Proxmox主机上PiVPN WireGuard LXC容器无法连接问题求助
问题描述
我现在碰到个头疼的问题:WireGuard VPN显示连接成功,但既没法访问互联网,也连不上本地局域网里的任何设备。
预期行为
我希望设备连上这个WireGuard VPN后,既能正常浏览网页,也能访问所有同样接入该VPN的设备。
问题复现步骤
- 在Proxmox主机上运行安装脚本:
bash -c "$(wget -qLO - https://github.com/tteck/Proxmox/raw/main/ct/wireguard.sh)" - 创建VMID为105的LXC容器,设置静态内部vmbr1 IP为
10.0.0.105/32 - 在Proxmox主机上配置端口转发:
iptables -t nat -A PREROUTING -i vmbr0 -p udp --dport 51280 -j DNAT --to 10.0.0.105:51820 - 编辑
/etc/pve/lxc/105.conf,在末尾添加两行配置:lxc.cgroup2.devices.allow: c 10:200 rwm lxc.mount.entry: /dev/net dev/net none bind,create=dir - 在Proxmox主机上执行:
chown 100000:100000 /dev/net/tun - 重启LXC容器(先关机再启动)
- 用
pivpn add添加客户端,再用pivpn -qr生成二维码,设备扫码连接后显示成功,但无法访问任何网络资源
额外环境信息
- 这是一台根服务器,所有端口均已开放
- vmbr0绑定eno1网卡,是承载公网IP的互联网连接接口
- vmbr1为内部局域网接口
已尝试的排查操作
运行
pivpn -d做调试,未检测到错误,调试输出如下:::: Generating Debug Output
:::: PiVPN debug :::::::: Installation settings ::::
PLAT=Debian
OSCN=bullseye
USING_UFW=0
pivpnforceipv6route=1
IPv4dev=eth0
install_user=root
install_home=/root
VPN=wireguard
pivpnPORT=51820
pivpnDNS1=1.1.1.1
pivpnDNS2=8.8.8.8
pivpnHOST=REDACTED
INPUT_CHAIN_EDITED=0
FORWARD_CHAIN_EDITED=0
INPUT_CHAIN_EDITEDv6=
FORWARD_CHAIN_EDITEDv6=
pivpnPROTO=udp
pivpnMTU=1420
pivpnPERSISTENTKEEPALIVE=25
pivpnDEV=wg0
pivpnNET=10.6.0.0
subnetClass=24
pivpnenableipv6=0
ALLOWED_IPS="0.0.0.0/0, ::0/0"
UNATTUPG=1
INSTALLED_PACKAGES=(git dnsutils grepcidr net-tools bsdmainutils iptables-persistent wireguard-tools qrencode linux-headers-amd64 wireguard-dkms unattended-upgrades):::: Server configuration shown below ::::
[Interface]
PrivateKey = server_priv
Address = 10.6.0.1/24
MTU = 1420
ListenPort = 51820begin t
[Peer]
PublicKey = t_pub
PresharedKey = t_psk
AllowedIPs = 10.6.0.2/32end t
:::: Recursive list of files in ::::
:::: /etc/wireguard shown below ::::
/etc/wireguard:
configs
keys
wg0.conf
/etc/wireguard/configs:
clients.txt
t.conf
/etc/wireguard/keys:
server_priv
server_pub
t_priv
t_psk
t_pub:::: Self check ::::
:: [OK] IP forwarding is enabled
:: [OK] Iptables MASQUERADE rule set
:: [OK] WireGuard is running
:: [OK] WireGuard is enabled
(it will automatically start on reboot)
:: [OK] WireGuard is listening on port 51820/udp:::: Debug complete ::::
:::
::: Debug output completed above.
::: Copy saved to /tmp/debug.log
:::重启WireGuard服务并检查模块加载:
systemctl restart wg-quick@wg0 lsmod | grep wireguard结果显示模块正常加载:
wireguard 94208 0 curve25519_x86_64 36864 1 wireguard libchacha20poly1305 16384 1 wireguard libcurve25519_generic 49152 2 curve25519_x86_64,wireguard ip6_udp_tunnel 16384 1 wireguard udp_tunnel 24576 1 wireguard检查LXC容器eth0接口IP:
ip -f inet address show eth0结果显示IP为
10.0.0.105/32,和设置一致;后来尝试改成10.0.0.105/24,问题依旧。验证公网IP一致性:用
curl -s https://checkip.amazonaws.com查询当前公网IP,和pivpnHOST设置一致。在Proxmox主机抓包,确认客户端UDP包能到达主机51820端口:
tcpdump -n -i eno1 udp port 51820抓包结果显示多个来自客户端公网IP的UDP包成功发送到主机公网IP的51820端口。
手动编辑
/etc/wireguard/wg0.conf添加PostUp/PostDown规则:PostUp : iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE PostDown: iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE重启容器并重新连接客户端,问题仍未解决。
系统信息
Proxmox主机
uname -a输出:Linux PXHOST 5.19.17-2-pve #1 SMP PREEMPT_DYNAMIC PVE 5.19.17-2 (Sat, 28 Jan 2023 16:40:25 x86_64 GNU/Linux- 系统版本:
PRETTY_NAME="Debian GNU/Linux 11 (bullseye)" NAME="Debian GNU/Linux" VERSION_ID="11" VERSION="11 (bullseye)" VERSION_CODENAME=bullseye ID=debian
WireGuard LXC容器
uname -a输出:Linux wireguard 5.19.17-2-pve #1 SMP PREEMPT_DYNAMIC PVE 5.19.17-2 (Sat, 28 Jan 2023 16:40:25 x86_64 GNU/Linux- 系统版本:
PRETTY_NAME="Debian GNU/Linux 11 (bullseye)" NAME="Debian GNU/Linux" VERSION_ID="11" VERSION="11 (bullseye)" VERSION_CODENAME=bullseye ID=debian
安装与客户端创建过程
安装过程
脚本执行完成后提示成功:
✓ Started LXC Container + '[' debian == alpine ']' ++ wget -qLO - https://raw.githubusercontent.com/tteck/Proxmox/main/install/wireguard-install.sh + lxc-attach -n 105 -- bash -c '#!/usr/bin/env bash # Copyright (c) 2021-2023 tteck # Author: tteck (tteckster) # License: MIT # https://github.com/tteck/Proxmox/raw/main/LICENSE Building dependency tree... Done Reading state information... Done 0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded. + apt-get autoclean Reading package lists... Done Building dependency tree... Done Reading state information... Done + msg_ok Cleaned + local msg=Cleaned + echo -e '\r\033[K \033[1;92m✓\033[m \033[1;92mCleaned\033[m' ✓ Cleaned + description ++ pct exec 105 ip a s dev eth0 ++ awk '/inet / {print $2}' ++ cut -d/ -f1 + IP=10.0.0.105 + pct set 105 -description '# Wireguard LXC ### https://tteck.github.io/Proxmox/ <a href='\''https://ko-fi.com/D1D7EP4GF'\''><img src='\''https://img.shields.io/badge/☕-Buy me a coffee-red'\'' /></a>' + msg_ok 'Completed Successfully!\n' + local 'msg=Completed Successfully!\n' + echo -e '\r\033[K \033[1;92m✓\033[m \033[1;92mCompleted Successfully!\n\033[m' ✓ Completed Successfully!
客户端创建
用pivpn add创建名为t的客户端,过程顺利:
pivpn add Enter a Name for the Client: t ::: Client Keys generated ::: Client config generated ::: Updated server config ::: WireGuard reloaded ====================================================================== ::: Done! t.conf successfully created! ::: t.conf was copied to /root/configs for easytransfer. ::: Please use this profile only on one device and create additional ::: profiles for other devices. You can also use pivpn -qr ::: to generate a QR Code you can scan with the mobile app. ======================================================================
备注:内容来源于stack exchange,提问作者mxwmnn

