You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

WireGuard握手期间Mac客户端周期性断网问题排查求助

WireGuard握手期间Mac客户端周期性断网问题排查求助

大家好,我遇到了一个非常诡异的WireGuard周期性断网问题,折腾了好久没找到根源,想请各位帮忙排查一下:

环境说明

  • 服务端:Debian主机上运行linuxserver.io的WireGuard容器
  • 客户端:MacBook

核心问题现象

连接本身稳定性和速度都没问题,但每隔10-20分钟就会触发一次外网断网:

  • 断网时仍能正常访问服务端内网服务,说明WireGuard链路本身没有中断
  • 外网完全无法访问,持续约16秒,直到下一次握手完成后立刻恢复
  • 不管是大流量下载(比如BT)还是普通网页浏览,都会触发这个问题
  • 已确认VPS本身网络正常(持续ping谷歌全程通),只有Mac客户端出现断网

服务端异常观察

当有大流量传输时,服务端会出现大量kworker/1:1-wg-crypt-wg0进程;断网发生时这些进程会被全部杀死,但WireGuard服务并没有重启(内网服务仍可访问)。

配置文件

服务端配置

[Interface]
# Core settings
PrivateKey = xxxxx
Address = 10.6.0.0/24
# Misc. settings (optional)
ListenPort = 51820
# Interface hooks (optional)
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -A FORWARD -o %i -j ACCEPT; iptables -t nat -A POSTROUTING -o eth+ -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -D FORWARD -o %i -j ACCEPT; iptables -t nat -D POSTROUTING -o eth+ -j MASQUERADE
MTU = 1400

# Peers
[Peer]
PublicKey = xxxxx
PresharedKey = xxxx
AllowedIPs = 10.6.0.2/32
PersistentKeepalive = 16

MacBook客户端配置

[Interface]
# Core settings
PrivateKey = xxxxx
Address = 10.6.0.2/32
# Misc. settings (optional)
DNS = xxxxx
MTU = 1400

[Peer]
PublicKey = xxxx
Endpoint = xxxx:51820
AllowedIPs = 10.6.0.1/32, 0.0.0.0/0
PresharedKey = xxxx
PersistentKeepalive = 16

日志分析(更新1)

服务端内核日志(加载wireguard模块后)

Mar 16 13:55:54 [  +2.156106] wireguard: wg0: Receiving handshake initiation from peer 315 (<my-client-ip>:16235)
Mar 16 13:55:54 [  +0.000003] wireguard: wg0: Sending handshake response to peer 315 (<my-client-ip>)
Mar 16 13:55:54 [  +0.000165] wireguard: wg0: Keypair 10604 destroyed for peer 315
Mar 16 13:55:54 [  +0.000002] wireguard: wg0: Keypair 10606 created for peer 315
Mar 16 13:56:10 [  +2.451426] wireguard: wg0: Receiving handshake initiation from peer 315 (<my-client-ip>)
Mar 16 13:56:10 [  +0.000003] wireguard: wg0: Sending handshake response to peer 315 (<my-client-ip>)
Mar 16 13:56:10 [  +0.000185] wireguard: wg0: Keypair 10605 destroyed for peer 315
Mar 16 13:56:10 [  +0.000001] wireguard: wg0: Keypair 10607 created for peer 315
Mar 16 13:56:10 [  +0.161195] wireguard: wg0: Receiving keepalive packet from peer 315 (<my-client-ip>)

客户端ping谷歌日志

Mar 16 10:55:54 64 bytes from <google-ip>: icmp_seq=187 ttl=108 time=161.723 ms
Mar 16 10:55:56 Request timeout for icmp_seq 188
...(连续16个请求超时)
Mar 16 10:56:11 64 bytes from <google-ip>: icmp_seq=204 ttl=108 time=161.172 ms

两次握手的时间窗口正好对应客户端断网的16秒

客户端日志分析(更新2)

通过执行sudo LOG_LEVEL=verbose wg show获取客户端详细日志,发现关键异常:

DEBUG: (utun6) 2023/03/16 13:46:35 peer(xxxx) - Sending handshake initiation
DEBUG: (utun6) 2023/03/16 13:46:35 peer(xxxx) - Received handshake response
DEBUG: (utun6) 2023/03/16 13:46:35 peer(xxxx) - Sending keepalive packet
DEBUG: (utun6) 2023/03/16 13:47:24 peer(xxxx) - Retrying handshake because we stopped hearing back after 15 seconds
DEBUG: (utun6) 2023/03/16 13:47:24 peer(xxxx) - Sending handshake initiation
DEBUG: (utun6) 2023/03/16 13:47:24 peer(xxxx) - Received handshake response
DEBUG: (utun6) 2023/03/16 13:47:24 peer(xxxx) - Sending keepalive packet

断网正好发生在客户端提示“15秒没收到响应,重试握手”的时间段,重试完成后网络立刻恢复

最新线索(更新3)

发现客户端握手使用的端口存在异常切换:

  • 服务端通过watch wg show all观察到,客户端正常通信的端口是<my-ip>:16918
  • 断网触发时,服务端收到的握手请求来自不同的随机端口(比如:16235),服务端会响应到这个新端口,但客户端似乎没有监听该端口:
Mar 16 18:17:19 [  +1.217668] wireguard: wg0: Receiving handshake initiation from peer 318 (<client-ip>:16235)
Mar 16 18:17:19 [  +0.000004] wireguard: wg0: Sending handshake response to peer 318 (<client-ip>:16235)
Mar 16 18:17:19 [  +0.000191] wireguard: wg0: Keypair 10893 destroyed for peer 318
Mar 16 18:17:19 [  +0.000002] wireguard: wg0: Keypair 10896 created for peer 318
Mar 16 18:17:19 [  +0.275182] wireguard: wg0: Receiving keepalive packet from peer 318 (<client-ip>:16235)
Mar 16 18:17:34 [  +0.687921] wireguard: wg0: Receiving handshake initiation from peer 318 (<client-ip>:16918)
Mar 16 18:17:34 [  +0.000004] wireguard: wg0: Sending handshake response to peer 318 (<client-ip>:16918)
Mar 16 18:17:34 [  +0.000250] wireguard: wg0: Keypair 10894 destroyed for peer 318
Mar 16 18:17:34 [  +0.000002] wireguard: wg0: Keypair 10897 created for peer 318
Mar 16 18:17:34 [  +0.164268] wireguard: wg0: Receiving keepalive packet from peer 318 (<client-ip>:16918)

求助方向

目前我怀疑可能是路由器NAT端口映射超时问题?或者WireGuard的MTU/Keepalive参数配置不合理?也有可能是Mac客户端的WireGuard实现存在端口复用的bug?

想请教各位:

  • 这个端口随机切换导致的握手异常是不是问题的核心原因?
  • 应该从哪些方向进一步排查?比如路由器的NAT超时设置、客户端的端口复用机制?
  • 有没有针对性的配置调整建议可以尝试?

备注:内容来源于stack exchange,提问作者Lorenzo Piccoli Módolo

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 10:14:34