Azure Linux虚拟机第二块网卡公网IPv6无法正常通信求助
问题:Azure Ubuntu 22.04多网卡环境下eth1公网IPv6无法正常使用
环境信息
网卡配置
eth0 Mac地址: 00:22:48:8f:ba:bf 私有IPv4地址: 10.0.0.4 公网IPv4地址: 20.25.226.73 私有IPv6地址: abc:abc:abc:abc::6 公网IPv6地址: 2a01:111:f100:1000::9d37:d42b eth1 Mac地址: 00:22:48:8f:64:21 私有IPv4地址: 10.0.0.14 公网IPv4地址: 172.183.16.91 私有IPv6地址: abc:abc:abc:abc::16 公网IPv6地址: 2603:1030:603::324
- 两块网卡均归属虚拟网络子网
10.0.0.0/24和abc:abc:abc:abc::/64 - 防火墙入站规则已开放22/80/443/3389/ICMP端口
现有Netplan配置
当前/etc/netplan/50-cloud-init.yaml配置如下:
network: ethernets: eth0: dhcp4: true dhcp4-overrides: &id001 route-metric: 100 dhcp6: true dhcp6-overrides: *id001 match: driver: hv_netvsc macaddress: 00:22:48:8f:ba:bf set-name: eth0 routes: - to: 10.0.0.0/24 via: 10.0.0.1 metric: 100 table: 200 - to: 0.0.0.0/0 via: 10.0.0.1 table: 200 routing-policy: - from: 10.0.0.4/32 table: 200 - to: 10.0.0.4/32 table: 200 eth1: dhcp4: true dhcp4-overrides: &id002 route-metric: 200 dhcp6: true dhcp6-overrides: *id002 match: driver: hv_netvsc macaddress: 00:22:48:8f:64:21 set-name: eth1 routes: - to: 10.0.0.0/24 via: 10.0.0.1 metric: 200 table: 201 - to: 0.0.0.0/0 via: 10.0.0.1 table: 201 routing-policy: - from: 10.0.0.14/32 table: 201 - to: 10.0.0.14/32 table: 201 version: 2
当前问题现象
- IPv4通信正常:两块网卡可互相ping通,绑定网站无异常
- IPv6通信异常:
- 通过eth0公网IPv4/IPv6登录后,执行
telnet -6 ipv6.telnetmyip.com返回eth0的公网IPv6地址,通信正常 - 通过eth1公网IPv4登录后,执行上述命令仍返回eth0的公网IPv6地址,未使用eth1的公网IPv6
- 通过eth0公网IPv4/IPv6登录后,执行
解决方案:修改Netplan配置
问题根源是现有配置仅对IPv4做了策略路由,未针对IPv6配置对应路由表及策略规则。修改后的完整配置如下:
network: ethernets: eth0: dhcp4: true dhcp4-overrides: &id001 route-metric: 100 dhcp6: true dhcp6-overrides: *id001 match: driver: hv_netvsc macaddress: 00:22:48:8f:ba:bf set-name: eth0 # IPv4路由及策略 routes: - to: 10.0.0.0/24 via: 10.0.0.1 metric: 100 table: 200 - to: 0.0.0.0/0 via: 10.0.0.1 table: 200 routing-policy: - from: 10.0.0.4/32 table: 200 - to: 10.0.0.4/32 table: 200 # 添加IPv6策略路由规则 - from: abc:abc:abc:abc::6/128 table: 200 - to: abc:abc:abc:abc::6/128 table: 200 # 添加IPv6路由表条目 routes6: - to: abc:abc:abc:abc::/64 via: abc:abc:abc:abc::1 metric: 100 table: 200 - to: ::/0 via: abc:abc:abc:abc::1 table: 200 eth1: dhcp4: true dhcp4-overrides: &id002 route-metric: 200 dhcp6: true dhcp6-overrides: *id002 match: driver: hv_netvsc macaddress: 00:22:48:8f:64:21 set-name: eth1 # IPv4路由及策略 routes: - to: 10.0.0.0/24 via: 10.0.0.1 metric: 200 table: 201 - to: 0.0.0.0/0 via: 10.0.0.1 table: 201 routing-policy: - from: 10.0.0.14/32 table: 201 - to: 10.0.0.14/32 table: 201 # 添加IPv6策略路由规则 - from: abc:abc:abc:abc::16/128 table: 201 - to: abc:abc:abc:abc::16/128 table: 201 # 添加IPv6路由表条目 routes6: - to: abc:abc:abc:abc::/64 via: abc:abc:abc:abc::1 metric: 200 table: 201 - to: ::/0 via: abc:abc:abc:abc::1 table: 201 version: 2
配置说明
- 添加IPv6路由表(routes6):为每块网卡的IPv6配置子网路由和默认路由,指定对应的路由表(eth0用200,eth1用201),网关为子网的IPv6默认网关
abc:abc:abc:abc::1 - 添加IPv6策略路由规则:在
routing-policy中补充基于网卡私有IPv6地址的源/目的规则,确保从eth1发出的IPv6流量使用eth1对应的路由表,返回流量也导向eth1
应用配置步骤
- 保存修改后的配置文件
- 执行命令应用配置:
sudo netplan apply - 验证路由规则:
ip -6 rule show ip -6 route show table 200 ip -6 route show table 201 - 使用
telnet -6 ipv6.telnetmyip.com测试eth1的公网IPv6是否正常
内容的提问来源于stack exchange,提问作者Edward Zhou
相关产品推荐
相关产品推荐

