Proxmox配置VLAN后DHCP响应无法传递至VM的问题求助
Proxmox配置VLAN后DHCP响应无法传递至VM的问题求助
大家好,我最近在服务器上装了Proxmox,现在正在梳理网络配置,但遇到了一个头疼的问题:某个VLAN的DHCP服务器响应能到达Proxmox,但就是传不到VM里,导致VM拿不到IP。下面详细说下我的情况,希望各位大佬能帮忙排查下问题!
需求与网络拓扑
- 从ISP拿到了一个/29子网,用MikroTik RouterOS 7作为主路由
- 目标是给Proxmox里的VM配置两个虚拟网卡:一个走192.168.x.x的内网子网,另一个走ISP分配的/29子网(对应VLAN ID=200)
- 网络拓扑:
ISP <-> Mikrotik路由器 <-> Proxmox服务器 <-> 非管理交换机 <-> 家用设备 - Proxmox里把两个物理网卡桥接成了vmbr0,因为下游的非管理交换机会剥掉VLAN标签,所以桥接是为了统一处理VLAN流量
已完成的Proxmox配置
- 给目标VM新增了一块虚拟网卡,设置VLAN标签为200
- 将vmbr0配置为VLAN感知模式
问题现象与排查过程
- VM的VLAN200网卡始终拿不到IP,但MikroTik后台显示已经分配了DHCP租约
- 用
tcpdump抓包验证流量:- 在Proxmox上抓
vmbr0v200接口的DHCP流量:能正常抓到DHCP Offer包,里面的VM虚拟网卡MAC地址(9a:01:73:ba:ab:15)和分配的45.xxx.xxx.234都是正确的 - 在VM里抓对应网卡(ens19)的流量:只能看到DHCP Discover请求,完全收不到Proxmox那边能抓到的Offer响应
- 在Proxmox上抓
- 对比测试:给VM的内网网卡设置VLAN标签为1(因为路由器会给无VLAN标签的包默认打VLAN1标签),这块网卡能正常收发DHCP请求和响应,IP分配完全正常
补充排查结果
第一次补充:Nmap验证DHCP响应正常
在Proxmox上执行Nmap的DHCP探测脚本:
- 执行
nmap --script broadcast-dhcp-discover -e vmbr0:能收到内网VLAN1的DHCP Offer,参数完全正确 - 执行
nmap --script broadcast-dhcp-discover -e vmbr0v200:能收到VLAN200的DHCP Offer,分配的IP、网关、DNS等信息都符合预期
第二次补充:关键配置文件展示
Proxmox的/etc/network/interfaces配置
# network interface settings; autogenerated # Please do NOT modify this file directly, unless you know what # you're doing. # # If you want to manage parts of the network configuration manually, # please utilize the 'source' or 'source-directory' directives to do # so. # PVE will preserve these directives, but will NOT read its network # configuration from sourced files, so do not attempt to move any of # the PVE managed interfaces into external files! auto lo iface lo inet loopback iface enp99s0f0 inet manual iface enx3a0de3575b59 inet manual iface enp99s0f1 inet manual auto vmbr0 iface vmbr0 inet static address 192.168.88.200/24 gateway 192.168.88.1 bridge-ports enp99s0f0 enp99s0f1 bridge-stp off bridge-fd 0 bridge-vlan-aware yes bridge-vids 2-4094
- 防火墙:Proxmox保持默认配置,未做任何自定义规则,理论上应该放行所有流量
MikroTik关键配置(仅保留相关部分)
/interface vlan add interface=bridge name=vlan-public vlan-id=200 /ip pool add name=dhcp ranges=192.168.88.10-192.168.88.254 add name=dhcp_pool_freedom ranges=45.xxx.xxx.234-45.xxx.xxx.238 /ip dhcp-server add address-pool=dhcp interface=bridge lease-time=10m name=defconf add address-pool=dhcp_pool_freedom interface=vlan-public lease-time=10m name=dhcp-freedom /interface bridge port add bridge=bridge comment=defconf ingress-filtering=no interface=ether5 add bridge=bridge interface=vlan-public /ip neighbor discovery-settings set discover-interface-list=LAN /interface list member add comment=defconf interface=bridge list=LAN /ip address add address=192.168.88.1/24 comment=defconf interface=bridge network=192.168.88.0 add address=45.xxx.xxx.233/29 interface=vlan-public network=45.xxx.xxx.232 /ip dhcp-server network add address=45.xxx.xxx.232/29 dns-server=8.8.8.8,8.8.4.4 gateway=45.xxx.xxx.233 netmask=29 add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1 netmask=24 /ip dns set allow-remote-requests=yes servers=8.8.8.8 /ip dns static add address=192.168.88.1 disabled=yes name=router.lan add address=8.8.8.8 name="Google DNS 1" /ip firewall filter add action=accept chain=forward connection-nat-state=dstnat disabled=yes add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked add action=drop chain=input src-address=!192.168.88.0/24 add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN /ip firewall mangle add action=passthrough chain=prerouting /ip firewall nat add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN src-address=!45.xxx.xxx.232/29 add action=masquerade chain=srcnat out-interface=ether1 /ip route add disabled=no dst-address=0.0.0.0/0 gateway=pppoe-freedom routing-table=to-freedom add disabled=no distance=10 dst-address=0.0.0.0/0 gateway=pppoe-freedom pref-src="" routing-table=main scope=30 suppress-hw-offload=no target-scope=10 add disabled=no distance=1 dst-address=45.xxx.xxx.232/29 gateway=45.xxx.xxx.232 pref-src="" routing-table=main suppress-hw-offload=no
- 备注:ether5是连接Proxmox服务器的物理接口
目前我实在找不到问题出在哪了,明明Proxmox能收到DHCP响应,但就是传不到VM里,有没有大佬遇到过类似的情况,或者能给点排查方向?感激不尽!
备注:内容来源于stack exchange,提问作者NSV
相关产品推荐
相关产品推荐

