WireGuard VPN中仅在对端发起Ping后才能连通的问题求助
WireGuard VPN中仅在对端发起Ping后才能连通的问题求助
大家好,我遇到一个WireGuard VPN的奇怪问题,想请帮忙分析下:
我有两台Linux PC,同时连接了本地局域网和WireGuard VPN网络。VPN子网是10.66.66.0/24,其中PC A的VPN地址是10.66.66.9,PC B是10.66.66.10。
问题现象
- 从A通过VPN ping或ssh到B完全没反应;
- 但如果先让B ping VPN子网里的任意IP(哪怕是不存在的地址),或者在A尝试连通B的同时,B去发起VPN内的ping请求,A就能立刻ping通B,而且之后一段时间内都能正常访问;
- 本地局域网内A和B互访完全正常,且A能被其他VPN节点正常访问,问题只出在B的VPN连通性上。
配置信息
WireGuard服务器配置
[Interface] Address = 10.66.66.1/24,fd42:42:42::1/64 ListenPort = 60207 PrivateKey = privatekey PostUp = iptables -I INPUT -p udp --dport 60207 -j ACCEPT PostUp = iptables -I FORWARD -i eth0 -o wg0 -j ACCEPT PostUp = iptables -I FORWARD -i wg0 -j ACCEPT PostUp = iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE PostUp = ip6tables -I FORWARD -i wg0 -j ACCEPT PostUp = ip6tables -t nat -A POSTROUTING -o eth0 -j MASQUERADE PostDown = iptables -D INPUT -p udp --dport 60207 -j ACCEPT PostDown = iptables -D FORWARD -i eth0 -o wg0 -j ACCEPT PostDown = iptables -D FORWARD -i wg0 -j ACCEPT PostDown = iptables -t nat -D POSTROUTING -o eth0 -j MASQUERADE PostDown = ip6tables -D FORWARD -i wg0 -j ACCEPT PostDown = ip6tables -t nat -D POSTROUTING -o eth0 -j MASQUERADE ### Client [Peer] PublicKey = pubkey PresharedKey = preshardkey AllowedIPs = 10.66.66.9/32,fd42:42:42::9/128 ### Client [Peer] PublicKey = pubkey PresharedKey = preshardkey AllowedIPs = 10.66.66.10/32,fd42:42:42::10/128 ### Client ...
PC A的WireGuard配置
[Interface] PrivateKey = privatekey Address = 10.66.66.9/32,fd42:42:42::9/128 [Peer] PublicKey = pubkey PresharedKey = preshardkey Endpoint = endpoint:60207 AllowedIPs = 0.0.0.0/0,::/0
PC B的WireGuard配置
[Interface] PrivateKey = privatekey Address = 10.66.66.10/32,fd42:42:42::10/128 [Peer] PublicKey = pubkey PresharedKey = preshardkey Endpoint = endpoint:60207 AllowedIPs = 10.66.66.0/24,fd42:42:42::0/112
问题复现步骤
- A尝试ping B(无响应)
A:~ $ ping 10.66.66.10 PING 10.66.66.10 (10.66.66.10) 56(84) bytes of data. # 无后续输出,一直卡住
- 在A卡住时,B发起VPN内的ping(比如不存在的地址)
B:~ $ ping 10.66.66.5 PING 10.66.66.5 (10.66.66.5) 56(84) bytes of data. From 10.66.66.1 icmp_seq=1 Destination Host Unreachable From 10.66.66.1 icmp_seq=2 Destination Host Unreachable From 10.66.66.1 icmp_seq=3 Destination Host Unreachable From 10.66.66.1 icmp_seq=4 Destination Host Unreachable ...
- A立刻开始收到B的响应
A:~ $ ping 10.66.66.10 (12-09 15:40) PING 10.66.66.10 (10.66.66.10) 56(84) bytes of data. 64 bytes from 10.66.66.10: icmp_seq=1 ttl=63 time=26756 ms 64 bytes from 10.66.66.10: icmp_seq=8 ttl=63 time=19592 ms 64 bytes from 10.66.66.10: icmp_seq=9 ttl=63 time=18568 ms 64 bytes from 10.66.66.10: icmp_seq=7 ttl=63 time=20615 ms 64 bytes from 10.66.66.10: icmp_seq=10 ttl=63 time=17544 ms 64 bytes from 10.66.66.10: icmp_seq=11 ttl=63 time=16520 ms 64 bytes from 10.66.66.10: icmp_seq=12 ttl=63 time=15496 ms 64 bytes from 10.66.66.10: icmp_seq=13 ttl=63 time=14472 ms 64 bytes from 10.66.66.10: icmp_seq=14 ttl=63 time=13448 ms 64 bytes from 10.66.66.10: icmp_seq=15 ttl=63 time=12424 ms 64 bytes from 10.66.66.10: icmp_seq=16 ttl=63 time=11400 ms 64 bytes from 10.66.66.10: icmp_seq=18 ttl=63 time=9352 ms 64 bytes from 10.66.66.10: icmp_seq=17 ttl=63 time=10376 ms 64 bytes from 10.66.66.10: icmp_seq=19 ttl=63 time=8328 ms 64 bytes from 10.66.66.10: icmp_seq=20 ttl=63 time=7304 ms 64 bytes from 10.66.66.10: icmp_seq=21 ttl=63 time=6279 ms 64 bytes from 10.66.66.10: icmp_seq=22 ttl=63 time=5256 ms 64 bytes from 10.66.66.10: icmp_seq=23 ttl=63 time=4232 ms 64 bytes from 10.66.66.10: icmp_seq=24 ttl=63 time=3208 ms 64 bytes from 10.66.66.10: icmp_seq=25 ttl=63 time=2185 ms 64 bytes from 10.66.66.10: icmp_seq=26 ttl=63 time=1160 ms 64 bytes from 10.66.66.10: icmp_seq=27 ttl=63 time=137 ms 64 bytes from 10.66.66.10: icmp_seq=28 ttl=63 time=94.4 ms 64 bytes from 10.66.66.10: icmp_seq=29 ttl=63 time=94.6 ms
之后就能正常ping和ssh访问B了,但过一段时间又会回到无法连通的状态,必须再让B发起一次VPN内的ping才行。
有没有朋友遇到过类似问题?或者能帮我分析下这是什么原因导致的?
备注:内容来源于stack exchange,提问作者KindFrog
相关产品推荐
相关产品推荐

