如何阻止Netplan为每个网络接口绑定默认网关?
I ran into this exact same headache when switching to Netplan on Ubuntu Server, so I totally get how frustrating it is to have both interfaces grabbing a default gateway when you only want one. Let's break down how to fix this:
Step 1: Locate Your Netplan Config File
First, head over to the Netplan configuration directory. You'll find a YAML file here—usually named something like 01-netcfg.yaml or 50-cloud-init.yaml if you used cloud-init during setup:
cd /etc/netplan/ ls
Step 2: Edit the Config to Explicitly Define Interface Behavior
Open the file with your preferred editor (I use nano for simplicity) and structure it so only your external DHCP interface gets a default gateway. Replace the interface names (enp0s3/enp0s8) with your actual NIC names (find them with ip link show):
network: version: 2 renderer: networkd # Server edition uses networkd; use NetworkManager for desktop setups ethernets: enp0s3: # Trusted internal LAN interface addresses: - 192.168.1.10/24 # Your static internal IP address nameservers: addresses: [192.168.1.1] # Internal DNS server (if you have one) # Critical: Do NOT set gateway4 or any default routes here enp0s8: # Untrusted external WAN interface dhcp4: true # Optional: If DHCP doesn't set the default gateway correctly, force it explicitly routes: - to: 0.0.0.0/0 via: 203.0.113.1 # Replace with your ISP's actual gateway IP metric: 100 # Lower metric = higher priority, ensures this is the default route
YAML Syntax Tips to Avoid Errors:
- Indentation is non-negotiable: Use 2 spaces per level (never tabs—YAML will throw errors).
- The internal interface has no gateway or default route defined, so Netplan won't assign one automatically.
- The
metricvalue guarantees your external gateway takes precedence if any conflicting routes pop up.
Step 3: Apply the Configuration
Save the file, then load the new settings without rebooting:
sudo netplan generate && sudo netplan apply
generate validates your config first, and apply pushes the changes live.
Step 4: Verify the Routing Table
Check that only your external interface has a default gateway with:
ip route show
You should see output like this (only one default entry):
default via 203.0.113.1 dev enp0s8 proto dhcp src 203.0.113.10 metric 100 192.168.1.0/24 dev enp0s3 proto kernel scope link src 192.168.1.10 203.0.113.0/24 dev enp0s8 proto kernel scope link src 203.0.113.10
If you still see a default gateway for the internal interface, double-check your config for accidental gateway4 entries or extra routes—Netplan will always respect explicit settings you add.
内容的提问来源于stack exchange,提问作者Aaron Murray

