背景
NetworkManager 不运行 dispatcher.d/pre-down.d 脚本,因此我创建了一个 systemd-service 脚本。它在启动和关闭期间运行良好,但在关闭期间它不会写入 syslog。文件 /etc/iptables.rules 在关闭期间会更新,但不会将任何内容记录到 /var/log/syslog。
从终端运行...
systemctl restart network-down
... 将信息写入系统日志。但在系统重启期间不会写入。
问题
我的服务脚本中缺少什么吗?
脚本:/etc/systemd/system/network-down.service:
[Unit]
Description=Firewall Iptables Save
Wants=network-online.target
After=network.target network-online.target
[Service]
Type=oneshot
ExecStart=/bin/true
ExecStop=/bin/bash /etc/NetworkManager/dispatcher.d/pre-down.d/01-firewall-pre-down network pre-down
RemainAfterExit=yes
StandardOutput=syslog
StandardError=syslog
SyslogIdentifier=Firewall Iptables Save
[Install]
WantedBy=multi-user.target
脚本:01-防火墙-预关闭:
if [ -x /usr/bin/logger ]; then
LOGGER="/usr/bin/logger -s -p daemon.info -t FirewallHandler[PREDOWN]"
else
LOGGER=echo
fi
case "$2" in
pre-up)
if [ ! -r /etc/iptables.rules ]; then
${LOGGER} "No iptables rules exist to restore."
return
fi
if [ ! -x /sbin/iptables-restore ]; then
${LOGGER} "No program exists to restore iptables rules."
return
fi
${LOGGER} "Restoring iptables rules (pre-up)"
/sbin/iptables-restore -c < /etc/iptables.rules
;;
pre-down)
if [ ! -x /sbin/iptables-save ]; then
${LOGGER} "No program exists to save iptables rules."
return
fi
${LOGGER} "Saving iptables rules. (pre-down)"
/sbin/iptables-save -c > /etc/iptables.rules
;;
*)
${LOGGER} "Nothing to do for case: ($2)"
;;
esac
答案1
改变:
After=network.target network-online.target
到:
After=network.target network-online.target rsyslog.service
现在应该可以记录了!