You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenWRT下通过DHCP获取ISP双公网IP的配置问题问询

配置方案说明

核心疑问解答

混杂模式开启对象

仅需为WAN侧VLAN子接口eth0.2开启混杂模式即可,无需操作物理接口eth0。所有ISP下发的公网流量都携带WAN侧VLAN标签,只会被转发到eth0.2,给物理接口开混杂会额外收到LAN侧流量,属于冗余操作,还会产生不必要的性能开销。

现有思路校验

整体思路完全正确,无需手动配置流量转发规则,直接使用Linux内核原生的macvlan功能即可实现需求:macvlan可以在父接口上生成携带独立MAC地址的虚拟接口,父接口开启混杂模式后,内核会自动将对应目标MAC的二层流量转发到匹配的macvlan接口,无需额外调整转发规则。

具体操作步骤

临时测试配置(重启后失效,用于快速验证可行性)

  1. 给eth0.2开启混杂模式
ip link set eth0.2 promisc on
  1. 创建名为wan2的macvlan虚拟接口,父接口指定为eth0.2
ip link add link eth0.2 name wan2 type macvlan mode bridge
  1. 启用wan2接口
ip link set wan2 up
  1. 对wan2发起DHCP请求,验证是否能获取到第二个公网IP
udhcpc -i wan2

测试IP获取正常、公网访问无问题后,可配置永久规则。

OpenWRT永久配置

  1. 编辑网络配置文件/etc/config/network,添加以下内容:
config interface 'wan2'
    option proto 'dhcp'
    option ifname 'wan2'
    # 可选:自定义MAC地址,不配置则系统自动生成
    # option macaddr 'xx:xx:xx:xx:xx:xx'

config device
    option name 'wan2'
    option type 'macvlan'
    option ifname 'eth0.2'
    option mode 'bridge'
    option promisc '1'
  1. 编辑防火墙配置文件/etc/config/firewall,将wan2接口划入WAN区域:
    找到name为wan的zone配置段,修改network字段,添加wan2:
config zone
    option name 'wan'
    option input 'REJECT'
    option output 'ACCEPT'
    option forward 'REJECT'
    option masq '1'
    option mtu_fix '1'
    option network 'wan wan2'
  1. 重启服务生效:
/etc/init.d/network restart
/etc/init.d/firewall restart

提示:如果需要将第二个公网IP的流量映射到内网指定服务器,配置DNAT规则时指定入站接口为wan2即可。

内容的提问来源于stack exchange,提问作者Hackerman21

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.24 15:54:05