CentOS 7服务器DMZ网卡仅root用户可用问题咨询
Hey there, let's dig into this weird issue with your CentOS 7 server's DMZ interface (ens33). It's confusing that root can push traffic through it just fine, but regular users can only pull the public IP before commands start lagging or failing—let's break down the most likely causes and fixes.
1. Check Firewall Rules for User-Level Restrictions
A common culprit here is firewall rules that explicitly allow only root (UID 0) traffic through the DMZ interface. Let's verify this first:
- For iptables, run:
iptables-save | grep -i uid - For nftables (if you're using it instead):
nft list ruleset | grep -i uid
If you see a rule like *-A OUTPUT -o ens33 -m owner --uid-owner 0 -j ACCEPT*, that's exactly the problem—it's blocking all non-root traffic from exiting via ens33. To fix this:
- Allow your specific regular user's traffic:
iptables -A OUTPUT -o ens33 -m owner --uid-owner [your-user-uid] -j ACCEPT - Or, if your security policy allows it, permit all users to use the DMZ interface:
iptables -A OUTPUT -o ens33 -j ACCEPT
Don't forget to save the rules to make them persistent:
service iptables save # If using firewalld, use firewall-cmd --runtime-to-permanent instead
2. Verify Policy Routing for User-Specific Traffic
If your server uses policy routing (e.g., routing traffic based on firewall marks), it's possible only root traffic is being tagged to use the DMZ's routing table. Let's check your routing rules and tables:
ip rule show ip route show table all
If you see a rule tied to a firewall mark (like 32766: from all fwmark 0x1 lookup 100), check if your iptables mangle table is only marking root traffic:
iptables -t mangle -L OUTPUT -v -n
If you spot a rule like *-A OUTPUT -m owner --uid-owner 0 -j MARK --set-mark 0x1*, you'll need to add a matching rule for your regular user, or adjust the routing policy to include unmarked traffic in the DMZ table.
3. Tweak Reverse Path Filtering (rp_filter)
Strict reverse path filtering on the DMZ interface can cause the kernel to drop traffic from regular users if it doesn't match expected routes. Check the current setting:
sysctl net.ipv4.conf.ens33.rp_filter
If the value is 1 (strict mode), try switching it to 2 (loose mode) temporarily:
sysctl -w net.ipv4.conf.ens33.rp_filter=2
If this fixes the issue, add the setting to /etc/sysctl.conf to make it permanent:
net.ipv4.conf.ens33.rp_filter=2
4. Grant Necessary Capabilities to Regular User Commands
While regular users don't need special permissions to initiate most network connections, tools like ping require raw socket access (CAP_NET_RAW), and custom network tools might need CAP_NET_ADMIN. Fix this with:
# Grant ping raw socket access setcap cap_net_raw+ep /usr/bin/ping # For other tools, replace the path as needed setcap cap_net_admin+ep /path/to/your/network-tool
After making changes, switch to your regular user and run these tests to confirm:
# Test direct connectivity via ens33 ping -I ens33 8.8.8.8 # Verify traffic is routing through the DMZ interface curl --interface ens33 ifconfig.me
If these run without lag or failure, you've resolved the issue!
内容的提问来源于stack exchange,提问作者8charz

