无VPN实现两个隔离系统间路由:树莓派特殊组网场景求助
Alright, let's break down how to get traffic flowing between your two Raspberry Pi Wi-Fi APs without needing a VPN. Your existing wired cross-cable setup is perfect as the backbone for this routing—here's exactly what to do:
1. Confirm Wi-Fi AP Subnet Configurations
First, make sure each Pi's Wi-Fi AP (wlan0) has a unique, non-overlapping subnet. For example:
- Device A: Set wlan0 to static IP
192.168.1.1/24, configure DHCP to assign addresses like192.168.1.10–100 - Device B: Set wlan0 to static IP
192.168.2.1/24, configure DHCP to assign addresses like192.168.2.10–100
(If you already have this set up, skip to the next step.)
2. Enable IP Forwarding on Both Pis
Linux blocks IP packet forwarding by default—we need to enable it to let each Pi route traffic between its Wi-Fi and Ethernet interfaces:
- Temporary fix (resets on reboot):
echo 1 > /proc/sys/net/ipv4/ip_forward - Permanent fix:
Edit/etc/sysctl.confand uncomment the line:
Then apply the change immediately:net.ipv4.ip_forward=1sysctl -p
3. Add Static Routes on Each Pi
We need to tell each Pi where to send traffic destined for the other Pi's Wi-Fi subnet:
- On Device A: Route traffic for Device B's Wi-Fi subnet (
192.168.2.0/24) through Device B's Ethernet IP (10.5.10.2)
To make this permanent, add the following line toip route add 192.168.2.0/24 via 10.5.10.2 dev eth0/etc/dhcpcd.conf(Raspbian uses dhcpcd for network config):static route 192.168.2.0/24 255.255.255.0 10.5.10.2 - On Device B: Route traffic for Device A's Wi-Fi subnet (
192.168.1.0/24) through Device A's Ethernet IP (10.5.10.1)
Permanent config inip route add 192.168.1.0/24 via 10.5.10.1 dev eth0/etc/dhcpcd.conf:static route 192.168.1.0/24 255.255.255.0 10.5.10.1
4. Configure DHCP to Push Routes to Clients (Optional but Recommended)
To avoid manually setting routes on every Wi-Fi client, configure your DHCP server (likely dnsmasq) to push the necessary routes:
- On Device A: Edit
/etc/dnsmasq.confand add:# Push default gateway (Device A's wlan0 IP) dhcp-option=3,192.168.1.1 # Push route to Device B's Wi-Fi subnet dhcp-option=121,192.168.2.0/24,10.5.10.1 - On Device B: Edit
/etc/dnsmasq.confand add:
Restart dnsmasq to apply changes:dhcp-option=3,192.168.2.1 dhcp-option=121,192.168.1.0/24,10.5.10.2sudo systemctl restart dnsmasq
5. Allow Forwarding in IPTables (If Needed)
If traffic still isn't flowing, check if iptables is blocking forwarding. Allow traffic between eth0 and wlan0 on both Pis:
iptables -A FORWARD -i eth0 -o wlan0 -j ACCEPT iptables -A FORWARD -i wlan0 -o eth0 -j ACCEPT
To save these rules permanently, install iptables-persistent:
sudo apt-get install iptables-persistent
Follow the prompts to save your current rules—they'll load automatically on boot.
6. Verify Connectivity
Test the setup by pinging a client on Device B's Wi-Fi from a client on Device A's Wi-Fi (and vice versa). If the ping goes through, you're good to go!
Content of the question comes from Stack Exchange, question author: Steven Sokol

