You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Site-to-Site WireGuard VPN单向无法发起握手问题求助

Site-to-Site WireGuard VPN单向无法发起握手问题求助

我正在尝试在SiteA(OpenWrt路由器)和SiteB(带公网IP的Oracle实例)之间搭建Site-to-Site WireGuard VPN。SiteA这边用的是OpenWrt的GUI配置,配置截图如下:

  • OpenWRT_Server_Conf_Screenshot
  • OpenWRT_Peer_Conf_Screenshot

以下是SiteA的wg showconf输出:

[Interface]
ListenPort = 51821
PrivateKey = REDACTED

[Peer]
PublicKey = BY...Cwo=
AllowedIPs = 10.2.0.0/16, 192.168.100.0/30
Endpoint = SITE_B_PUBLIC_IP:51821

SiteB的配置内容如下:

[Interface]
Address = 192.168.100.2/30
ListenPort = 51821
PrivateKey = REDACTED
PostUp = iptables -A FORWARD -i %i -j ACCEPT; iptables -t nat -A POSTROUTING -o  enp0s3 -j MASQUERADE
PostDown = iptables -D FORWARD -i %i -j ACCEPT; iptables -t nat -D POSTROUTING -o enp0s3 -j MASQUERADE

[Peer]
PublicKey = ZX...z4=
AllowedIPs = 192.168.100.0/30, 172.16.1.0/24, 172.16.255.0/24
Endpoint = SITE_A_PUBLIC_IP:51821

我遇到了一个非常奇怪的问题:从SiteB ping SiteA的任意地址,隧道能正常建立,两者之间通信完全没问题;但如果事先没有从SiteB发起连接,我从SiteA ping SiteB根本行不通。我能看到SiteA有51821端口的流量发往SiteB,猜测是握手包,但SiteB的WireGuard好像完全不响应这些请求。

SiteB上执行tcpdump -v port 51821的输出:

root@ubuntu:~# tcpdump -v port 51821
tcpdump: listening on enp0s3, link-type EN10MB (Ethernet), snapshot length 262144 bytes
09:23:59.004307 IP (tos 0x20, ttl 49, id 2251, offset 0, flags [none], proto UDP (17), length 176)
SITE_A_PUBLIC_IP.51821 > SITE_B_PUBLIC_IP.51821: UDP, length 148
09:24:04.052134 IP (tos 0x20, ttl 49, id 2467, offset 0, flags [none], proto UDP (17), length 176)
SITE_A_PUBLIC_IP.51821 > SITE_B_PUBLIC_IP.51821: UDP, length 148
09:24:09.102989 IP (tos 0x20, ttl 49, id 2658, offset 0, flags [none], proto UDP (17), length 176)
SITE_A_PUBLIC_IP.51821 > SITE_B_PUBLIC_IP.51821: UDP, length 148
09:24:14.152403 IP (tos 0x20, ttl 49, id 2769, offset 0, flags [none], proto UDP (17), length 176)
SITE_A_PUBLIC_IP.51821 > SITE_B_PUBLIC_IP.51821: UDP, length 148
09:24:19.202805 IP (tos 0x20, ttl 49, id 3187, offset 0, flags [none], proto UDP (17), length 176)

我已经开启了WireGuard的调试模式,但没看到相关的有效日志,日志内容如下:

Jan 09 09:31:14 ubuntu wg-quick[868]: [#] ip link add wgA type wireguard
Jan 09 09:31:14 ubuntu kernel: wireguard: WireGuard 1.0.0 loaded. See www.wireguard.com for information.
Jan 09 09:31:14 ubuntu kernel: wireguard: Copyright (C) 2015-2019 Jason A. Donenfeld <Jason@zx2c4.com>. All Rights Reserved.
Jan 09 09:31:15 ubuntu wg-quick[868]: [#] wg set wgA private-key /etc/wireguard/wgA.key

备注:内容来源于stack exchange,提问作者Teacup

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 13:39:06