You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

StrongSwan站点到站点IPsec VPN隧道已建立但无法路由问题求助

StrongSwan站点到站点IPsec VPN隧道已建立但无法路由问题求助

各位大佬,我碰到个StrongSwan站点到站点IPsec VPN的棘手问题,想请大家帮忙看看!

情况是这样的:对方那边坚持要做站点到站点模式的VPN,但我这边只有一台带公网IP的KVM托管服务器,没有什么“真实”的加密域或者本地子网要对接,就只想让这台主机本身和对方的网络连通。

我已经做了这些操作:

  • 在UFW里添加了允许IPsec端口流量的规则:ufw allow 500,4500/udp
  • 现在隧道已经成功建立了,用ipsec status查询的结果如下:

Security Associations (1 up, 0 connecting):
mytunnel[1]: ESTABLISHED 28 minutes ago, 89.XX.YY.ZZZ[89.XX.YY.ZZZ]...195.AAA.BBB.CCC[195.AAA.BBB.CCC]
mytunnel{1}: INSTALLED, TUNNEL, reqid 1, ESP in UDP SPIs: cb15f465_i 26413994_o
mytunnel{1}: 10.210.8.32/27 === 10.210.8.0/27

但现在的问题是,我ping对方子网10.210.8.0/27里的主机(比如10.210.8.1)完全不通,我用tcpdump抓ping的包,结果是这样的:

tcpdump: listening on eth0, link-type EN10MB (Ethernet), snapshot length 262144 bytes
16:34:58.457551 IP (tos 0x0, ttl 64, id 62575, offset 0, flags [DF], proto ICMP (1), length 84)
10.210.8.32 > 10.210.8.1: ICMP echo request, id 32734, seq 1, length 64
16:34:58.457572 IP (tos 0x0, ttl 64, id 62576, offset 0, flags [DF], proto ICMP (1), length 84)
10.210.8.32 > 10.210.8.1: ICMP echo request, id 32734, seq 2, length 64
16:34:59.461553 IP (tos 0x0, ttl 64, id 62577, offset 0, flags [DF], proto ICMP (1), length 84)
10.210.8.32 > 10.210.8.1: ICMP echo request, id 32734, seq 3, length 64

从抓包能看到请求发出去了,但完全没有回包。有没有大佬遇到过类似的情况?麻烦给指点下怎么解决,谢谢啦!

备注:内容来源于stack exchange,提问作者Philomatic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.17 08:13:13