Red Hat 8服务器firewalld无规律自动停止问题排查及持续运行解决方案咨询
看起来你的firewalld是被systemd主动停止的(日志里明确显示systemd[1]: Stopping firewalld...且退出状态为成功),不是进程崩溃导致的异常退出,咱们一步步来排查和解决:
一、先紧急保障firewalld持续运行(治标)
先给firewalld加上自动重启机制,避免业务因防火墙中断受影响:
- 编辑firewalld的systemd服务配置:
在打开的临时编辑器中添加以下内容:systemctl edit firewalld.service
保存退出后,重载systemd配置并重启firewalld:[Service] Restart=always RestartSec=5
这样不管什么原因导致firewalld停止,systemd都会在5秒后自动重启它。systemctl daemon-reload systemctl restart firewalld
二、排查自动停止的根本原因(治本)
接下来要找出是谁在触发systemd停止firewalld:
1. 检查是否有互斥的防火墙服务在运行
Red Hat 8中,firewalld和传统的iptables-services/ip6tables-services是互斥的,如果这些服务被启用或启动,会自动停止firewalld。检查方式:
systemctl list-unit-files | grep -E 'iptables|ip6tables'
如果看到这些服务的状态是enabled,赶紧禁用并停止它们:
systemctl disable --now iptables.service ip6tables.service
2. 排查定时任务
看看有没有cron或者systemd定时器在执行停止firewalld的操作:
- 检查当前用户和root的crontab:
crontab -l sudo crontab -l - 检查所有systemd定时器:
重点看定时器的触发时间是否和firewalld停止时间吻合,同时可以排查定时脚本里是否包含systemctl list-timers --allsystemctl stop firewalld这类命令。
3. 查看停止时间点的完整上下文日志
针对firewalld停止的具体时间点,拉取前后的完整systemd日志,看看有没有其他服务操作触发了停止:
比如拿22:38:50这个停止时间点为例,执行:
journalctl --since "2023-12-27 22:38:00" --until "2023-12-27 22:39:00"
重点关注停止firewalld的前后,有没有其他服务启动、系统配置变更或者管理员操作的记录。
4. 检查firewalld自身的systemd单元配置
看看firewalld的服务单元有没有异常的自动停止参数:
systemctl cat firewalld.service
重点查看ExecStop、TimeoutStopSec、Type这些字段,正常情况下不会有自动停止的配置,如果发现异常可以手动修正。
额外提示:处理日志里的AllowZoneDrifting警告
虽然这个警告和自动停止无关,但官方已标记为不安全配置,未来版本会移除,建议关闭:
编辑/etc/firewalld/firewalld.conf,找到AllowZoneDrifting一行,修改为:
AllowZoneDrifting=no
然后重启firewalld生效:
systemctl restart firewalld
备注:内容来源于stack exchange,提问作者Migwell

