You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 20.04服务器基于UFW配置路由器的跨网段连通性故障排查求助

Ubuntu 20.04服务器基于UFW配置路由器的跨网段连通性故障排查求助

各位好,我现在正在用Ubuntu 20.04 Server搭建一台路由器,选用UFW作为防火墙,但遇到了跨网段连通的问题,折腾了好一阵还是没解决,想请大家帮忙排查下问题所在。

基础环境与已完成的配置

我是从干净的系统安装开始配置的,网络拓扑图已经附上。目前用Netplan完成了双网卡的配置,YAML配置文件如下:

network:
  ethernets:
    enp2s0:
      addresses:
        - 192.168.1.230/24
      gateway4: 192.168.1.1
      nameservers:
        addresses:
          - 192.168.1.1
        search: []
    enx000acd394549:
      addresses:
        - 192.168.10.230/24
      nameservers:
        addresses: []
        search: []
  version: 2

这里我有个小疑问:192.168.1.0/24网段的默认网关(192.168.1.1)是否需要配置?

接下来是UFW的基础配置:

  • 编辑/etc/ufw/sysctl.conf,取消注释net_ipv4_ip_forward=1,开启IP转发功能
  • 允许SSH访问:ufw allow 22
  • 重启UFW使其生效:ufw disable && ufw enable

问题现象

我用一台连接在192.168.10.x/24网段的机器做测试:

  • 可以正常ping通路由器的两个网卡IP(192.168.1.230和192.168.10.230)
  • 可以正常SSH登录路由器
  • 但无法ping通192.168.1.x/24网段的其他设备,也无法访问外网

此时查看UFW的详细状态:

root@router:~# ufw status verbose

Status: active
Logging: on (low)
Default: deny (incoming), allow (outgoing), deny (routed)
New profiles: skip

To                         Action      From
--                         ------      ----
22                         ALLOW IN    Anywhere
22 (v6)                    ALLOW IN    Anywhere (v6)

可以看到默认的转发策略是deny (routed)。

后续尝试的排查操作

  1. 修改转发策略:

    • 编辑/etc/default/ufw,将DEFAULT_FORWARD_POLICY从DROP改为ACCEPT
    • 执行命令:ufw default allow forward
  2. 添加网段允许规则:
    为了确保网段能通过防火墙,我添加了两条宽松的规则:

    ufw allow from 192.168.10.0/24 to any
    ufw allow from 192.168.1.0/24 to any
    

此时再次查看UFW状态:

root@router:~# ufw status verbose

Status: active
Logging: on (medium)
Default: deny (incoming), allow (outgoing), allow (routed)
New profiles: skip

To                         Action      From
--                         ------      ----
22                         ALLOW IN    Anywhere
Anywhere                   ALLOW IN    192.168.10.0/24
Anywhere                   ALLOW IN    192.168.1.0/24
22 (v6)                    ALLOW IN    Anywhere (v6)

默认转发策略已经变成allow (routed),规则也添加成功,但问题依旧:测试机还是无法ping通跨网段的设备。

  1. 检查ICMP规则:
    我查看了/etc/ufw/before.rules里的ICMP相关规则,确认已经允许了必要的ICMP类型,包括ping请求(echo-request):

    # allow all on loopback
    -A ufw-before-input -i lo -j ACCEPT
    -A ufw-before-output -o lo -j ACCEPT
    
    # quickly process packets for which we already have a connection
    -A ufw-before-input -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    -A ufw-before-output -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    -A ufw-before-forward -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
    
    # drop INVALID packets (logs these in loglevel medium and higher)
    -A ufw-before-input -m conntrack --ctstate INVALID -j ufw-logging-deny
    -A ufw-before-input -m conntrack --ctstate INVALID -j DROP
    
    # ok icmp codes for INPUT
    -A ufw-before-input -p icmp --icmp-type destination-unreachable -j ACCEPT
    -A ufw-before-input -p icmp --icmp-type time-exceeded -j ACCEPT
    -A ufw-before-input -p icmp --icmp-type parameter-problem -j ACCEPT
    -A ufw-before-input -p icmp --icmp-type echo-request -j ACCEPT
    
    # ok icmp code for FORWARD
    -A ufw-before-forward -p icmp --icmp-type destination-unreachable -j ACCEPT
    -A ufw-before-forward -p icmp --icmp-type time-exceeded -j ACCEPT
    -A ufw-before-forward -p icmp --icmp-type parameter-problem -j ACCEPT
    -A ufw-before-forward -p icmp --icmp-type echo-request -j ACCEPT
    
  2. 日志监控:
    我用tail -f /var/log/ufw.log实时监控防火墙日志,但没有看到任何UFW BLOCK的记录,只有一些审计日志。

当前困惑

现在我已经开启了IP转发,调整了UFW的转发策略,添加了网段允许规则,ICMP规则也没问题,日志里也没有拦截记录,但跨网段的连通性还是没解决。实在不知道哪里出问题了,恳请各位大佬给点思路和建议,谢谢大家!

备注:内容来源于stack exchange,提问作者philn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 10:03:03