You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

QEMU虚拟机无法访问主机直连树莓派的私有子网求助

问题:QEMU虚拟机无法访问直连的树莓派

环境概述

  • 主机系统:Ubuntu 24.04,已部署QEMU虚拟机(VM),VM同样运行Ubuntu 24.04,初始运行正常
  • 网络拓扑:主机通过网线直连树莓派(无路由器),生成子网10.42.0.0/24,其中主机IP为10.42.0.1,树莓派IP为10.42.0.4;VM通过virbr0网桥连接到192.168.122.0/24子网
  • 通信现状:主机与树莓派可互ping;VM无法ping通树莓派(返回"Destination Port Unreachable"),树莓派也无法访问VM
  • 已确认信息:主机已启用net.ipv4.ip_forward,IPv6已通过ip6tables拦截禁用;树莓派到VM的通信被iptables FORWARD链阻挡(可通过调整该链解决),但VM到树莓派的通信未触发任何iptables拒绝规则(规则计数均为0),无法定位阻塞原因

主机路由表

$ route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         172.20.10.1     0.0.0.0         UG    600    0        0 wlo1
10.42.0.0       0.0.0.0         255.255.255.0   U     100    0        0 eno2
172.20.10.0     0.0.0.0         255.255.255.240 U     600    0        0 wlo1
192.168.122.0   0.0.0.0         255.255.255.0   U     0      0        0 virbr0
$ 

主机iptables FORWARD链相关规则

$ sudo iptables -L FORWARD -v
Chain FORWARD (policy ACCEPT 559 packets, 45927 bytes)
 pkts bytes target     prot opt in     out     source               destination         
  559 45927 LIBVIRT_FWX  all  --  any    any     anywhere             anywhere            
  559 45927 LIBVIRT_FWI  all  --  any    any     anywhere             anywhere            
  559 45927 LIBVIRT_FWO  all  --  any    any     anywhere             anywhere            
$ sudo iptables -L LIBVIRT_FWX -v
Chain LIBVIRT_FWX (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  virbr0 virbr0  anywhere             anywhere            
$ sudo iptables -L LIBVIRT_FWI -v
Chain LIBVIRT_FWI (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  any    virbr0  anywhere             192.168.122.0/24     ctstate RELATED,ESTABLISHED
    0     0 REJECT     all  --  any    virbr0  anywhere             anywhere             reject-with icmp-port-unreachable
$ sudo iptables -L LIBVIRT_FWO -v
Chain LIBVIRT_FWO (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 ACCEPT     all  --  virbr0 any     192.168.122.0/24     anywhere            
    0     0 REJECT     all  --  virbr0 any     anywhere             anywhere             reject-with icmp-port-unreachable
$ 

需求

提供允许VM访问树莓派的解决思路,重点排查VM到树莓派通信的阻塞点(非iptables拒绝规则触发)。

内容的提问来源于stack exchange,提问作者yty

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 21:07:03