You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于WireGuard隧道IP子网掩码作用的技术问询

关于WireGuard隧道IP子网掩码作用的技术问询

最近折腾WireGuard的时候发现个有意思的点——哪怕不设置隧道IP地址,只配好AllowedIPs、端点地址还有公私钥,WireGuard居然也能正常跑起来。但像OpnSense和pfSense这类防火墙的文档里,却对隧道IP的子网掩码有明确要求,这就让我有点摸不着头脑了,想跟大家唠唠这事儿。

先看看相关文档里的说法:

OpnSense的警告

Note: The tunnel address must be in CIDR notation and must be a unique IP
and subnet for your network. [..] Do not use a tunnel
address that is a /32 (IPv4) or a /128 (IPv6)

pfSense的相关解释

Note: Routes are not automatically created in the system routing table.
Routes for networks other than the tunnel network itself must be
configured separately using static or dynamic routes.

我在网上搜了半天,找到的相关讨论大多是基础的子网掩码疑问,比如Reddit上的「子网掩码困惑」、「VPN服务器中/24和/32的区别」、「/8、/16这些掩码到底用来干嘛」,都没找到直接针对WireGuard隧道IP子网掩码作用的清晰答案。

为了搞明白,我自己也做了些测试,结果发现子网掩码好像没什么实际功能:

  • 和本地流量路由无关:不管子网掩码是否包含所有连接的节点,路由到第二个peer都能正常工作
  • 和「流量留在接口」还是「走内核转发」无关:两种情况下我都能用防火墙规则正常控制流量

所以想请教各位大佬,WireGuard隧道IP里的子网掩码到底有什么作用?

备注:内容来源于stack exchange,提问作者Georg Schölly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 07:55:28