Wi-Fi接口桥接模式下VM的802.1q VLAN数据包接收异常问题排查求助
Wi-Fi接口桥接模式下VM的802.1q VLAN数据包接收异常问题排查求助
大家好,我遇到了一个挺费解的网络问题,折腾了好一阵没理清根因,想请教下各位大佬的思路。
我的网络环境
- 一台刷了OpenWRT的路由器
- 一台笔记本通过网线直连路由器,路由器上该端口配置了VID为5的untagged VLAN
- 一台MacBook M1 Pro通过Wi-Fi连接路由器
问题现象
在MacBook上,我以en0(Wi-Fi接口)为父接口创建了VLAN5接口,之后用QEMU(hvf加速器)或者lima/UTM(VZ加速器)创建了虚拟机,结果出现了异常:
- 笔记本上用
arping发送的数据包,偶尔能到达MacBook上VLAN接口桥接的VM - 但VM上运行
arping时,只能发出请求,完全收不到笔记本的回复
不过有个关键例外:如果我给macOS的VLAN5接口分配同网段IP,笔记本和MacBook之间的任何协议数据包都能正常传输,问题只出在VM接收数据包这一环。
抓包与测试细节
我做了不少抓包和验证测试:
- 在笔记本上用
tcpdump能看到它确实回复了ARP请求,路由器上也能看到ARP回复通过Wi-Fi接口转发了,但在MacBook的en0上用tcpdump却看不到这些回复,这一点也很奇怪 - 给MacBook的VLAN5接口分配IP(192.168.24.20)后,ping和arping笔记本(192.168.24.50)完全正常:
➜ ~ ping 192.168.24.50 -c2 PING 192.168.24.50 (192.168.24.50): 56 data bytes 64 bytes from 192.168.24.50: icmp_seq=0 ttl=64 time=5.241 ms 64 bytes from 192.168.24.50: icmp_seq=1 ttl=64 time=5.429 ms --- 192.168.24.50 ping statistics --- 2 packets transmitted, 2 packets received, 0.0% packet loss round-trip min/avg/max/stddev = 5.241/5.335/5.429/0.094 ms ➜ ~ sudo arping -c 5 -i vlan5 192.168.24.50 ARPING 192.168.24.50 60 bytes from 10:e7:c6:xx:xx:xx (192.168.24.50): index=0 time=6.061 msec 60 bytes from 10:e7:c6:xx:xx:xx (192.168.24.50): index=1 time=6.084 msec 60 bytes from 10:e7:c6:xx:xx:xx (192.168.24.50): index=2 time=5.945 msec 60 bytes from 10:e7:c6:xx:xx:xx (192.168.24.50): index=3 time=3.092 msec 60 bytes from 10:e7:c6:xx:xx:xx (192.168.24.50): index=4 time=3.848 msec --- 192.168.24.50 statistics --- 5 packets transmitted, 5 packets received, 0% unanswered (0 extra) rtt min/avg/max/std-dev = 3.092/5.006/6.084/1.278 ms
- MacBook上的桥接配置(bridge100,连接vlan5和vmenet0):
➜ ~ ifconfig bridge100 bridge100: flags=8863<UP,BROADCAST,SMART,RUNNING,SIMPLEX,MULTICAST> mtu 1496 options=3<RXCSUM,TXCSUM> ether f2:2f:4b:xx:xx:xx Configuration: id 0:0:0:0:0:0 priority 0 hellotime 0 fwddelay 0 maxage 0 holdcnt 0 proto stp maxaddr 100 timeout 1200 root id 0:0:0:0:0:0 priority 0 ifcost 0 port 0 ipfilter disabled flags 0x0 member: vlan5 flags=3<LEARNING,DISCOVER> ifmaxaddr 0 port 22 priority 0 path cost 0 member: vmenet0 flags=3<LEARNING,DISCOVER> ifmaxaddr 0 port 23 priority 0 path cost 0 Address cache: 10:e7:c6:xx:xx:xx Vlan1 vlan5 326 flags=0<> 52:55:55:ae:36:b4 Vlan1 vmenet0 1172 flags=0<> nd6 options=201<PERFORMNUD,DAD> media: autoselect status: active
- VM(IP 192.168.24.10)上的arping结果:
[root@VM1 ~]# arping 192.168.24.50 -c5 ARPING 192.168.24.50 from 192.168.24.10 lima0 Sent 5 probes (5 broadcast(s)) Received 0 response(s)
- 笔记本上arping VM的结果(能收到回复):
[root@laptop ~]# arping 192.168.24.10 -c5 ARPING 192.168.24.10 from 192.168.24.50 eth0 Unicast reply from 192.168.24.10 [52:55:55:AE:36:B4] 2.492ms Unicast reply from 192.168.24.10 [52:55:55:AE:36:B4] 1.791ms Unicast reply from 192.168.24.10 [52:55:55:AE:36:B4] 3.059ms Sent 5 probes (1 broadcast(s)) Received 3 response(s)
补充测试
我还在笔记本上做了对比测试:用VirtualBox创建VM,桥接模式下在VM里创建VLAN接口,然后把笔记本切换到Wi-Fi,尝试ping MacBook上的VM,结果是笔记本VM的数据包能发出去,但MacBook的VM收不到。
这说明问题不是操作系统相关的,核心是当VM通过桥接模式连接到Wi-Fi接口时,数据包无法送达VM本身。
我的疑问
VLAN头只有4字节,为什么桥接模式下VM接口和Wi-Fi接口之间传递这个帧会有问题?而且给OS的VLAN接口分配IP后(父接口是Wi-Fi)一切正常,偏偏VM不行?
UPD:感谢A.B.的评论,已经搞清楚是什么阻止VM接收数据包了!
备注:内容来源于stack exchange,提问作者amkgi
相关产品推荐
相关产品推荐

