> For AI agents: the complete documentation index is available at https://docs.vps.town/llms.txt, the full documentation bundle is available at https://docs.vps.town/llms-full.txt.

# PVE 安装切 KVM 虚拟机以及基于 NAT 实现独立双栈 IP

:::tip 温馨提示

本文由用户 `灰机喵喵喵` 撰写，并已加入 `VPS.Town 优秀原创文章激励计划`，未经允许不得转载。

本文已通过 [VPS.Town 社区文章投稿及奖励规则 (试行稿)](https://docs.vps.town/kb/community.md) 格式审核，投稿内容真实性由原作者负责。

:::

::: details 📖 本文目录

[](#准备)[](#安装-pve)[](#dd-重装系统)[](#安装基本包)[](#安装-pve-1)[](#配置-pve-宿主机的网络)[](#分-kvm-虚拟机)[](#给-kvm-虚拟机添加独立-ipv6)[](#开启-root-密码登录)[](#nat-端口转发)
:::

## 准备

- 大鸡一台
- 一个人
- 一双手
- 一键盘

## 安装 PVE

### DD 重装系统

首先，进入 SSH，重装一下系统，这里使用 [bin456789/reinstall](https://github.com/bin456789/reinstall) 的 DD 重装脚本。

```shell
curl -O https://raw.githubusercontent.com/bin456789/reinstall/main/reinstall.sh || wget -O ${_##*/} $_
bash reinstall.sh debian 12 --password 这里填写你的root密码 --ssh-key "这里填写你的ssh公钥ID (没有可不填)"
```

:::info 注意

安装`PVE8`必须是`Debian12`，如果要装`PVE9`，则需要`Debian13`。

:::

### 安装基本包

```shell
apt update
apt install curl sudo wget -y
```

### 安装 PVE

1. 使用`oneclickvirt`的`install_pve.sh`一键安装 PVE 脚本

```shell
curl -L https://raw.githubusercontent.com/oneclickvirt/pve/main/scripts/install_pve.sh -o install_pve.sh && chmod +x install_pve.sh && bash install_pve.sh
```

2. 安装直到显示以下对话：

```bash
Please execute reboot to reboot the system and then execute this script again
Please wait for at least 20 seconds without automatically rebooting the system before executing this script.
请执行 reboot 重启系统后再次执行本脚本，再次使用SSH登录后请等待至少20秒未自动重启系统再执行本脚本
```

3. 如文本所示，这时候只需要`reboot`重启，然后再次连接等待 20s 后再执行一次脚本

```shell
bash install_pve.sh
```

4. 然后会要求输入新主机名字：

```bash
Please enter a new host name (can only contain English letters and numbers, not pure numbers or special characters, enter the default pve):
请输入新的主机名(只能包含英文字母和数字,不能是纯数字或特殊字符,回车默认为pve):
```

不修改默认回车就好。
然后等待安装完成。

5. 当显示如下信息则已经安装完成：

```plaintext
Running kernel: pve-manager/8.4.14/b502d23c55afcba1 (running kernel: 6.1.0-41-cloud-amd64)

Installation complete, please open HTTPS web page https://123.123.123.123:8006/
The username and password are the username and password used by the server (e.g. root and root user's password)
If the login is correct please do not rush to reboot the system, go to execute the commands of the pre-configured environment and then reboot the system
If there is a problem logging in the web side is not up(Referring to the page reporting an error, it keeps loading or is normal), wait 10 seconds and restart the system to see

安装完毕，请打开HTTPS网页 https://123.123.123.123:8006/
用户名、密码就是服务器所使用的用户名、密码(如root和root用户的密码)

如果登录无误请不要急着重启系统，去执行预配置环境的命令后再重启系统
如果登录有问题web端没起来(指的是网页报错，一直在加载还是正常的)，等待10秒后重启系统看看
```

这时候就去访问信息中的链接地址就可以访问到 PVE 后台了，用户名是`root`，密码则是你`ssh`的`root`密码。

### 配置 PVE 宿主机的网络

> \[!警告]
> 确定能够进入 PVE 之后，再进行此操作。

使用一键脚本进行配置：

```shell
bash <(wget -qO- --no-check-certificate https://raw.githubusercontent.com/oneclickvirt/pve/main/scripts/build_nat_network.sh)
```

然后就会自动创建`brige`网络接口。
**`vmbr0`负责 v4 的独立 IP，`vmbr1`负责复杂 v4/v6 的 NAT，`vmbr2`负责 v6 的独立 IP**

:::info 注意

如果宿主机自带的`IPV6`是`/64`的，就不会有`vmbr2`。

因为有一些杜甫是直接给多个`IPV6`的`/64`子段（VPS.Town 的 A4 就是），这时候就直接用`vmbr0`去分即可。

:::

## 分 KVM 虚拟机

1. 首先，先下镜像，这里直接用 Debian 的官方镜像，[传送门](https://cdimage.debian.org/cdimage/cloud/)
   这里使用[debian-12-genericcloud-amd64.qcow2](https://cdimage.debian.org/cdimage/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2)作为小鸡的系统。
   先下载到 PVE 上：

```shell
wget https://cdimage.debian.org/cdimage/cloud/bookworm/latest/debian-12-genericcloud-amd64.qcow2
```

2. 接下来去创建虚拟机，填写虚拟机名称，然后`操作系统`选择`不使用任何介质`：
   ![操作系统设置](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-1.png)

`系统`默认即可

`磁盘` 删除掉默认的硬盘，不需要添加硬盘：
![硬盘设置](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-2.png)

`CPU`根据需要选择，`类别`如需要高性能可选择`host`否则默认即可：
![CPU设置](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-3.png)

`内存`根据需要给就行：
![内存设置](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-4.png)

`网络`如果有多个独立 IPV4 选择`vmbr0`，如果使用 NAT，选择`vmbr1`：
![网络设置](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-5.png)

:::info 注意

防火墙需要关闭，不然 KVM 虚拟机可能会无法访问公网。如需开启防火墙需要去主机防火墙放行`in` 来源 IP 内网网段规则。
:::

然后创建即可。

3. 然后进入 PVE 控制台，将镜像导入到该虚拟机中：

```shell
qm disk import 100 debian-12-genericcloud-amd64.qcow2 local --format qcow2
```

`100`是虚拟机 ID `debian-12-genericcloud-amd64.qcow2`是镜像 `local`是本地存储

4. 导入之后，进入虚拟机的`硬件`，找到`未使用的硬盘0`，双击或者点编辑，然后添加硬盘，`总线/设备`可选`VirtIO Block`：
   ![添加硬盘](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-6.png)

5. 然后再选择硬盘，然后点击`磁盘操作`-`调整大小`，输入要增大硬盘的大小：
   ![调整硬盘大小](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-7.png)

6. 然后再点`选项`，双击`引导顺序`，将`virtio0`硬盘启用，然后拉到第一位：
   ![设置引导顺序](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-8.png)

7. 再回到`硬件`，点击`添加`，选择`Cloudinit 设备`，然后添加：
   ![添加CloudInit](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-9.png)

8. 然后点击`Cloud-Init`，然后可以设置`用户`、`密码`、`SSH公钥`、`DNS服务器`、`IP设置`
   按需设置，这里还需要讲清楚`IP设置`，NAT4 需要为虚拟机设置固定的内网 IP：
   ![设置NAT4](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-10.png)

这里因为我要给虚拟机设置独立 IPV6，就不需要设置 NAT6 了，如果需要设置 NAT6，就给它设置 NAT 的子网段，例如：
![设置NAT6](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-11.png)

9. 然后再回到`硬件`，添加`串行接口`：
   ![添加串行端口](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-12.png)

10. 然后选中`显示`，显卡换成`串行终端 0`：
    ![更改显示端口](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-13.png)

11. 然后就可以正常开机，享受刚切的小鸡鸡了。

## 给 KVM 虚拟机添加独立 IPV6

1. 在虚拟机`硬件`中点击添加`网络设备`：
   ![添加网络设备](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-14.png)

:::info 注意
`桥接`选择宿主机的`vmbr0`或者`vmbr2`，具体看宿主机的 IPV6 分配情况。
:::

2. 然后回到`Cloud-Init`中，编辑`IP配置(net1)`，设置静态的 IPV6：
   ![设置静态IPV6](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-15.png)

3. 进入虚拟机，使用`ip.sb`测试 IPV4 和 IPV6 是否正常：

```shell
curl ip.sb -4
curl ip.sb -6
```

![测试IPV4和IPV6](/assets/images/proxmox-pve-installation-kvm-vm-setup-nat-and-dualstack-ipv4-ipv6/image-16.png)

## 开启 ROOT 密码登录

1. 进入虚拟机的`控制台`，然后输入用户名和密码进行登录

2. 编辑`/etc/ssh/sshd_config`文件

```shell
nano /etc/ssh/sshd_config
```

找到`PermitRootLogin`和`PasswordAuthentication`，去掉注释改成：

```bash
PermitRootLogin yes
PasswordAuthentication yes
```

然后按`Ctrl+X`，按 Y 确认然后回车保存，然后再重启 ssh 服务：

```shell
systemctl restart sshd
```

## NAT 端口转发

1. 使用`iptables`宿主机上的端口转发到虚拟机的端口上

```shell
iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport 10000 -j DNAT --to-destination 172.16.1.2:22
```

`dport` 宿主机端口 `to-destination` 虚拟机地址端口

2. 永久保存方法：
   编辑`/etc/network/interfaces`
   在`iface vmbr1 inet static`后面添加上

```shell
post-up iptables -t nat -A PREROUTING -i vmbr0 -p tcp --dport 10000 -j DNAT --to-destination 172.16.1.2:22
post-dodwn iptables -t nat -D PREROUTING -i vmbr0 -p tcp --dport 10000 -j DNAT --to-destination 172.16.1.2:22
```

保存即可，然后重启网络：

```shell
systemctl restart networking
```
