Ad Widget

Collapse

SSH Firewall Rules Stoping Zabbix Proxy for Some. Why?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rburns
    Junior Member
    • May 2022
    • 16

    #1

    SSH Firewall Rules Stoping Zabbix Proxy for Some. Why?

    We are locking down our SSH access to servers. We create a new zone, add ssh to that zone, add source addresses , and remove ssh from public.
    We have 127 hosts monitored by one of proxies. When we enable this SSH settings, three of the 127 hosts are unable to send active checks. The three are all Rocky Linux. Two are Rocky 9, one is Rocky 8. There are other Rocky Linux servers on this proxy that are fine.
    A netstat before and after appears to be the same for port 10051. I tried this the other day to do this and it was the same three servers.
    If I remove the firewall config, active checks start working again.
    It's like the Zabbix Proxy needs ssh, but I put the IP of the proxy in but it did not help.​
    Attached Files
  • LenR
    Senior Member
    • Sep 2009
    • 1005

    #2
    Firewalld? Share a --list-all of it working and not.

    Comment

    • rburns
      Junior Member
      • May 2022
      • 16

      #3
      I don't think you will get much of the firewall, but here you go. Zabbix-working is the working config. Zabbix-not-work1 and Zabbix-not-work2 are the firewall rules where ssh is moved to a new zone. The key here is that this config works to restrict ssh on the proxy and other servers. It only seems to be a problem with certain Zabbix hosts communicating with the proxy.
      Attached Files

      Comment

      Working...