Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Yes, Proxmox VE can use two physical NICs on the same Layer-2 network—but you should not normally give both independent interfaces addresses in the same subnet. For redundancy or combined capacity, create a Linux bond and attach that bond to one Proxmox bridge. If the NICs serve different purposes, use separate bridges or VLANs with different subnets.

First, define “the same network”

These terms describe different things:

  • Same switch: both cables connect to the same physical switch.
  • Same broadcast domain or VLAN: both ports carry the same Layer-2 network.
  • Same IP subnet: both interfaces use addresses such as 192.168.1.20/24 and 192.168.1.21/24.
  • Same bridge: both physical ports are attached to one Linux bridge.
  • Same logical link: both NICs are combined into a bond such as bond0.

Two NICs can be connected to the same switch while belonging to different VLANs. Conversely, putting two unbonded uplinks into the same bridge can create a Layer-2 loop or duplicate path. The correct design depends on whether you want one logical connection or two separate networks.

Choose the design that matches your goal

Goal Recommended design
Simple link failover active-backup bond → one bridge
Aggregate capacity across multiple flows 802.3ad LACP bond → one bridge
Management and VM traffic on one LAN One bridge, optionally over a bond
Dedicated storage or migration traffic Separate bridge or VLAN with a different subnet
Two genuinely separate physical networks Two bridges with different networks
Two independent same-subnet interfaces Only for deliberate policy-routing and ARP designs

Recommended setup: two NICs in a bond

For most Proxmox installations, the correct topology is:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
eno1 ─┐
      ├── bond0 ── vmbr0 ── Proxmox host and guests
eno2 ─┘

The physical NICs should have no IP addresses. The bond normally has no IP address when it is used as a bridge port. Put the Proxmox management address and gateway on vmbr0.

#1 Best Overall
Dual-Port PCIe Gigabit Network Card 1000M PCI Express Ethernet Adapter with Intel 82575/82576 Two Ports LAN NIC Card for Support PXE for Windows/Windows Server/Linux/Freebsd/DOS with Low Profile
  • Supports Windows 7/8/2000/XP/Vista/Windows Server 2003/2008/2012; Novell Netware 5.x/6.x; Linux; FreeBSD 7.x or later; DOS; SCO Open Server; UnixWare / OpenUnix 8; Sun Solaris x86; OS Independent Vmware ESX (Does not support VMware ESXi 7.0 or above)
  • PCI Express 2.1. 2.5 GT/s x1 Lane. Compatible with x1, x2,x4, x8, x16 standard and low-profile PCI Express slots.
  • Compatible with IPMI pass-through (SMBus or NC-SI), iSCSI boot, WoL, PXE remote boot, VLAN filtering
  • Support Network Management Protocol (SNMP) and Remote Network Monitoring (RMON).
  • Imported alloy heat sink , can effectively remove excess heat , keep the network card at normal operating temperature and double stable operation

Active-backup: the safest general-purpose option

Use active-backup when your priority is failover, when the switch is unmanaged, or when the two cables connect to separate switches that are not configured as one logical aggregation system. Only one link is normally active at a time, so this mode does not generally combine both links’ throughput for one connection.

A typical /etc/network/interfaces configuration is:

auto lo
iface lo inet loopback

iface eno1 inet manual
iface eno2 inet manual

auto bond0
iface bond0 inet manual
        bond-slaves eno1 eno2
        bond-miimon 100
        bond-mode active-backup

auto vmbr0
iface vmbr0 inet static
        address 192.168.1.20/24
        gateway 192.168.1.1
        bridge-ports bond0
        bridge-stp off
        bridge-fd 0

Replace the interface names, address, and gateway with values appropriate for your host. Confirm the names with ip -br link; do not assume the ports are called eno1 and eno2.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

LACP / 802.3ad: aggregate capacity with switch support

Use 802.3ad only when the upstream switch is configured with both ports in the same LACP port channel. The switch ports must have matching VLAN membership, speed, duplex, MTU, and other relevant settings.

auto bond0
iface bond0 inet manual
        bond-slaves eno1 eno2
        bond-miimon 100
        bond-mode 802.3ad
        bond-xmit-hash-policy layer2+3

LACP can improve aggregate throughput when multiple VMs, destinations, or independent flows are active. It does not guarantee that one TCP connection will use both links. A single flow may remain on one physical link because the bond and switch distribute traffic using hashing.

Rank #2
2.5GBase-T Dual Port Server Network Card with Intel Intel I226-V 2500/1000/100Mbps PCI Express Gigabit Ethernet Adapter NIC Card RJ45 LAN Controller for Windows 10/11 with Low Profile Bracket
  • PCI Express 3.1 :5GT/s Support for x1 width (Lane).The original I225-v has been discontinued, and the new generation I226-v will replace it. The two models have identical functionality. Compared to the I225, the I226 has improved error rates, offering better data packet stability over longer cable lengths and providing a more stable network connection. It also enhances the accuracy and stability of data transmission. In the end, the new generation I226 reduced active power consumption, making it more energy-efficient
  • Network Interfaces:Integrated MAC + BASE-T PHY. MDI (Copper) standard IEEE 802.3 Ethernet interface for 2500BASE-T, 1000BASE-T, 100BASE-TX, and 10BASE-TE applications (802.3, 802.3u, 802.3bz, and 802.3ab)
  • This 2.5GB Dual-Port NIC RJ45 Ethernet Network Card supports a motherboard with an X1/X4/X8/X16 slot and a PCIe gold-plated pin with nice electrical conductivity and high oxidation resistance.In addition, this Dual port network adapter gigabit network card comes with low profile bracket, suitable for desktop/server/workstation and other computer cases 
  • Support Win10/11,Linux Kernel 5.8/5.16.18,RHEL 8.1/8.3/8.6,Ubuntu* 22.04 LTS,FreeBBSD 13.0,VMware ESXi7.0/8.0,DPDK 20.05/22.07,OPENWRT/UNRAID/PVE.Support PXE function
  • Worry free warranty and friendly customer service. If you have any questions, we will help you solve the problem when you need it. If it cannot be solved, we will provide a refund without the need for a return

Incorrect switch-side LACP configuration can cause packet loss or an unstable connection. If you cannot configure the switch, use active-backup instead.

Alternative: two separate bridges for two separate networks

Use separate bridges when the NICs intentionally serve different networks—for example, management, storage, migration, backups, an isolated lab, or a firewall/router connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
auto eno1
iface eno1 inet manual

auto vmbr0
iface vmbr0 inet static
        address 192.168.1.20/24
        gateway 192.168.1.1
        bridge-ports eno1
        bridge-stp off
        bridge-fd 0

auto eno2
iface eno2 inet manual

auto vmbr1
iface vmbr1 inet static
        address 10.10.10.20/24
        bridge-ports eno2
        bridge-stp off
        bridge-fd 0

A guest can have one virtual NIC connected to vmbr0 and another connected to vmbr1. Use different subnets or VLANs for the two networks. Do not normally configure a second default gateway; the host should generally have one preferred default route unless you have deliberately implemented policy routing.

One VLAN-aware bridge over a bond

In a managed-switch environment, a scalable design is to carry several VLANs over one bonded uplink:

eno1 + eno2 → bond0 → VLAN-aware vmbr0
                         ├─ management VLAN
                         ├─ VM VLANs
                         ├─ storage VLAN
                         └─ migration VLAN

The bridge can be configured like this:

iface eno1 inet manual
iface eno2 inet manual

auto bond0
iface bond0 inet manual
        bond-slaves eno1 eno2
        bond-miimon 100
        bond-mode 802.3ad
        bond-xmit-hash-policy layer2+3

auto vmbr0
iface vmbr0 inet static
        address 192.168.1.20/24
        gateway 192.168.1.1
        bridge-ports bond0
        bridge-stp off
        bridge-fd 0
        bridge-vlan-aware yes

The switch must be configured as a compatible tagged trunk. Assign VLAN tags to guest NICs in Proxmox, and ensure the management VLAN’s native or tagged behavior matches on both sides. An accidental mismatch between an untagged management network and a tagged-only switch port can make the host unreachable.

Rank #3
Sale
TP-Link 2.5GB PCIe Network Card (TX201) – PCIe to 2.5 Gigabit Ethernet Card
  • 2.5 Gbps PCIe Network Card: With the 2.5G Base-T Technology, TX201 delivers high-speeds of up to 2.5 Gbps, which is 2.5x faster than typical Gigabit adapters. Performance varies by conditions, distance to devices, and obstacles such as walls
  • Versatile Compatibility – The Ethernet Network Adapter is backwards compatible with multiple data rates(2.5 Gbps, 1 Gbps, 100 Mbps Base-T connectivity). The 2.5G Ethernet port automatically negotiates between higher and lower speed connection.
  • QoS: Quality of Service technology delivers prioritized performance for gamers and ensures to avoid network congestion for PC gaming
  • Wake on LAN – Remotely power on or off your computer with WOL, helps to manage your devices more easily
  • Low-Profile and Full-Height Brackets: In addition to the standard bracket, a low-profile bracket is provided for mini tower computer cases

Why two independent same-subnet addresses are usually a mistake

A configuration such as this is generally not the right way to obtain redundancy:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
eno1: 192.168.1.20/24
eno2: 192.168.1.21/24

The same problem applies to two bridges:

vmbr0: 192.168.1.20/24
vmbr1: 192.168.1.21/24

Linux treats IP addresses as belonging to the host as a whole rather than being cleanly isolated to one interface. With multiple interfaces on one subnet, questions arise about which interface answers ARP, which source address is selected, and whether replies return through the expected path. Reverse-path filtering and switch MAC learning can add further complications.

The Linux kernel documentation explains that controlled ARP behavior for this type of design requires source-based routing. In practice, that means policy-routing rules, ARP controls, and careful validation—not merely assigning two addresses. Reserve this approach for administrators who specifically need it and understand the routing design. For ordinary Proxmox redundancy, use a bond.

Do not put two ordinary uplinks into one bridge

A Linux bridge acts as a software switch. If both physical ports are added as independent bridge ports and both lead to the same upstream Layer-2 network, the bridge may forward frames between them. That can create a loop or an unintended duplicate path.

A bond treats multiple physical links as one logical uplink. A bridge connects the host and guests to a network as a software switch. They solve different problems. For redundant or aggregated uplinks, place the bond beneath the bridge.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Gigabit Dual NIC with Intel 82576 Chip, 1Gb Network Card Compare to Intel E1G42ET NIC, 2 RJ45 Ports, PCI Express 2.1 X1, Ethernet Card with Low Profile for Windows/Windows Server/Linux
  • Ethernet Controller: 1Gb Network Card equipped with original Intel 82576 Controller, which supports Quality-of-Service (QoS) technology to streamline your online experience and ensure stability; Compare to Intel E1G42ET, 1 Pack
  • Dual RJ45 Ports: Gigabit RJ45 Support 10/100/1000Mbps data rates and Cat5e Cable, up to 100 meters, simplifying the transition to 1 Gb; PCI Express 2.0 (2.5 GT/s), X1 Lane, compatible with PCIE X1, X4, X8, X16 Slot. Support 1 Gbps/ 100 Mbps data rates
  • Widely Compatible OS: Windows 7/8/10/11, Windows Server 2008/2012/2016/2019, Centos/RHEL 6/7/8, Ubuntu 16/18/19/20, Debian 9/10/11,FreeBSD 10/11/12, Vmware Esxi 5/6, SLSE 11/12. (Not support Vmware Esxi 7.0, Mac OS and Bypass Mode)
  • Easy to Install: Network Card is packed with both Low Profile Bracket and Full-height Bracket that support on Standard and Slim computer/server; Download operating systems driver from intel website or scan the QR code on the network card
  • Friendly Service: Provides 24/7 Customer Service, 30 Days Free-returned, 3 Years Free Warranty and Lifetime Technology Support

Before changing the configuration

  1. Back up or record the current configuration:
    cat /etc/network/interfaces
    ip -br link
    ip -br addr
    ip route
  2. Identify the physical ports and check their link state:
    ethtool eno1
    ethtool eno2
  3. Confirm which port currently carries management traffic.
  4. Arrange console, IPMI, or another out-of-band recovery path. A remote network change can disconnect your session.
  5. Configure the switch first when using LACP or VLAN trunks.
  6. Schedule the change if the node runs production guests.

Proxmox provides network configuration through the GUI and /etc/network/interfaces. The GUI path is generally Node → System → Network, although labels can vary by Proxmox VE release. Create a Linux Bond, select its ports and mode, then create or edit a Linux Bridge whose bridge port is bond0. Put the host IP and gateway on the bridge, not on the physical NICs.

Proxmox’s ifupdown2 tooling can apply many changes without a reboot, but “no reboot required” does not mean “no disruption.” Treat a remote network change as a possible outage and use the console if the configuration does not apply as expected.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Validate the result

On the Proxmox host, check:

ip -br link
ip -br addr
ip route
cat /proc/net/bonding/bond0
bridge link
bridge vlan show

In the normal bridged design, the expected arrangement is:

eno1  — no host IP
eno2  — no host IP
bond0 — no host IP
vmbr0 — 192.168.1.20/24 and the default gateway

Test the gateway and an external destination:

ping -c 4 192.168.1.1
ping -c 4 1.1.1.1

From a guest, verify its address, route, gateway, DNS, and connectivity. To test failover, first confirm the bond is healthy, then disconnect or disable one link:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
cat /proc/net/bonding/bond0
ip link set eno1 down
# verify connectivity and the active slave
ip link set eno1 up

Do not disable the only management path unless console or out-of-band access is available.

Best Value
Dual-Port PCIe Gigabit Ethernet Server Adapter with NetXtreme BCM5720-2P Chipset PCI Express 1000M Network LAN Card for Windows Sever Linux Ubuntu VMware
  • The BCM5720-2P is compatible with x86 and x64 servers utilizing the PCIe v1.X and v2.X interfaces
  • PCI-E x1,compatible with pci-e x2,x4,x8,x16.Comes with Low Profile Bracket
  • Wide range of applications:Cloud and Web2.0 data center servers,Enterprise data center servers,Private Cloud,Machine Learning (ML) clusters,High-Performance Computing (HPC) clusters,Multi-node container platforms,NVMe storage disaggregation (NVMe-oF),Database servers
  • OS Support:CentOS, Debian, Microsoft Windows, Oracle Linux, Oracle Solaris, Red Hat Enterprise Linux, SUSE Linux Enterprise Server, SUSE Linux Enterprise Server, Ubuntu, VMware, VMware ESX(Esxi 5/6/7/8), VMware vSphere, Windows Hyper-V, Windows Server
  • 180 day worry-free warranty and friendly customer service. If you have any questions, we will help you solve the problem when you need it, and if it can’t be solved, we will provide a refund and no return is required.

Troubleshooting

The host becomes unreachable

Use the console or IPMI and inspect:

cat /etc/network/interfaces
ip -br addr
ip route

Look for an IP left on a physical NIC, a wrong bridge-ports name, a missing gateway, a wrong VLAN, or LACP enabled on Proxmox without matching switch configuration. Temporarily simplify the setup to one known-good NIC and one bridge, restore connectivity, then add bonding or VLANs incrementally.

The LACP bond does not come up

cat /proc/net/bonding/bond0

Verify that both switch ports are in the same LACP group, the switch sees both as active members, VLAN settings match, and speed, duplex, MTU, and port profiles are compatible. If switch configuration is unavailable, change to active-backup.

Connectivity is intermittent or ARP warnings appear

Possible causes include independent same-subnet interfaces, two bridges attached to the same LAN, a bridge loop, unexpected ARP replies, or a duplicate guest IP. Inspect:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ip route
ip neigh
bridge fdb show
tcpdump -ni eno1 arp
tcpdump -ni eno2 arp

Kernel settings such as arp_filter, arp_ignore, arp_announce, and reverse-path filtering matter in advanced multi-interface designs. Changing them blindly is not a substitute for correcting a misconfigured bond or bridge.

One failed link does not recover traffic

Check cat /proc/net/bonding/bond0 and ethtool on both NICs. Possible causes include missing or unsuitable bond-miimon, a cable or transceiver fault, inconsistent LACP state, or a bridge/VLAN configuration that still references the failed NIC directly.

Performance does not double

This is usually expected. Bonding distributes traffic according to its mode and hash policy. Aggregate throughput can improve across multiple VMs or flows, but two 1-Gb/s links are not a guaranteed 2-Gb/s path for every individual connection.

Important edge cases

  • Two switches: active-backup is often appropriate when each NIC connects to a different switch. LACP across separate switches generally requires a supported MLAG, stacking, or equivalent multi-chassis aggregation design.
  • Unmanaged switch: use active-backup, not LACP.
  • Different-speed NICs: bonding may be possible, but matching speed, duplex, MTU, and hardware is easier to operate and troubleshoot.
  • Clusters: Corosync and other cluster traffic deserve deliberate planning. Proxmox recommends at least one dedicated physical NIC for the primary Corosync link; sharing cluster, management, VM, and storage traffic can increase the impact of congestion or failure.
  • Ceph or shared storage: a separate VLAN, subnet, bond, or physical network may be appropriate. A second NIC on the same ordinary bridge does not automatically isolate or prioritize storage.
  • VMs and containers: both use Proxmox bridges and VLANs, although guest-side configuration differs. The host’s bridge and bond configuration does not replace configuring the guest’s own IP settings.

Final recommendation

If the two NICs are intended to provide one connection to the same LAN, use one bond beneath one bridge: choose active-backup for straightforward failover, or 802.3ad when the switch is correctly configured for LACP. If the ports serve different functions, use separate VLANs or subnets and normally separate bridges. Avoid assigning ordinary same-subnet addresses to independent NICs, and never assume that LACP doubles the speed of a single connection.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For reference, see Proxmox’s network configuration documentation, the Proxmox VE Administration Guide, Linux’s Ethernet bonding documentation, and the kernel guidance on ARP, routing, and multiple interfaces.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.