You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

OpenShift集群中Zabbix连接外部VM失败,Agent拒绝动态IP请求

OpenShift部署Zabbix后无法监控集群外VM的解决方案

问题背景

在OpenShift集群中通过官方kubernetes.yaml部署Zabbix 6.2后,监控集群外VM时出现连接失败:

  • Zabbix Server日志显示持续网络错误,最终临时禁用主机检查
  • 集群外VM的Zabbix Agent日志明确拒绝了来自9.x.x.x系列动态IP的连接,因为Agent配置的Server参数为集群内服务名zabbix-server,无法匹配动态变化的节点出口IP

Zabbix Server错误日志

Defaulted container "zabbix-server" out of: zabbix-server, zabbix-snmptraps
** Updating '/etc/zabbix/zabbix_server.conf' parameter "DBHost": 'mysql-server'...added
287:20230120:060843.131 Zabbix agent item "system.cpu.load[all,avg5]" on host "Host-C" failed: first network error, wait for 15 seconds
289:20230120:060858.592 Zabbix agent item "system.cpu.num" on host "Host-C" failed: another network error, wait for 15 seconds
289:20230120:060913.843 Zabbix agent item "system.sw.arch" on host "Host-C" failed: another network error, wait for 15 seconds
289:20230120:060929.095 temporarily disabling Zabbix agent checks on host "Host-C": interface unavailable

Zabbix Agent错误日志

350446:20230122:103232.230 failed to accept an incoming connection: connection from "9.x.x.219" rejected, allowed hosts: "zabbix-server"
350444:20230122:103332.525 failed to accept an incoming connection: connection from "9.x.x.219" rejected, allowed hosts: "zabbix-server"
350445:20230122:103432.819 failed to accept an incoming connection: connection from "9.x.x.210" rejected, allowed hosts: "zabbix-server"
350446:20230122:103533.114 failed to accept an incoming connection: connection from "9.x.x.217" rejected, allowed hosts: "zabbix-server"

稳定解决方案

方案1:为Zabbix Server配置固定出口IP(推荐)

利用OpenShift的EgressIP或LoadBalancer特性,让Zabbix Server的所有出站请求使用固定IP:

  1. 为Zabbix Server所在命名空间配置EgressIP,指定集群的固定出口IP地址
  2. 将VM上的/etc/zabbix/zabbix_agentd.conf中Server参数修改为该固定IP
  3. 重启Zabbix Agent服务:
systemctl restart zabbix-agent

这种方式既保证安全,又避免IP动态变化的问题

方案2:允许Agent接受整个9.x.x.x网段

如果确认9.x.x.x网段仅为OpenShift节点的出口网段,可直接在Agent配置中放行整个网段:

  1. 修改VM的/etc/zabbix/zabbix_agentd.conf:
Server=9.x.x.0/24

(根据实际网段调整子网掩码,比如9.x.x.0/16)
2. 重启Zabbix Agent服务

方案3:切换为Zabbix主动监控模式

让Agent主动向Zabbix Server上报数据,无需Server主动连接:

  1. 在Zabbix Web控制台中,将目标主机的监控模式设置为主动式
  2. 修改VM的/etc/zabbix/zabbix_agentd.conf:
ServerActive=你的Zabbix Server外部可访问地址/域名
Hostname=Host-C  # 必须与Zabbix Web中配置的主机名完全一致
  1. 重启Zabbix Agent服务

内容的提问来源于stack exchange,提问作者Resham Chaney

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 02:45:34