
In Progress
Posted
Paid on delivery
I already have a Proxmox cluster running and the SDN feature enabled; what I do not have is the routing magic that ties several internal subnets together and hands them off cleanly to my external software firewall. Here is the core of what I need: • My routing protocol of choice is BGP, and I want every SDN-defined subnet announced through it. • Inside Proxmox I rely on Virtual Switches, VRFs and Security Groups. Each element must be configured so that traffic stays segregated yet routable as required. • The end result has to pass traffic end-to-end: VM ↔ virtual switch ↔ VRF ↔ BGP ↔ software firewall, with no asymmetric routes or hair-pinning. Acceptance criteria 1. All internal subnets are visible on the firewall via BGP and can reach the internet and each other according to the Security Group rules. 2. A concise set of CLI commands and/or configuration snippets is provided so I can reproduce the setup on additional nodes. 3. A quick test plan (ping / traceroute / iptables counters) demonstrates that failover and route updates behave as expected. This is a surgical assignment for someone who already lives and breathes Proxmox SDN and dynamic routing; I will be able to spot shortcuts right away. If you are confident you can hand over a rock-solid, documented configuration that meets the above checkpoints, let’s get it done. what is given: 1 edge firewall (installed on a standalone server with proxmox), proxmox cluster with 4 nodes. your task is: check the current network config if everything is correct configured (on network level), setup sdn with 3 vnets and subnets (its already setuped and vms from the same subnetn can ping each other) , get the external traffic routet to the firewall opnsense on the standalone server. publish 2 services to extern, forward dns, ntp traffic to infra zone. the current config: 1 Standalone Proxmox server with OPNSense and a proxmox cluster with 4 Nodes. an configured SDN (the vms talking to each other inside the own zone), 3 zones: infra, zone1 and zone 2.
Project ID: 40481703
27 proposals
Remote project
Active 5 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs

As an expert in Network administration and Virtualization, I am confident in my ability to successfully carry out this project for you. With over a decade of hands-on experience in the IT and networking industry, working with various vendors like Cisco, Checkpoint, Pfsense, and Proxmox - I come with extensive exposure to dynamic routing, networking appliances and virtualization platforms. In regard to your project's specific requirements of BGP-based routing within a Proxmox SDN environment using VRFs and Security Groups, my work history makes me uniquely suited to deliver the desired outcomes. In my previous roles, I've designed and implemented complex network infrastructure that involve similar elements such as virtual switches, VRFs and security groups, ensuring both segregation of traffic and uncompromised routing capabilities.I can bring this same deep understanding and methodology to your project. My approach is all about providing work based on best practices, which translates into a documented configuration that guarantees rock-solid performance while meeting all your checkpoints. Hit accept on my proposal and let's get started on building efficient BGP-based routing for your internal subnets that also interoperates seamlessly with your software firewall.
$600 USD in 7 days
7.3
7.3
27 freelancers are bidding on average $487 USD for this job

Hello Dear, I am a BGP and Proxmox expert and I have a Cisco CCNP certificate. I have great experience in various routing protocols such as OSPF, EIGRP, IS-IS and even RIP. Also, I have great hands-on experience in, - Cisco Routers ASR 9k&1k, ISR 4K, 2900, 2800, 878, 888, Switches Nexus 9K, Cat 6500, 3850, 2900 and ASA 5505, 5506x, 5508. - Juniper Routers (M7, M10, MX 480, MX 960) and SRX (300, 500). - Palo Alto 220, 550, 850 and 3200 and Fortigate 40F, 60F, 100E, 200E and 800E Firewalls. - Huawei routers NE-40, NE5000E and Switches Quidway S2700 and S5300. - HP Switches procurve 3500 and procurve 5900. - Mikrotik CCR1036, CCR1009, CCR1700, CCR2204 and RB2011. We can discuss it further, let me know if you are interested. Regards, Ahmed Fakkar
$600 USD in 2 days
7.8
7.8

Hey, I will set up BGP peering between your Proxmox cluster's SDN and the standalone OPNsense firewall — ensuring all three zones (infra, zone1, zone2) announce their subnets, traffic egresses correctly, and the two published services are reachable externally. For the BGP setup, I will configure FRRouting on each node with per-VRF BGP instances so each zone advertises only its own prefixes. This prevents route leaking between zones while still allowing controlled inter-zone traffic through OPNsense — keeping your Security Group segregation intact. Questions: 1) Which ASN scheme do you prefer — private ASNs per VRF or a single ASN with route distinguishers? 2) Is FRRouting already installed on the cluster nodes, or are you using the default Proxmox SDN controller? Ready to start whenever you are. Kamran
$281 USD in 10 days
4.1
4.1

The gap between having Proxmox SDN enabled and actually getting BGP routes working is almost always in the FRRouting daemon layer, Proxmox writes the zone config, but FRR's BGP neighbor statements, AS path filters, and route redistribution don't wire themselves up, and that's exactly where clusters stall or silently blackhole traffic with no obvious error message. The approach here is methodical: confirm your SDN zone type (EVPN or simple), build the correct FRR peer config with the right AS numbers, redistribute connected routes into BGP, then verify with show bgp summary and live cross-VNet ping tests, all via your TeamViewer session with nothing changed blindly. I can join today and have verified BGP peering fully running within 2 to 3 hours, leaving a clean configuration snapshot and a short explanation of every change made so you understand exactly what's running in your cluster. Are you peering BGP with an upstream provider or routing between your Proxmox nodes internally, that changes the AS design and which FRR modules need to start first? Best, Salma Noreen
$669 USD in 5 days
3.6
3.6

Warm greetings, Your Proxmox SDN setup with BGP routing and OPNsense edge firewall requires precise control of VRFs, vSwitches, and routing symmetry to avoid leaks or asymmetric paths. We are a team of 62 professionals with over 9 years of experience in Linux networking, SDN architecture, BGP routing, and secure infrastructure design. Here's how we can help: * Audit full Proxmox cluster (4 nodes + standalone firewall) network topology * Validate SDN zones (infra, zone1, zone2) with VRF/vSwitch configuration * Configure BGP route exchange between SDN subnets and OPNsense * Ensure symmetric routing, failover behavior, and clean traffic handoff * Publish external services + configure DNS/NTP forwarding rules Questions: Are you running FRR or OPNsense native BGP? Is EVPN integrated in your SDN design? Do you require active-active or active-passive edge routing? We can begin with a full network verification and routing map before implementing changes.
$500 USD in 7 days
3.2
3.2

Hi, I've thoroughly reviewed your project details, and your requirement for a surgical integration of Proxmox SDN with BGP routing to ensure seamless traffic flow through your external firewall resonates perfectly with my expertise. With extensive experience in Proxmox SDN, VRFs, BGP, and integrating complex network segments, I can confidently validate your existing network setup and fine-tune the routing to eliminate asymmetric paths and hair-pinning. I'll configure the 3 VNets with the right segregation and routing, ensure external traffic is cleanly routed to the OPNSense firewall on your standalone server, and publish the requested services with security in mind. The deliverables will include comprehensive CLI-based configuration snippets and a concise test plan for failover and route validation. Next step: I'll start by auditing your network config via TeamViewer and quickly proceed with the setup. We can wrap this up efficiently and with rock-solid documentation. Could you please share the current network config details or snapshots to help me start the audit smoothly via TeamViewer? Best regards,
$555 USD in 13 days
2.4
2.4

I understand that this project requires a highly specialized Proxmox SDN and BGP integration expert. Fortunately, that's precisely my forte. With years of experience configuring routing protocols, I can ensure your internal subnets are connected seamlessly and effectively with BGP. Using Virtual Switches, VRFs, and Security Groups intelligently is essential to keep traffic segregated yet routable, and these are skills I've honed over the years working with similar projects. Rest assured, there will be no room for asymmetric routes or hair-pinning in our configuration. What sets me apart is that I understand the importance of not just delivering a working setup, but a documented one as well. I'll provide you with a concise set of CLI commands/configuration snippets so you can effortlessly replicate the setup on other nodes. A quick yet thorough test plan will also be in place to assure you that our failover and route update mechanisms behave as expected. Working with me and my team at Web Crest ensures dealing with well-experienced professionals who take every jobas a challenge to provide the best service possible. Together, we'll build a rock-solid solution that meets all your requirements while staying scalable and future-ready. Don't compromise on surgical assignments like this, let's get it done
$700 USD in 5 days
1.5
1.5

Hello, I can help review and fix your Proxmox SDN and BGP routing setup through TeamViewer only, including the standalone Proxmox server with OPNSense and the 4 node Proxmox cluster. I understand the current SDN zones already allow VMs inside the same subnet to communicate, but the missing part is clean external routing through OPNSense without asymmetric routing, hair pinning, or broken zone separation. I can check the current network configuration, validate bridges, VRFs, VNets, subnets, security groups, BGP settings, OPNSense routes, and then configure the 3 zones: infra, zone1, and zone2 so traffic is routed correctly. I can also help publish 2 services externally, forward DNS and NTP traffic to the infra zone, verify firewall visibility of internal subnets through BGP, and provide CLI/config snippets plus a small test plan using ping, traceroute, route tables, and firewall counters. Best regards Ankit
$250 USD in 3 days
1.0
1.0

Hi there, I just read your posting. It sounds like you need an expert in Proxmox SDN and BGP integration, specifically for a setup that meets your precise routing requirements. I am a seasoned network engineer with over 10 years of experience in network administration, routing protocols, and Linux environments. My expertise in BGP and SDN configurations allows me to design and implement solutions that ensure clean traffic flow across your VMs, virtual switches, and security groups without compromising security or route integrity. I will carefully review your current network configuration to ensure everything is set up correctly. After that, I will configure the SDN with the required virtual networks and subnets, ensuring seamless routing through the edge firewall. You will receive concise CLI commands and configuration snippets for reproduction, along with a test plan to verify functionality. Let me know if my profile looks interesting, and we can set up a time to talk. Best regards, Elijah M.
$450 USD in 5 days
0.4
0.4

Hi, I will configure the BGP routing for your Proxmox cluster, ensuring all SDN-defined subnets are properly announced and routed through your external firewall. With extensive experience in Proxmox SDN, I’ll assess your current network configuration, ensuring virtual switches, VRFs, and Security Groups are optimized for traffic segregation while allowing necessary routing. The setup will enable seamless communication from VMs to the external firewall without asymmetric routing or hair-pinning. I’ll provide a concise set of CLI commands and configuration snippets for easy replication across additional nodes. Additionally, I’ll draft a quick test plan to validate connectivity, failover, and proper routing behavior. To ensure clarity, could you confirm if there are specific services you want to publish externally, or any additional security policies that must be considered? Your requirements are clear, and I’m ready to deliver a robust solution. Thank you.
$537 USD in 7 days
0.0
0.0

Hello, With over a decade of experience in Linux system administration and network engineering, I know I am the right fit for your Proxmox SDN BGP integration project. My deep understanding of networking principles, including dynamic routing protocols like BGP, combined with my proficiency in working with Proxmox setups make me uniquely qualified to solve the complex network challenges you're facing. Delivering high-quality, well-documented work is always my priority. After assessing your current network configuration, I will implement the necessary changes for routing internal subnets to your external software firewall without any asymmetric routes or hair-pinning. Furthermore, my past projects have honed my ability to create comprehensive documentation that empower clients to reproduce the setup on their own. Along with the thorough design of your SDN structure consisting of Virtual Switches, VRFs and Security Groups, I will provide precise CLI commands/configurations that demonstrate failover and route updates exactly as expected. Let's ensure your network not only meets but exceeds your expectations! Thanks!
$250 USD in 3 days
0.0
0.0

Hi there, I reviewed your Proxmox SDN/BGP requirements carefully and can help you validate the current cluster networking, complete the 3 VNet/VRF setup, and route external traffic cleanly through your OPNsense firewall via BGP. Why I’m a good fit: • Strong hands-on experience with Proxmox SDN, VNets, VRFs, Linux routing, BGP, and firewall segmentation • Familiar with end-to-end designs like VM ↔ VNet ↔ VRF ↔ BGP ↔ OPNsense, avoiding asymmetric routing and hair-pinning • I’ll provide clear CLI/config snippets plus a practical ping/traceroute/counter-based test plan for failover and route updates I’ll work only through TeamViewer as requested, review the current network level first, then configure routing, DNS/NTP forwarding to infra, and publish the 2 external services safely. I can start immediately and would be happy to discuss the project in more detail. Best regards,
$725 USD in 3 days
0.0
0.0

Hello, I reviewed your project requirements for the Proxmox SDN BGP Integration Expert assignment, where you need assistance with configuring BGP routing for your Proxmox cluster. I have experience with Linux and network administration, which are relevant skills for this task. I understand that you already have the Proxmox cluster set up with SDN features enabled, and now you need to integrate BGP routing to ensure seamless traffic flow. Here is how I plan to assist you with achieving your goals: • Configure BGP routing to announce every SDN-defined subnet. • Set up Virtual Switches, VRFs, and Security Groups within Proxmox for segregated yet routable traffic. • Ensure end-to-end traffic flow from VMs to the software firewall via Virtual Switches, VRF, and BGP with no asymmetric routes. Before we proceed, I would like to clarify a few questions: • Do you have any specific timeline in mind for completing this configuration? • Is there any additional information or requirements that you would like to share? My approach to this project will involve: 1. Analyzing your current network configuration to ensure everything is correctly set up. 2. Configuring SDN with 3 VNets and subnets, ensuring VMs from the same subnet can communicate. 3. Routing external traffic to the standalone server hosting the firewall (OpnSense). 4. Publishing 2 services to the external network and forwarding DNS and NTP traffic to the infra zone. The deliverables will include: 1. Ensuring all internal subnets are visible on the firewall via BGP with internet access and inter-subnet connectivity. 2. Providing a concise set of CLI commands/configurations for reproducing the setup on additional nodes. 3. Creating a test plan (ping, traceroute, iptables counters) to validate failover and route updates. Given your requirements, I am confident in my ability to provide a rock-solid, documented configuration that meets your expectations. I understand the need for precision in this task and will ensure that the setup is thorough and well-documented. Thank you for considering my proposal. I look forward to discussing the project details with you further. Best regards, bhargav922002
$525 USD in 3 days
0.0
0.0

Rough numbers above are placeholders, we'll pin down the real figure once we've had a look at the current state of things via TeamViewer. Sounds like the heavy lifting is already done on the SDN side, three VNets up and intra-subnet traffic working. What's missing is the BGP peering between Proxmox's SDN layer and the OPNsense edge, VRF awareness so each subnet stays properly segregated in the routing table, and the last-mile bits like publishing two services outward and steering DNS/NTP into the infra zone. Getting asymmetric routes out of the picture is usually where these setups trip up, so we'll verify that carefully before signing off. Here's how we'd approach this: - Audit pass: connect via TeamViewer, review the current SDN config across all four nodes, map the existing VNet/VRF layout and confirm the OPNsense uplink interfaces are sane. - BGP setup: configure FRR on the Proxmox nodes to peer with OPNsense, announce all three SDN subnets, and verify route propagation in both directions with no blackholes. - VRF and Security Group alignment: make sure each VRF boundary matches the Security Group rules so traffic is segregated where it should be and routable where it needs to be. - Service publishing: set up the two external-facing forwarding rules on OPNsense and confirm inbound paths are clean. - DNS and NTP forwarding: redirect both to the infra zone and test from a VM inside each subnet. - Handoff doc: a tight set of CLI snippets and a ping/traceroute/iptables test plan so you can reproduce this on any new node. After the call we'll send a short written proposal with milestones and a firm price. Want to book a quick TeamViewer session this week to start with the audit? Best, 96 Studio
$488 USD in 4 days
0.0
0.0

Hello, I read your request for "Proxmox SDN BGP Integration Expert, ONLY WoRKING on TEAMVIWER". I can help you turn the brief into a clear, reviewable delivery focused on Linux, Computer Security, Cisco, Network Administration. My first step would be to confirm the exact scope, the expected format and the priority items. I would then share a first version early enough for your feedback, apply the agreed revisions and deliver the final files cleanly. Could you confirm the most important result you want to receive first and your target deadline? Best regards
$250 USD in 2 days
0.0
0.0

Hello, this is a narrowly scoped network-routing job, and the important part is not enabling another SDN object in Proxmox but making the end-to-end path deterministic across the cluster and the standalone OPNsense edge. The real engineering risk is asymmetric routing between VRFs, node uplinks, and the firewall handoff, which is where internet reachability and inter-zone policy usually break even when same-subnet VM traffic already works. My closest relevant work is Enterprise ProxyTool Client App, where I designed traffic routing, DNS behavior, failover handling, and clean separation between control and data paths. That is not the same platform, but the troubleshooting discipline is similar. I usually structure this by validating the current node-level network state first, then tracing each zone’s forward and return path, then tightening route ownership and policy boundaries so the firewall sees stable prefixes and return traffic stays clean. I would review the existing SDN, bridge, and zone wiring, map the path for infra, zone1, and zone2, and identify where route propagation or policy is leaking. If useful, I can start by sketching the traffic path and a concise validation checklist for ping, traceroute, and counter-based verification. Clifton
$500 USD in 7 days
0.0
0.0

I am an experienced Proxmox SDN and BGP engineer and can configure your cluster for seamless end-to-end routing. I’ll audit the current network setup across your 4-node cluster and standalone OPNsense firewall, ensuring SDN, VRFs, and Security Groups are correct. I’ll configure BGP to announce all internal subnets to the firewall, route external traffic through OPNsense, forward DNS/NTP to the infra zone, and publish 2 external services. You will receive a documented, reproducible configuration with CLI commands and a test plan (ping/traceroute/iptables counters) to verify failover and route updates. Work will be performed remotely via TeamViewer as requested.
$500 USD in 7 days
0.0
0.0

Hi there, I am a System and Network Engineer with hands-on experience in Proxmox virtual environments and advanced routing. I am fully comfortable working exclusively via TeamViewer to complete this surgical assignment. Based on your requirements, here is how I will approach your setup: Review & Audit: First, I will verify the current network configurations on your 4-node Proxmox cluster and the standalone OPNSense firewall to ensure the base layer is correctly set up. BGP & SDN Integration: I will configure BGP to cleanly announce the 3 VNET subnets to your OPNSense firewall. I will ensure the Virtual Switches, VRFs, and Security Groups are perfectly aligned so traffic flows end-to-end without hair-pinning or asymmetric routing. Service Publishing: I will route the external traffic to the firewall, publish the 2 required services externally, and set up the DNS and NTP traffic forwarding into the infra zone. Documentation & Testing: As requested, I will provide the exact CLI commands and configuration snippets so you can reproduce the setup later. Finally, we will run the test plan (ping, traceroute, and iptables counters) together to verify failover and route updates. I do not take shortcuts and understand the importance of a rock-solid, documented configuration. I am ready to connect via TeamViewer and start immediately. Best regards,Isuru M.
$275 USD in 7 days
0.0
0.0

Hello, I can help review and complete your Proxmox SDN and OPNsense integration. My approach is to first validate the existing network configuration, SDN setup, routing, and firewall policies before making changes. I will review the current cluster networking, SDN zones/VNETs/subnets, and OPNsense configuration to ensure the design supports the required traffic flow. Scope of work: * Review and validate current Proxmox networking and SDN configuration * Verify Virtual Switches, VRFs, and Security Groups * Configure/validate routing between Infra, Zone1, and Zone2 * Integrate BGP route advertisement for SDN subnets * Ensure traffic is routed correctly through OPNsense without asymmetric routing * Configure DNS and NTP forwarding to the Infra zone * Publish the two required services externally * Perform connectivity, routing, and failover testing * Provide documentation and reproducible configuration steps Deliverables: * Validated and documented network design * Working SDN-to-OPNsense routing * BGP-advertised internal subnets * DNS/NTP forwarding configuration * External service publishing * Testing and handover documentation Estimated timeline: 5 business days including assessment, implementation, testing, and documentation. I would be happy to review the current environment and discuss the topology before proceeding.
$350 USD in 5 days
0.0
0.0

⚠️ If you're not happy, you don’t pay. ⚠️ I’ve worked on this exact type of Proxmox SDN + BGP routing setup, including multi-node clusters with VRFs, virtual switches, and firewall handoff architectures using OPNsense. Your requirement for clean end-to-end routing without asymmetry is clear. I specialise in Proxmox networking, BGP route advertisement, and SDN segmentation where traffic must stay isolated between zones while still being correctly routed to an external firewall. I can also validate your current config, adjust SDN (VNets/subnets), and ensure proper service exposure for DNS/NTP and published services. Happy to review your existing setup and outline the routing design in a quick, no-pressure call. Regards, Blaze Nicholas
$500 USD in 14 days
0.0
0.0

Hello, I will review your current Proxmox SDN and network setup and make sure routing between zones, VRFs, and your external OPNsense firewall works cleanly. I will verify existing virtual switches, subnets, and SDN zones first, then correct any misconfigurations causing routing gaps or asymmetry. After that, I will configure BGP integration so all SDN subnets are properly announced to your firewall. I will ensure traffic flow is stable between VM ↔ virtual switch ↔ VRF ↔ BGP ↔ OPNsense with correct return paths. I will also implement clean separation for infra, zone1, and zone2 while allowing controlled routing based on security rules. Finally, I will set up service exposure (2 external services) and route DNS + NTP traffic securely to infra zone. I will include a clear CLI-based documentation and a validation test plan using ping, traceroute, and routing checks to confirm failover and stability.
$500 USD in 7 days
0.0
0.0

Wallisellen, Switzerland
Payment method verified
Member since Sep 2, 2022
$250-750 USD
$1500-3000 USD
$250-750 USD
$250-750 USD
$30-250 USD
₹1500-12500 INR
$15-25 AUD / hour
₹12500-37500 INR
₹500000-1000000 INR
$30-250 USD
$250-750 USD
$250-750 USD
₹600-5000 INR
₹12500-37500 INR
$30-250 USD
₹600-1500 INR
$30-250 USD
$250-750 USD
₹600-20000 INR
$250-750 USD
$14-120 NZD
₹1500-12500 INR
₹12500-37500 INR
$30-250 NZD
$10-30 AUD