重庆思庄Oracle、Redhat认证学习论坛

标题: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configu... [打印本页]

作者: jiawang    时间: 2024-9-9 09:36
标题: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configu...
本帖最后由 jiawang 于 2024-9-9 09:36 编辑

查看防火墙状态时,日志中有警告: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration option. I... it now.
[root@70_12-mysql mysql]# systemctl status firewalld  
● firewalld.service - firewalld - dynamic firewall daemon
   Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
   Active: inactive (dead) since Thu 2024-09-05 09:37:36 CST; 19s ago
     Docs: man:firewalld(1)
  Process: 694 ExecStart=/usr/sbin/firewalld --nofork --nopid $FIREWALLD_ARGS (code=exited, status=0/SUCCESS)
Main PID: 694 (code=exited, status=0/SUCCESS)


Sep 04 09:20:38 70_12-mysql systemd[1]: Starting firewalld - dynamic firewall daemon...
Sep 04 09:20:39 70_12-mysql systemd[1]: Started firewalld - dynamic firewall daemon.
Sep 04 09:20:40 70_12-mysql firewalld[694]: WARNING: AllowZoneDrifting is enabled. This is considered an insecure configuration...it now.
Sep 05 09:37:35 70_12-mysql systemd[1]: Stopping firewalld - dynamic firewall daemon...
Sep 05 09:37:36 70_12-mysql systemd[1]: Stopped firewalld - dynamic firewall daemon.
Hint: Some lines were ellipsized, use -l to show in full.


解决:
1、在/etc/firewalld/firewalld.conf文件中将AllowZoneDrifting的配置项值改为no
8699766d90cb071c2b.png
登录/注册后可看大图