如何通过Ubuntu 16.04路由器为多个802.1Q VLAN配置互联网访问?
Alright, let's walk through setting up internet access for your VLANs on Ubuntu 16.04 step by step. I've tackled this exact scenario multiple times, so here's the practical, tested workflow I'd use:
Ubuntu 16.04 doesn't include 802.1Q VLAN support by default, so first we'll add the necessary packages and kernel module:
sudo apt-get update && sudo apt-get install vlan sudo modprobe 8021q
To ensure the VLAN module loads automatically on boot, add it to your modules list:
echo "8021q" | sudo tee -a /etc/modules
Next, we'll define the tagged VLAN interfaces on ens1f1. Open /etc/network/interfaces with your editor of choice (nano, vim, etc.) and append these sections for each VLAN:
# Main physical interface (no IP assigned here—we'll use sub-interfaces) auto ens1f1 iface ens1f1 inet manual # VLAN 10 auto ens1f1.10 iface ens1f1.10 inet static address 192.168.10.1 netmask 255.255.255.0 vlan-raw-device ens1f1 # VLAN 20 auto ens1f1.20 iface ens1f1.20 inet static address 192.168.20.1 netmask 255.255.255.0 vlan-raw-device ens1f1 # VLAN 30 auto ens1f1.30 iface ens1f1.30 inet static address 192.168.30.1 netmask 255.255.255.0 vlan-raw-device ens1f1 # VLAN 40 auto ens1f1.40 iface ens1f1.40 inet static address 192.168.40.1 netmask 255.255.255.0 vlan-raw-device ens1f1
Note: Adjust the IP subnets to match your network plan—just ensure each VLAN uses a unique private IP range.
For the router to route traffic between VLANs and the internet, we need to enable IPv4 forwarding. Edit /etc/sysctl.conf and uncomment this line:
net.ipv4.ip_forward=1
Apply the change right away with:
sudo sysctl -p
Since your upstream ISP device doesn't support VLANs, we'll use SNAT (Source Network Address Translation) to masquerade all VLAN traffic behind your static public IP. Run this command (replace YOUR_STATIC_PUBLIC_IP with the actual IP provided by your ISP):
sudo iptables -t nat -A POSTROUTING -o enp0s25 -j SNAT --to-source YOUR_STATIC_PUBLIC_IP
To make these iptables rules persist after a reboot, install iptables-persistent:
sudo apt-get install iptables-persistent
When prompted, select "Yes" to save your current IPv4 rules. You can manually save rules anytime with:
sudo iptables-save > /etc/iptables/rules.v4
To ensure traffic flows correctly between VLANs and the internet, add these rules to allow outbound traffic and related inbound responses:
# Allow established/return traffic from the internet to VLANs sudo iptables -A FORWARD -i enp0s25 -o ens1f1.* -m state --state RELATED,ESTABLISHED -j ACCEPT # Allow all outbound traffic from VLANs to the internet sudo iptables -A FORWARD -i ens1f1.* -o enp0s25 -j ACCEPT
Don't forget to save the updated rules again with sudo iptables-save > /etc/iptables/rules.v4.
Restart the networking service to apply all changes:
sudo systemctl restart networking
Now verify connectivity from a device on one of your VLANs:
- Ping the VLAN gateway (e.g.,
192.168.10.1for VLAN 10) to confirm local network access. - Ping a public IP like
8.8.8.8to check internet connectivity. - Verify NAT rules are active with
sudo iptables -t nat -L -n.
If everything works, you're good to go! If you hit issues, double-check that VLAN tags match between your switch and router, and confirm your static public IP is correctly assigned to enp0s25.
内容的提问来源于stack exchange,提问作者Kevin Anderson

