升级Debian 9后多IP LXC容器网络配置异常求助
Hey there, let's work through this Proxmox LXC multi-IP routing issue on Debian 9 together. I’ve dealt with similar OVH + Debian network quirks before, so here’s what’s going on and how to fix it without letting PVE overwrite your configs.
The Root of the Problem
Debian 9 (Stretch) changed how it handles duplicate default routes compared to Debian 8. Your old post-up rules worked on Jessie because the system allowed multiple default routes pointing to the same gateway, but Stretch will silently ignore or reject subsequent duplicate route entries. That’s why only your first IP works—all the other route additions are getting dropped.
Solution 1: Use Proxmox’s interfaces.tail (Safe from Overwrites)
Proxmox lets you append custom configs to /etc/network/interfaces using /etc/network/interfaces.tail—this file won’t be overwritten when PVE restarts or updates network settings. Here’s how to set it up:
- Create/edit the file:
nano /etc/network/interfaces.tail - Add this config (replace
XX.XX.XX.254with your OVH gateway, andeth2with your container’s interface):# Fix multi-IP routing for Debian 9 (OVH setup) iface eth2 inet static # Add routes for all secondary IPs, each tied to their source IP post-up for ip_cidr in $(ip addr show eth2 | grep -oP '(?<=inet\s)\d+(\.\d+){3}/\d+' | tail -n +2); do ip_addr=$(echo $ip_cidr | cut -d '/' -f1) # Use unique metric to avoid route conflicts, tie traffic to the specific IP ip route add default via XX.XX.XX.254 dev eth2 src $ip_addr metric $((100 + $(echo $ip_addr | cut -d '.' -f4))) done # Clean up routes when the interface goes down pre-down for ip_cidr in $(ip addr show eth2 | grep -oP '(?<=inet\s)\d+(\.\d+){3}/\d+' | tail -n +2); do ip_addr=$(echo $ip_cidr | cut -d '/' -f1) ip route del default via XX.XX.XX.254 dev eth2 src $ip_addr done - Save the file and restart your LXC container:
pct restart <container-id>
Solution 2: Custom if-up.d Script (More Flexible)
If you prefer a standalone script that runs when the interface comes up, use the /etc/network/if-up.d/ directory—scripts here execute automatically after an interface is brought online, and PVE won’t touch them.
- Create the script:
nano /etc/network/if-up.d/multi-ip-routing - Paste this content (update gateway and interface as needed):
#!/bin/sh # Only run for our target interface if [ "$IFACE" != "eth2" ]; then exit 0 fi # OVH default gateway GATEWAY="XX.XX.XX.254" # Skip the first IP (our primary) and process all secondary IPs for ip_cidr in $(ip addr show eth2 | grep -oP '(?<=inet\s)\d+(\.\d+){3}/\d+' | tail -n +2); do ip_addr=$(echo $ip_cidr | cut -d '/' -f1) # Add route with source IP binding and unique metric ip route add default via $GATEWAY dev eth2 src $ip_addr metric $((100 + $(echo $ip_addr | cut -d '.' -f4))) done - Make the script executable:
chmod +x /etc/network/if-up.d/multi-ip-routing - Restart the container to apply changes.
Why This Works
By adding the src $ip_addr parameter to each route, we tell the system to use that specific IP for traffic going through the gateway. The unique metric value ensures each route is treated as distinct, so Debian 9 doesn’t reject them as duplicates. This keeps your OVH-required per-IP virtual MACs intact—no need to share a single MAC across all IPs.
Testing the Fix
After restarting, check your route table to confirm all routes exist:
ip route show
Then test each secondary IP to ensure it can reach the internet:
curl --interface <secondary-ip> ifconfig.me
You should see the secondary IP returned as your public address.
内容的提问来源于stack exchange,提问作者luison

