24.04 server ISO from ubuntu.com/download/server and click Query URL, then Download.
  2. Click Create VM at the top right. Give it an ID (for example 102) and a name.
  3. OS: select the ISO you just downloaded.
  4. System: keep the defaults and tick Qemu Agent.
  5. Disks: bus SCSI, storage local, size 32 GB. Tick Discard if the underlying disks are SSDs.
  6. CPU: 2 cores, type host if this VM will never be migrated to a node with a different CPU.
  7. Memory: 2048 MB.
  8. Network: bridge vmbr1, model VirtIO (paravirtualized).
  9. Confirm and start the VM, then open Console to run the Ubuntu installer. Give it a static address in 10.10.10.0/24, gateway 10.10.10.1.

After installation, install the guest agent inside the VM so Proxmox can show its IP address and shut it down cleanly:

sudo apt install qemu-guest-agent
sudo systemctl start qemu-guest-agent

On the host, check that the agent responds:

qm agent 102 ping && echo "agent OK"
agent OK

Step 10 - Securing the web interface

Port 8006 gives full control of the host, so protect it:

  • Enable two-factor authentication for root under Datacenter > Permissions > Two Factor (TOTP).
  • Create a personal administrator account in the Proxmox VE authentication server realm under Datacenter > Permissions > Users instead of sharing the root login.
  • Limit access to port 8006 to your own IP addresses. You can do this with the built-in firewall under Datacenter > Firewall: add rules that accept 8006 and 22 from your IPs before enabling the firewall in Datacenter > Firewall > Options, or you will lock yourself out.

Step 11 - Joining more nodes into a cluster (optional)

A Proxmox cluster lets you manage several hosts from one interface and migrate guests between them. Use at least three nodes so the cluster keeps quorum when one fails, and connect them with a low-latency network. Every node must run the same Proxmox VE version, have a unique hostname and have no guests before joining.

On the first node, create the cluster:

pvecm create my-cluster

On each additional node, join it using the IP address of the first node. You are asked for the first node's root password:

pvecm add 203.0.113.10

Check the result on any node:

pvecm status
Votequorum information
----------------------
Expected votes:   3
Total votes:      3
Quorum:           2
Flags:            Quorate

Troubleshooting

  • apt update returns 401 Unauthorized: an enterprise repository is still enabled. Disable it under Updates > Repositories as in Step 5.
  • pve-cluster fails to start after installation: the hostname does not resolve to the server's IP. Fix /etc/hosts as in Step 1 and run systemctl restart pve-cluster pveproxy.
  • No network after ifreload -a: log in through the out-of-band console, restore the backup with cp /etc/network/interfaces.bak /etc/network/interfaces and run ifreload -a again, then check the interface name and gateway.
  • "KVM virtualisation configured, but not available" when starting a VM: virtualization is disabled in the BIOS/UEFI, or the server is a VPS without nested virtualization.

Conclusion

You installed Proxmox VE 9 on Debian 13, switched to the no-subscription repository, created a NAT network for guests and launched both an LXC container and a KVM virtual machine. Next, configure scheduled backups under Datacenter > Backup (ideally to a Proxmox Backup Server), add a ZFS or LVM-thin storage for better disk performance, and replace the self-signed certificate under System > Certificates with a Let's Encrypt one using the built-in ACME client.