OpenWRT下通过DHCP获取ISP双公网IP的配置问题问询
配置方案说明
核心疑问解答
混杂模式开启对象
仅需为WAN侧VLAN子接口eth0.2开启混杂模式即可,无需操作物理接口eth0。所有ISP下发的公网流量都携带WAN侧VLAN标签,只会被转发到eth0.2,给物理接口开混杂会额外收到LAN侧流量,属于冗余操作,还会产生不必要的性能开销。
现有思路校验
整体思路完全正确,无需手动配置流量转发规则,直接使用Linux内核原生的macvlan功能即可实现需求:macvlan可以在父接口上生成携带独立MAC地址的虚拟接口,父接口开启混杂模式后,内核会自动将对应目标MAC的二层流量转发到匹配的macvlan接口,无需额外调整转发规则。
具体操作步骤
临时测试配置(重启后失效,用于快速验证可行性)
- 给eth0.2开启混杂模式
ip link set eth0.2 promisc on
- 创建名为wan2的macvlan虚拟接口,父接口指定为eth0.2
ip link add link eth0.2 name wan2 type macvlan mode bridge
- 启用wan2接口
ip link set wan2 up
- 对wan2发起DHCP请求,验证是否能获取到第二个公网IP
udhcpc -i wan2
测试IP获取正常、公网访问无问题后,可配置永久规则。
OpenWRT永久配置
- 编辑网络配置文件
/etc/config/network,添加以下内容:
config interface 'wan2' option proto 'dhcp' option ifname 'wan2' # 可选:自定义MAC地址,不配置则系统自动生成 # option macaddr 'xx:xx:xx:xx:xx:xx' config device option name 'wan2' option type 'macvlan' option ifname 'eth0.2' option mode 'bridge' option promisc '1'
- 编辑防火墙配置文件
/etc/config/firewall,将wan2接口划入WAN区域:
找到name为wan的zone配置段,修改network字段,添加wan2:
config zone option name 'wan' option input 'REJECT' option output 'ACCEPT' option forward 'REJECT' option masq '1' option mtu_fix '1' option network 'wan wan2'
- 重启服务生效:
/etc/init.d/network restart /etc/init.d/firewall restart
提示:如果需要将第二个公网IP的流量映射到内网指定服务器,配置DNAT规则时指定入站接口为
wan2即可。
内容的提问来源于stack exchange,提问作者Hackerman21
相关产品推荐
相关产品推荐

