You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Red Hat 8服务器firewalld无规律自动停止问题排查及持续运行解决方案咨询

Red Hat 8服务器firewalld无规律自动停止问题排查及持续运行解决方案咨询

看起来你的firewalld是被systemd主动停止的(日志里明确显示systemd[1]: Stopping firewalld...且退出状态为成功),不是进程崩溃导致的异常退出,咱们一步步来排查和解决:

一、先紧急保障firewalld持续运行(治标)

先给firewalld加上自动重启机制,避免业务因防火墙中断受影响:

  • 编辑firewalld的systemd服务配置:
    systemctl edit firewalld.service
    
    在打开的临时编辑器中添加以下内容:
    [Service]
    Restart=always
    RestartSec=5
    
    保存退出后,重载systemd配置并重启firewalld:
    systemctl daemon-reload
    systemctl restart firewalld
    
    这样不管什么原因导致firewalld停止,systemd都会在5秒后自动重启它。

二、排查自动停止的根本原因(治本)

接下来要找出是谁在触发systemd停止firewalld:

1. 检查是否有互斥的防火墙服务在运行

Red Hat 8中,firewalld和传统的iptables-services/ip6tables-services是互斥的,如果这些服务被启用或启动,会自动停止firewalld。检查方式:

systemctl list-unit-files | grep -E 'iptables|ip6tables'

如果看到这些服务的状态是enabled,赶紧禁用并停止它们:

systemctl disable --now iptables.service ip6tables.service

2. 排查定时任务

看看有没有cron或者systemd定时器在执行停止firewalld的操作:

  • 检查当前用户和root的crontab:
    crontab -l
    sudo crontab -l
    
  • 检查所有systemd定时器:
    systemctl list-timers --all
    
    重点看定时器的触发时间是否和firewalld停止时间吻合,同时可以排查定时脚本里是否包含systemctl stop firewalld这类命令。

3. 查看停止时间点的完整上下文日志

针对firewalld停止的具体时间点,拉取前后的完整systemd日志,看看有没有其他服务操作触发了停止:
比如拿22:38:50这个停止时间点为例,执行:

journalctl --since "2023-12-27 22:38:00" --until "2023-12-27 22:39:00"

重点关注停止firewalld的前后,有没有其他服务启动、系统配置变更或者管理员操作的记录。

4. 检查firewalld自身的systemd单元配置

看看firewalld的服务单元有没有异常的自动停止参数:

systemctl cat firewalld.service

重点查看ExecStop、TimeoutStopSec、Type这些字段,正常情况下不会有自动停止的配置,如果发现异常可以手动修正。

额外提示:处理日志里的AllowZoneDrifting警告

虽然这个警告和自动停止无关,但官方已标记为不安全配置,未来版本会移除,建议关闭:
编辑/etc/firewalld/firewalld.conf,找到AllowZoneDrifting一行,修改为:

AllowZoneDrifting=no

然后重启firewalld生效:

systemctl restart firewalld

备注:内容来源于stack exchange,提问作者Migwell

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.23 09:07:40