You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Bind9使用OpenVPN作为转发器无法工作的问题求助

Bind9使用OpenVPN作为转发器无法工作的问题求助

大家好,我最近在Ubuntu服务器上折腾OpenVPN和Bind9的组合,遇到了一个棘手的问题,想请各位帮忙分析下原因。

先说说我的OpenVPN配置和运行情况

我在服务器上跑了OpenVPN,配置了仅让两个特定目标IP走VPN网关,其余所有流量直接走公网的规则,相关配置如下:

client

remote XXXXXXXXXXXX 443

dev tun

proto udp

auth-user-pass /etc/openvpn/user.txt

#redirect-gateway def1

route-nopull

route 0.0.0.0 128.0.0.0 net_gateway

route 128.0.0.0 128.0.0.0 net_gateway

route XXX.xx.xXx.xx 255.255.255.255 vpn_gateway

route XXX.xx.xXx.xx 255.255.255.255 vpn_gateway

dhcp-option DNS 1.1.1.1

dhcp-option DNS 8.8.8.8

resolv-retry infinite

persist-key

persist-tun

nobind

cipher AES-256-CBC

ncp-disable

auth SHA256

ping 5

ping-exit 60

ping-timer-rem

explicit-exit-notify 2

script-security 2

remote-cert-tls server

route-delay 5

verb 4

log-append /var/log/openvpn/openvpn.log

up /etc/openvpn/update-resolv-conf

down /etc/openvpn/update-resolv-conf

up /etc/openvpn/update_bind_forwarder.sh

ca ca.crt

cert client.crt

key client.key

目前这个VPN配置是正常工作的:

  • 当我ping那两个指定的目标IP时,traceroute显示第一跳是VPN的网关10.12.4.1
  • 访问其他所有IP时,traceroute走的是我服务器自己的公网IP,路由规则生效没问题

Bind9的配置问题

我现在想把Bind9配置成使用OpenVPN的tun0接口IP作为DNS转发器,我的named.conf.options配置如下:

options {

directory "/var/cache/bind";

recursion yes;

allow-query { any; 10.12.4.216; 192.168.0.0/32; 127.0.0.1; };

forwarders {
10.12.4.216;
};

forward only;

};

这里的10.12.4.216是我通过ip addr show tun0查到的当前tun0接口IP(这个IP是OpenVPN动态分配的,每次连接可能会变化)。

问题来了:

  • 如果我把转发器改成8.8.8.8,Bind9完全正常,能正常解析DNS
  • 但改成tun0的IP10.12.4.216后,Bind9完全无法解析任何域名,查看日志只看到这条错误:
named[5621]: managed-keys-zone: Unable to fetch DNSKEY set '.': timed out

我的疑问

为什么Bind9无法使用OpenVPN的tun0地址作为转发器?明明VPN本身是正常工作的,特定IP的路由也没问题,有没有办法解决这个问题?

备注:内容来源于stack exchange,提问作者jelkaa

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.20 13:34:35