You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Debian 12 LXC环境下UFW无法创建链致启动失败排查

UFW在Proxmox VE下Debian 12 LXC启动失败问题

问题背景

在Proxmox VE 8.1.3环境中,2台Debian 12 Bookworm LXC出现UFW启动失败问题,但相同规则在其他12台Debian 12 LXC和7台Debian 12虚拟机中可正常运行。

已尝试的排查操作

  • 重装iptables,执行过iptables -F清空规则
  • 多次重装UFW,确保清理所有含ufw的文件/文件夹
  • 重启系统、调整自定义规则,甚至禁用所有自定义规则

故障现象

  • UFW启动失败,systemctl status ufw显示明确错误
  • IPv4完全无法使用,但IPv6可正常工作(如SSH连接)
  • 第二次启动UFW时会显示启动成功,但IPv4仍无法正常工作;禁用UFW后IPv4恢复正常
  • 其中一台LXC曾随机恢复正常,但重启后问题复现

相关命令输出

root@pass:~# ufw status
Status: active

To                         Action      From
--                         ------      ----
22/tcp                     ALLOW       192.168.1.0/24            
22/tcp                     ALLOW       10.14.0.0/24              
80/tcp                     ALLOW       192.168.1.0/24            
80/tcp                     ALLOW       10.14.0.0/24              
443/tcp                    ALLOW       192.168.1.0/24            
443/tcp                    ALLOW       10.14.0.0/24              
5432/tcp                   ALLOW       172.16.0.0/12             
22/tcp                     ALLOW       fc01::/48                 
80/tcp                     ALLOW       fc01::/48                 
443/tcp                    ALLOW       fc01::/48                 

root@pass:~# systemctl status ufw
x ufw.service - Uncomplicated firewall
     Loaded: loaded (/etc/systemd/system/ufw.service; enabled; preset: enabled)
     Active: failed (Result: exit-code) since Sun 2024-02-18 23:07:44 EST; 57s ago
       Docs: man:ufw(8)
    Process: 71 ExecStart=/lib/ufw/ufw-init start quiet (code=exited, status=1/FAILURE)
   Main PID: 71 (code=exited, status=1/FAILURE)
        CPU: 54ms

Feb 18 23:07:44 pass ufw-init[86]: Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Feb 18 23:07:44 pass ufw-init[88]: iptables-restore v1.8.9 (nf_tables): Chain 'ufw-skip-to-policy-input' does not exist
Feb 18 23:07:44 pass ufw-init[88]: Error occurred at line: 30
Feb 18 23:07:44 pass ufw-init[88]: Try `iptables-restore -h' or 'iptables-restore --help' for more information.
Feb 18 23:07:44 pass ufw-init[94]: iptables-restore: line 2 failed: No chain/target/match by that name.
Feb 18 23:07:44 pass ufw-init[123]: Problem running '/etc/ufw/before.rules'
Feb 18 23:07:44 pass ufw-init[123]: Problem running '/etc/ufw/after.rules'
Feb 18 23:07:44 pass systemd[1]: ufw.service: Main process exited, code=exited, status=1/FAILURE
Feb 18 23:07:44 pass systemd[1]: ufw.service: Failed with result 'exit-code'.
Feb 18 23:07:44 pass systemd[1]: Failed to start ufw.service - Uncomplicated firewall.
root@pass:~# systemctl restart ufw
root@pass:~# systemctl restart ufw
Job for ufw.service failed because the control process exited with error code.
See "systemctl status ufw.service" and "journalctl -xeu ufw.service" for details.
root@pass:~# systemctl restart ufw

补充信息

  • 正常与异常LXC的iptables版本均为1.8.9(nf_tables变体)
  • 对比正常机器的UFW相关文件(systemd配置、before.rules、after.rules等)未发现差异
  • 未找到此类特定UFW问题的相关资料

最终解决方式

通过重装系统解决问题,但未找到根本原因。

内容的提问来源于stack exchange,提问作者JordanPlayz158

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 23:26:08