You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CentOS 7服务器DMZ网卡仅root用户可用问题咨询

Hey there, let's dig into this weird issue with your CentOS 7 server's DMZ interface (ens33). It's confusing that root can push traffic through it just fine, but regular users can only pull the public IP before commands start lagging or failing—let's break down the most likely causes and fixes.

Key Troubleshooting Areas & Fixes

1. Check Firewall Rules for User-Level Restrictions

A common culprit here is firewall rules that explicitly allow only root (UID 0) traffic through the DMZ interface. Let's verify this first:

  • For iptables, run:
    iptables-save | grep -i uid
    
  • For nftables (if you're using it instead):
    nft list ruleset | grep -i uid
    

If you see a rule like *-A OUTPUT -o ens33 -m owner --uid-owner 0 -j ACCEPT*, that's exactly the problem—it's blocking all non-root traffic from exiting via ens33. To fix this:

  • Allow your specific regular user's traffic:
    iptables -A OUTPUT -o ens33 -m owner --uid-owner [your-user-uid] -j ACCEPT
    
  • Or, if your security policy allows it, permit all users to use the DMZ interface:
    iptables -A OUTPUT -o ens33 -j ACCEPT
    

Don't forget to save the rules to make them persistent:

service iptables save
# If using firewalld, use firewall-cmd --runtime-to-permanent instead

2. Verify Policy Routing for User-Specific Traffic

If your server uses policy routing (e.g., routing traffic based on firewall marks), it's possible only root traffic is being tagged to use the DMZ's routing table. Let's check your routing rules and tables:

ip rule show
ip route show table all

If you see a rule tied to a firewall mark (like 32766: from all fwmark 0x1 lookup 100), check if your iptables mangle table is only marking root traffic:

iptables -t mangle -L OUTPUT -v -n

If you spot a rule like *-A OUTPUT -m owner --uid-owner 0 -j MARK --set-mark 0x1*, you'll need to add a matching rule for your regular user, or adjust the routing policy to include unmarked traffic in the DMZ table.

3. Tweak Reverse Path Filtering (rp_filter)

Strict reverse path filtering on the DMZ interface can cause the kernel to drop traffic from regular users if it doesn't match expected routes. Check the current setting:

sysctl net.ipv4.conf.ens33.rp_filter

If the value is 1 (strict mode), try switching it to 2 (loose mode) temporarily:

sysctl -w net.ipv4.conf.ens33.rp_filter=2

If this fixes the issue, add the setting to /etc/sysctl.conf to make it permanent:

net.ipv4.conf.ens33.rp_filter=2

4. Grant Necessary Capabilities to Regular User Commands

While regular users don't need special permissions to initiate most network connections, tools like ping require raw socket access (CAP_NET_RAW), and custom network tools might need CAP_NET_ADMIN. Fix this with:

# Grant ping raw socket access
setcap cap_net_raw+ep /usr/bin/ping
# For other tools, replace the path as needed
setcap cap_net_admin+ep /path/to/your/network-tool
Final Testing

After making changes, switch to your regular user and run these tests to confirm:

# Test direct connectivity via ens33
ping -I ens33 8.8.8.8
# Verify traffic is routing through the DMZ interface
curl --interface ens33 ifconfig.me

If these run without lag or failure, you've resolved the issue!


内容的提问来源于stack exchange,提问作者8charz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 10:35:58