You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Proxmox主机上PiVPN WireGuard LXC容器无法连接问题求助

Proxmox主机上PiVPN WireGuard LXC容器无法连接问题求助

问题描述

我现在碰到个头疼的问题:WireGuard VPN显示连接成功,但既没法访问互联网,也连不上本地局域网里的任何设备。

预期行为

我希望设备连上这个WireGuard VPN后,既能正常浏览网页,也能访问所有同样接入该VPN的设备。

问题复现步骤

  • 在Proxmox主机上运行安装脚本:bash -c "$(wget -qLO - https://github.com/tteck/Proxmox/raw/main/ct/wireguard.sh)"
  • 创建VMID为105的LXC容器,设置静态内部vmbr1 IP为10.0.0.105/32
  • 在Proxmox主机上配置端口转发:iptables -t nat -A PREROUTING -i vmbr0 -p udp --dport 51280 -j DNAT --to 10.0.0.105:51820
  • 编辑/etc/pve/lxc/105.conf,在末尾添加两行配置:
    lxc.cgroup2.devices.allow: c 10:200 rwm
    lxc.mount.entry: /dev/net dev/net none bind,create=dir
    
  • 在Proxmox主机上执行:chown 100000:100000 /dev/net/tun
  • 重启LXC容器(先关机再启动)
  • 用pivpn add添加客户端,再用pivpn -qr生成二维码,设备扫码连接后显示成功,但无法访问任何网络资源

额外环境信息

  • 这是一台根服务器,所有端口均已开放
  • vmbr0绑定eno1网卡,是承载公网IP的互联网连接接口
  • vmbr1为内部局域网接口

已尝试的排查操作

  1. 运行pivpn -d做调试,未检测到错误,调试输出如下:

    ::: Generating Debug Output

    :::: PiVPN debug ::::
    :::: Latest commit ::::
    Branch: master
    Commit: 4032a55c80f25b51419180eda93f44d579ab79e9
    Author: 4s3ti
    Date: Wed Mar 29 14:54:19 2023 +0200
    Summary: docs(issues): Remove old markdown template
    :::: Installation settings ::::
    PLAT=Debian
    OSCN=bullseye
    USING_UFW=0
    pivpnforceipv6route=1
    IPv4dev=eth0
    install_user=root
    install_home=/root
    VPN=wireguard
    pivpnPORT=51820
    pivpnDNS1=1.1.1.1
    pivpnDNS2=8.8.8.8
    pivpnHOST=REDACTED
    INPUT_CHAIN_EDITED=0
    FORWARD_CHAIN_EDITED=0
    INPUT_CHAIN_EDITEDv6=
    FORWARD_CHAIN_EDITEDv6=
    pivpnPROTO=udp
    pivpnMTU=1420
    pivpnPERSISTENTKEEPALIVE=25
    pivpnDEV=wg0
    pivpnNET=10.6.0.0
    subnetClass=24
    pivpnenableipv6=0
    ALLOWED_IPS="0.0.0.0/0, ::0/0"
    UNATTUPG=1
    INSTALLED_PACKAGES=(git dnsutils grepcidr net-tools bsdmainutils iptables-persistent wireguard-tools qrencode linux-headers-amd64 wireguard-dkms unattended-upgrades)

    :::: Server configuration shown below ::::
    [Interface]
    PrivateKey = server_priv
    Address = 10.6.0.1/24
    MTU = 1420
    ListenPort = 51820

    begin t

    [Peer]
    PublicKey = t_pub
    PresharedKey = t_psk
    AllowedIPs = 10.6.0.2/32

    end t

    =============================================
    :::: Client configuration shown below ::::
    [Interface]
    PrivateKey = t_priv
    Address = 10.6.0.2/24
    DNS = 1.1.1.1, 8.8.8.8
    [Peer]
    PublicKey = server_pub
    PresharedKey = t_psk
    Endpoint = REDACTED:51820
    AllowedIPs = 0.0.0.0/0, ::0/0
    PersistentKeepalive = 25
    :::: Recursive list of files in ::::
    :::: /etc/wireguard shown below ::::
    /etc/wireguard:
    configs
    keys
    wg0.conf
    /etc/wireguard/configs:
    clients.txt
    t.conf
    /etc/wireguard/keys:
    server_priv
    server_pub
    t_priv
    t_psk
    t_pub
    :::: Self check ::::
    :: [OK] IP forwarding is enabled
    :: [OK] Iptables MASQUERADE rule set
    :: [OK] WireGuard is running
    :: [OK] WireGuard is enabled
    (it will automatically start on reboot)
    :: [OK] WireGuard is listening on port 51820/udp
    :::: WARNING: This script should have automatically masked sensitive ::::
    :::: information, however, still make sure that PrivateKey, PublicKey ::::
    :::: and PresharedKey are masked before reporting an issue. An example key ::::
    :::: that you should NOT see in this log looks like this: ::::
    :::: YIAoJVsdIeyvXfGGDDadHh6AxsMRymZTnnzZoAb9cxRe ::::

    :::: Debug complete ::::
    :::
    ::: Debug output completed above.
    ::: Copy saved to /tmp/debug.log
    :::

  2. 重启WireGuard服务并检查模块加载:

    systemctl restart wg-quick@wg0
    lsmod | grep wireguard
    

    结果显示模块正常加载:

    wireguard              94208  0
    curve25519_x86_64      36864  1 wireguard
    libchacha20poly1305    16384  1 wireguard
    libcurve25519_generic    49152  2 curve25519_x86_64,wireguard
    ip6_udp_tunnel         16384  1 wireguard
    udp_tunnel             24576  1 wireguard
    
  3. 检查LXC容器eth0接口IP:

    ip -f inet address show eth0
    

    结果显示IP为10.0.0.105/32,和设置一致;后来尝试改成10.0.0.105/24,问题依旧。

  4. 验证公网IP一致性:用curl -s https://checkip.amazonaws.com查询当前公网IP,和pivpnHOST设置一致。

  5. 在Proxmox主机抓包,确认客户端UDP包能到达主机51820端口:

    tcpdump -n -i eno1 udp port 51820
    

    抓包结果显示多个来自客户端公网IP的UDP包成功发送到主机公网IP的51820端口。

  6. 手动编辑/etc/wireguard/wg0.conf添加PostUp/PostDown规则:

    PostUp : iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
    PostDown: iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE
    

    重启容器并重新连接客户端,问题仍未解决。

系统信息

Proxmox主机

  • uname -a输出:
    Linux PXHOST 5.19.17-2-pve #1 SMP PREEMPT_DYNAMIC PVE 5.19.17-2 (Sat, 28 Jan 2023 16:40:25  x86_64 GNU/Linux
    
  • 系统版本:
    PRETTY_NAME="Debian GNU/Linux 11 (bullseye)"
    NAME="Debian GNU/Linux"
    VERSION_ID="11"
    VERSION="11 (bullseye)"
    VERSION_CODENAME=bullseye
    ID=debian
    

WireGuard LXC容器

  • uname -a输出:
    Linux wireguard 5.19.17-2-pve #1 SMP PREEMPT_DYNAMIC PVE 5.19.17-2 (Sat, 28 Jan 2023 16:40:25  x86_64 GNU/Linux
    
  • 系统版本:
    PRETTY_NAME="Debian GNU/Linux 11 (bullseye)"
    NAME="Debian GNU/Linux"
    VERSION_ID="11"
    VERSION="11 (bullseye)"
    VERSION_CODENAME=bullseye
    ID=debian
    

安装与客户端创建过程

安装过程

脚本执行完成后提示成功:

✓ Started LXC Container
+ '[' debian == alpine ']'
++ wget -qLO - https://raw.githubusercontent.com/tteck/Proxmox/main/install/wireguard-install.sh
+ lxc-attach -n 105 -- bash -c '#!/usr/bin/env bash
# Copyright (c) 2021-2023 tteck
# Author: tteck (tteckster)
# License: MIT
# https://github.com/tteck/Proxmox/raw/main/LICENSE
Building dependency tree... Done
Reading state information... Done
0 upgraded, 0 newly installed, 0 to remove and 0 not upgraded.
+ apt-get autoclean
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
+ msg_ok Cleaned
+ local msg=Cleaned
+ echo -e '\r\033[K \033[1;92m✓\033[m \033[1;92mCleaned\033[m'
✓ Cleaned
+ description
++ pct exec 105 ip a s dev eth0
++ awk '/inet / {print $2}'
++ cut -d/ -f1
+ IP=10.0.0.105
+ pct set 105 -description '# Wireguard LXC
### https://tteck.github.io/Proxmox/
<a href='\''https://ko-fi.com/D1D7EP4GF'\''><img src='\''https://img.shields.io/badge/☕-Buy me a coffee-red'\'' /></a>'
+ msg_ok 'Completed Successfully!\n'
+ local 'msg=Completed Successfully!\n'
+ echo -e '\r\033[K \033[1;92m✓\033[m \033[1;92mCompleted Successfully!\n\033[m'
✓ Completed Successfully!

客户端创建

用pivpn add创建名为t的客户端,过程顺利:

pivpn add
Enter a Name for the Client: t
::: Client Keys generated
::: Client config generated
::: Updated server config
::: WireGuard reloaded
======================================================================
::: Done! t.conf successfully created!
::: t.conf was copied to /root/configs for easytransfer.
::: Please use this profile only on one device and create additional
::: profiles for other devices. You can also use pivpn -qr
::: to generate a QR Code you can scan with the mobile app.
======================================================================

备注:内容来源于stack exchange,提问作者mxwmnn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.22 16:19:41