You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Proxmox配置VLAN后DHCP响应无法传递至VM的问题求助

Proxmox配置VLAN后DHCP响应无法传递至VM的问题求助

大家好,我最近在服务器上装了Proxmox,现在正在梳理网络配置,但遇到了一个头疼的问题:某个VLAN的DHCP服务器响应能到达Proxmox,但就是传不到VM里,导致VM拿不到IP。下面详细说下我的情况,希望各位大佬能帮忙排查下问题!

需求与网络拓扑

  • 从ISP拿到了一个/29子网,用MikroTik RouterOS 7作为主路由
  • 目标是给Proxmox里的VM配置两个虚拟网卡:一个走192.168.x.x的内网子网,另一个走ISP分配的/29子网(对应VLAN ID=200)
  • 网络拓扑:ISP <-> Mikrotik路由器 <-> Proxmox服务器 <-> 非管理交换机 <-> 家用设备
  • Proxmox里把两个物理网卡桥接成了vmbr0,因为下游的非管理交换机会剥掉VLAN标签,所以桥接是为了统一处理VLAN流量

已完成的Proxmox配置

  • 给目标VM新增了一块虚拟网卡,设置VLAN标签为200
  • 将vmbr0配置为VLAN感知模式

问题现象与排查过程

  • VM的VLAN200网卡始终拿不到IP,但MikroTik后台显示已经分配了DHCP租约
  • 用tcpdump抓包验证流量:
    • 在Proxmox上抓vmbr0v200接口的DHCP流量:能正常抓到DHCP Offer包,里面的VM虚拟网卡MAC地址(9a:01:73:ba:ab:15)和分配的45.xxx.xxx.234都是正确的
    • 在VM里抓对应网卡(ens19)的流量:只能看到DHCP Discover请求,完全收不到Proxmox那边能抓到的Offer响应
  • 对比测试:给VM的内网网卡设置VLAN标签为1(因为路由器会给无VLAN标签的包默认打VLAN1标签),这块网卡能正常收发DHCP请求和响应,IP分配完全正常

补充排查结果

第一次补充:Nmap验证DHCP响应正常

在Proxmox上执行Nmap的DHCP探测脚本:

  • 执行nmap --script broadcast-dhcp-discover -e vmbr0:能收到内网VLAN1的DHCP Offer,参数完全正确
  • 执行nmap --script broadcast-dhcp-discover -e vmbr0v200:能收到VLAN200的DHCP Offer,分配的IP、网关、DNS等信息都符合预期

第二次补充:关键配置文件展示

Proxmox的/etc/network/interfaces配置

# network interface settings; autogenerated
# Please do NOT modify this file directly, unless you know what
# you're doing.
#
# If you want to manage parts of the network configuration manually,
# please utilize the 'source' or 'source-directory' directives to do
# so.
# PVE will preserve these directives, but will NOT read its network
# configuration from sourced files, so do not attempt to move any of
# the PVE managed interfaces into external files!

auto lo
iface lo inet loopback

iface enp99s0f0 inet manual

iface enx3a0de3575b59 inet manual

iface enp99s0f1 inet manual

auto vmbr0
iface vmbr0 inet static
        address 192.168.88.200/24
        gateway 192.168.88.1
        bridge-ports enp99s0f0 enp99s0f1
        bridge-stp off
        bridge-fd 0
        bridge-vlan-aware yes
        bridge-vids 2-4094
  • 防火墙:Proxmox保持默认配置,未做任何自定义规则,理论上应该放行所有流量

MikroTik关键配置(仅保留相关部分)

/interface vlan
add interface=bridge name=vlan-public vlan-id=200

/ip pool
add name=dhcp ranges=192.168.88.10-192.168.88.254
add name=dhcp_pool_freedom ranges=45.xxx.xxx.234-45.xxx.xxx.238

/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=10m name=defconf
add address-pool=dhcp_pool_freedom interface=vlan-public lease-time=10m name=dhcp-freedom

/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether5
add bridge=bridge interface=vlan-public

/ip neighbor discovery-settings
set discover-interface-list=LAN

/interface list member
add comment=defconf interface=bridge list=LAN

/ip address
add address=192.168.88.1/24 comment=defconf interface=bridge network=192.168.88.0
add address=45.xxx.xxx.233/29 interface=vlan-public network=45.xxx.xxx.232

/ip dhcp-server network
add address=45.xxx.xxx.232/29 dns-server=8.8.8.8,8.8.4.4 gateway=45.xxx.xxx.233 netmask=29
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1 netmask=24

/ip dns
set allow-remote-requests=yes servers=8.8.8.8

/ip dns static
add address=192.168.88.1 disabled=yes name=router.lan
add address=8.8.8.8 name="Google DNS 1"

/ip firewall filter
add action=accept chain=forward connection-nat-state=dstnat disabled=yes
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input src-address=!192.168.88.0/24
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf:  drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN

/ip firewall mangle
add action=passthrough chain=prerouting

/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN src-address=!45.xxx.xxx.232/29
add action=masquerade chain=srcnat out-interface=ether1

/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=pppoe-freedom routing-table=to-freedom
add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=pppoe-freedom pref-src="" routing-table=main scope=30 suppress-hw-offload=no target-scope=10
add disabled=no distance=1 dst-address=45.xxx.xxx.232/29 gateway=45.xxx.xxx.232 pref-src="" routing-table=main suppress-hw-offload=no
  • 备注:ether5是连接Proxmox服务器的物理接口

目前我实在找不到问题出在哪了,明明Proxmox能收到DHCP响应,但就是传不到VM里,有没有大佬遇到过类似的情况,或者能给点排查方向?感激不尽!

备注:内容来源于stack exchange,提问作者NSV

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 07:43:09