技术求助:DHCP服务器向WAN接口客户端分配租约问题(附配置)
Hey there, let's work through your DHCP lease problem step by step. First, let's recap your network setup to align on context:
- Network topology:
Modem ---> Router ---> Router (192.168.1.1) ---> Wireless Bridge (DD-WRT, static 192.168.1.254) ---> Proxmox Server (static 192.168.1.101) - Proxmox bridges:
vmbr0(bridged to eth0, connected to wireless bridge) andvmbr1(unconfigured) - Proxmox VMs: CentOS 7, Debian stable, pfSense 2.4.x
Based on your description of DHCP issues related to WAN interface clients, here are targeted troubleshooting steps:
1. Verify pfSense Interface & DHCP Configurations
First, confirm your pfSense setup maps correctly to your Proxmox bridges:
- Log into pfSense's web UI, go to Interfaces > Assignments to ensure:
vmbr0is assigned as your WAN interface (since this connects to your upstream network)vmbr1is assigned as your LAN interface (you'll need to configure this if it's empty—assign a static IP like192.168.2.1/24here for your internal VM network)
- Check DHCP server settings:
- If your pfSense WAN is supposed to act as a DHCP client (to get an IP from your upstream 192.168.1.1 router), go to Interfaces > WAN and confirm "DHCP" is selected as the IPv4 configuration type.
- If you're seeing pfSense's DHCP server accidentally assigning leases to WAN-side devices, go to Services > DHCP Server and ensure the DHCP service is only enabled for your LAN interface (not WAN).
2. Test Network Connectivity & Bridge Paths
Let's rule out physical/bridge-level connectivity issues:
- On your Proxmox host, run these commands to confirm it can reach upstream devices:
If these fail, check your wireless bridge (DD-WRT) settings: disable AP isolation if enabled, and ensure bridge mode is properly configured to pass all traffic (including DHCP broadcasts).ping 192.168.1.1 # Upstream router ping 192.168.1.254 # Wireless bridge - In pfSense, open the Diagnostics > Ping tool and ping
192.168.1.1from the WAN interface. If this fails, double-check your Proxmoxvmbr0configuration (it should be a simple bridge to eth0 without extra VLAN filters).
3. Capture DHCP Traffic to Diagnose Handshakes
To see exactly what's happening with DHCP packets, use packet capture on pfSense:
- Go to Diagnostics > Packet Capture and configure it for your WAN interface, with filter
port 67 or port 68(DHCP uses these ports). - Start the capture, then renew the WAN interface's DHCP lease (Interfaces > WAN > Renew DHCP Lease).
- Stop the capture and look for:
DHCP Discoverpackets from pfSense's WAN IPDHCP Offerpackets from your upstream 192.168.1.1 router
If you don't see Offers, your upstream router isn't responding—check if it's set to block DHCP requests from the wireless bridge segment. If you see Offers but no final ACK, there might be a firewall rule blocking traffic on pfSense's WAN.
4. Check Proxmox Bridge Configuration
Ensure your Proxmox bridges are set up correctly by checking /etc/network/interfaces:
- Run this command on Proxmox to view the config:
Yourcat /etc/network/interfacesvmbr0should look something like this (static IP matching your setup):
Forauto vmbr0 iface vmbr0 inet static address 192.168.1.101/24 gateway 192.168.1.1 bridge-ports eth0 bridge-stp off bridge-fd 0vmbr1, if you're using it for LAN, add a static IP in a separate subnet (e.g.,192.168.2.1/24) and ensure bridge-ports is set to none (since it's for VMs only).
5. Review pfSense DHCP Logs
Logs are your best friend for pinpointing errors:
- In pfSense, go to Status > System Logs > DHCP to view DHCP-related events. Look for messages like:
No DHCPOFFERS received(indicates upstream isn't responding)DHCP lease denied(indicates upstream router is rejecting the request)DHCP server started on <WAN interface>(indicates you accidentally enabled DHCP on WAN—disable this immediately to avoid conflicts with your upstream router)
If you can share specific error messages from the logs or packet captures, we can narrow this down further!
内容的提问来源于stack exchange,提问作者kilrainebc

