Windows Server(EC2)与远程Linux树莓派间IP路由配置问题求助
Alright, let's break down your setup and fix the routing gap step by step. You've got a solid foundation: the Raspberry Pi is connected to both your local PLC network and the EC2 VPN server, but traffic isn't flowing between the VPN's 10.0.1.0/24 range and the PLC's 192.168.0.0/24 range. Here's how to wire that up:
1. First: Enable IP Forwarding on the Raspberry Pi
Your Pi needs to act as a router between its vpn_se VPN interface and the eth0 PLC-connected interface.
- Temporary fix (reverts on reboot):
sudo sysctl -w net.ipv4.ip_forward=1 - Permanent fix:
Edit the sysctl config file:
Uncomment the linesudo nano /etc/sysctl.confnet.ipv4.ip_forward=1, save and exit (Ctrl+O,Enter,Ctrl+X), then apply the change:sudo sysctl -p
2. Add Static Routing on the Windows VPN Server
The EC2 VPN server needs to know that traffic destined for the PLC's 192.168.0.0/24 network should go through the Raspberry Pi's VPN client IP.
First, grab the Pi's VPN client IP: on the Pi, run:
ip addr show vpn_se
Look for the inet line under vpn_se (it'll be something like 10.0.1.10/24).
Then on the Windows Server 2016 VPN machine (run Command Prompt as Administrator):
route add 192.168.0.0 mask 255.255.255.0 [PI_VPN_IP] -p
Replace [PI_VPN_IP] with the IP you found (e.g., 10.0.1.10). The -p flag makes this route permanent across reboots.
Verify the route exists with:
route print
You should see an entry for 192.168.0.0 pointing to your Pi's VPN IP.
3. Configure Firewall/Forwarding Rules on the Raspberry Pi
Make sure the Pi's firewall allows traffic to pass between the two interfaces. Run these commands to add forwarding rules:
sudo iptables -A FORWARD -i vpn_se -o eth0 -j ACCEPT sudo iptables -A FORWARD -i eth0 -o vpn_se -j ACCEPT
To save these rules so they persist after reboot (Raspbian):
sudo iptables-save > /etc/iptables/rules.v4
4. (Optional) Enable Reverse Traffic (PLC → VPN Server)
If you need the PLC to reach the VPN server or other resources in the 10.0.1.0/24 network, you have two options:
- Preferred: Add a static route on the PLC itself. Point traffic for
10.0.1.0/24to the Pi'seth0IP (find it withip addr show eth0on the Pi). - Workaround (if PLC can't set routes): Configure NAT on the Pi for reverse traffic:
sudo iptables -t nat -A POSTROUTING -o vpn_se -s 192.168.0.0/24 -j MASQUERADE
5. Double-Check EC2 Security Groups & Windows Firewall
- EC2 Security Group: Ensure it allows inbound/outbound traffic between
10.0.1.0/24and192.168.0.0/24(or at least the specific PLC IP192.168.0.99). - Windows Firewall: Make sure it allows ICMP (ping) and any other protocols you need through the VPN interface. You can verify by temporarily disabling the firewall for testing (re-enable after!).
Verify Connectivity
- From the Windows VPN server, ping
192.168.0.99—it should now respond. - From the Pi, ping a different device in the
10.0.1.0/24network (if exists) to confirm reverse routing. - If you set up reverse traffic, ping the VPN server from the PLC (if supported).
内容的提问来源于stack exchange,提问作者Andres Mora

