Updating CERT data...
/usr/local/sbin/greenbone-feed-sync: 259: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 260: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 261: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 262: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 263: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 264: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 265: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 266: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 267: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 268: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 269: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
/usr/local/sbin/greenbone-feed-sync: 270: cannot create /usr/local/var/lib/gvm/cert-data/feed.xml: Permission denied
rsync: getaddrinfo: feed.community.greenbone.net 873: Temporary failure in name resolution
rsync error: error in socket IO (code 10) at clientserver.c(137) [Receiver=3.2.3]
报这个错误,百度搜是同步错误需要关闭防火墙
[root@adp-test-5 ~]# systemctl stop firewalld.service
[root@adp-test-5 ~]# systemctl status firewalld.service
● firewalld.service - firewalld - dynamic firewall daemon
Loaded: loaded (/usr/lib/systemd/system/firewalld.service; enabled; vendor preset: enabled)
Active: inactive (dead) since Thu 2021-07-29 18:02:22 CST; 2s ago
Docs: man:firewalld(1)
Process: 741 ExecStart=/usr/sbin/firewalld --nofork --nopid $FIREWALLD_ARGS (code=exited, status=0/SUCCESS)
Main PID: 741 (code=exited, status=0/SUCCESS)
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -t filter -X DOCKER-ISOLATION-STAGE...t name.
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -t filter -F DOCKER-ISOLATION' fail...t name.
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -t filter -X DOCKER-ISOLATION' fail...t name.
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i br-4f59456c2015 -o br...hain?).
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i br-6606fe589b7b -o br...hain?).
Jul 13 14:35:55 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i br-6bb95632fd07 -o br...hain?).
Jul 13 14:35:56 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i docker0 -o docker0 -j...hain?).
Jul 13 14:35:59 adp-test-5.208 firewalld[741]: WARNING: COMMAND_FAILED: '/usr/sbin/iptables -w10 -D FORWARD -i docker0 -o docker0 -j...hain?).
Jul 29 18:02:21 adp-test-5.208 systemd[1]: Stopping firewalld - dynamic firewall daemon...
Jul 29 18:02:22 adp-test-5.208 systemd[1]: Stopped firewalld - dynamic firewall daemon.
Hint: Some lines were ellipsized, use -l to show in full.
防火墙关闭后,docker 启动容易失败
Error response from daemon: driver failed programming external connectivity on endpoint gvm (ee768a6df4b2cdd3645abe535856920a9fcff691f11c92e22d6cc10a0a05933e): (iptables failed: iptables --wait -t nat -A DOCKER -p tcp -d 0/0 --dport 9390 -j DNAT --to-destination 172.17.0.2:9392 ! -i docker0: iptables: No chain/target/match by that name.
(exit status 1))
docker服务启动时定义的自定义链DOCKER由于 centos7 firewall 被清掉
firewall的底层是使用iptables进行数据过滤,建立在iptables之上,这可能会与 Docker 产生冲突。
当 firewalld
启动或者重启的时候,将会从 iptables 中移除 DOCKER
的规则,从而影响了 Docker 的正常工作。
当你使用的是 Systemd 的时候, firewalld
会在 Docker 之前启动,但是如果你在 Docker 启动之后再启动 或者重启 firewalld
,你就需要重启 Docker 进程了。
重启docker服务及可重新生成自定义链DOCKER
systemctl restart docker
重启容器成功
[root@adp-test-5 ~]# docker start aa93219a636b
aa93219a636b