Windows路由中最长前缀匹配失效的原因排查求助
Windows路由中最长前缀匹配失效的原因排查求助
各位大佬好!最近在实验室环境里遇到一个Windows路由的奇怪问题——最长前缀匹配规则居然失效了,折腾了好久没搞明白,想请大家帮忙分析下原因!
问题核心
按道理说,访问181.0.0.1应该优先匹配181.0.0.0/8的路由条目,走VMnet11网卡,但实际流量却走了默认网关(0.0.0.0/0)跑到外网去了。而且这两条路由的Metric值都是291,完全符合最长前缀匹配的优先级条件啊!
环境配置
- 虚拟网卡VMnet11(VMware):分配IP
181.0.0.10/8 - 物理网卡:分配IP
192.168.4.110/24,默认网关为192.168.4.84(可正常访问互联网)
异常现象
- ping
181.0.0.1时,流量通过默认网关转发到外网,而非走VMnet11网卡 - 但ping VMnet11自身IP
181.0.0.10时行为正常,会匹配主机路由(255.255.255.255)走本地接口
相关命令输出
1. route print 关键内容
=========================================================================== Interface List 26...00 e0 4c 62 16 05 ......Realtek RTL8139/810x Family Fast Ethernet NIC 7...00 50 56 c0 00 0b ......VMware Virtual Ethernet Adapter for VMnet11 Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.4.84 192.168.4.110 291 181.0.0.0 255.0.0.0 On-link 181.0.0.10 291 181.0.0.10 255.255.255.255 On-link 181.0.0.10 291 255.255.255.255 255.255.255.255 On-link 181.0.0.10 291 =========================================================================== Persistent Routes: Network Address Netmask Gateway Address Metric 0.0.0.0 0.0.0.0 192.168.4.84 Default ===========================================================================
2. ipconfig 关键内容
C:\Users\user>ipconfig Ethernet adapter PCI: Connection-specific DNS Suffix . : IPv4 Address. . . . . . . . . . . : 192.168.4.110 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.4.84 Ethernet adapter VMware Network Adapter VMnet11: Connection-specific DNS Suffix . : Link-local IPv6 Address . . . . . : fe80::a2e7:a501:ffd5:ccac%7 IPv4 Address. . . . . . . . . . . : 181.0.0.10 Subnet Mask . . . . . . . . . . . : 255.0.0.0 Default Gateway . . . . . . . . . :
3. tracert 针对181.0.0.1的输出
C:\Users\user>tracert -d 181.0.0.1 Tracing route to 181.0.0.1 over a maximum of 30 hops 1 <1 ms 1 ms <1 ms 192.168.4.84 2 1 ms 1 ms <1 ms <public ip> ...
补充测试信息
后来我又做了几组测试,发现更诡异的点:
- ping
181.0.0.2时,收到181.0.0.10返回的「目标主机不可达」,这是我预期的结果(实验室网络里没有这个IP) - 但ping
181.0.0.1时,居然收到了外网的回包,延迟高达400+ms - 查看ARP表,
181.0.0.1和181.0.0.2都没有ARP条目:
C:\Users\user>arp -a 181.0.0.1 No ARP Entries Found. C:\Users\user>arp -a 181.0.0.2 No ARP Entries Found.
我的猜测
现在我怀疑这是Windows系统的「设计特性」?看到一些讨论提到Windows在ARP请求失败时会 fallback 到默认网关,这和常规路由器的行为不太一样。但还是想确认是不是这个原因,或者有没有其他配置问题导致最长前缀匹配没生效?
备注:内容来源于stack exchange,提问作者F.I.V
相关产品推荐
相关产品推荐

