firewalld启动失败大概率是底层依赖缺失,需检查journalctl日志中的python导入错误、可执行文件路径异常或dbus连接失败;验证gi、dbus、firewall模块是否就位,并确保dbus服务正常运行及shebang指向正确python版本。

firewalld 启动失败但提示“Failed to start firewalld - dynamic firewall daemon”,且日志里没有明显语法错误或 SELinux 拒绝记录,大概率是底层依赖缺失——这类问题在多 Python 版本共存、精简系统或手动编译环境里特别常见。
看 journalctl 里真正的启动失败线索
别只信 systemctl status firewalld 的 summary 行。执行:
journalctl -u firewalld -n 50 --no-pager
重点找三类信息:
- Python 导入失败:如
ImportError: No module named gi.repository或ModuleNotFoundError: No module named 'dbus' - 找不到可执行文件:如
execv() failed: No such file or directory(可能指向 python2.7 或 python3 路径异常) - DBus 连接失败:如
Could not connect: Connection refused或Failed to get D-Bus connection(说明 dbus 服务没起来或权限不对)
验证 Python 环境和关键模块是否就位
firewalld 依赖 Python GObject 绑定(gi)、dbus-python 和 firewall 模块。先确认实际运行的 Python 版本:
head -1 /usr/sbin/firewalld
再用该版本检查模块:
/usr/bin/python2.7 -c "from gi.repository import GObject; print('OK')"
/usr/bin/python2.7 -c "import dbus; print('OK')"
/usr/bin/python2.7 -c "import firewall; print('OK')"
任一报错,就说明对应模块缺失。常见修复方式:
- 安装 GObject 绑定:
yum install python-gobject(CentOS/RHEL 7)或dnf install python3-gobject(RHEL 8+/Rocky 9) - 安装 dbus 支持:
yum install python-dbus或dnf install python3-dbus - 安装 firewall 模块:
yum install python-firewall(注意包名不含 python3- 前缀,即使跑在 Python 3 下)
检查 dbus 服务是否真正可用
firewalld 需要系统总线(system bus)通信。运行:
systemctl status dbus
确保状态为 active (running),且无 failed unit 提示。若 dbus 异常,先修复它:
- 重启 dbus:
systemctl restart dbus - 验证连接:
busctl list | head -5—— 应能列出若干 service - 如果 dbus 启动失败,需查
journalctl -u dbus,常见原因是/var/run/dbus权限错误或磁盘满
排除 Python 脚本头指定错误
当系统有多个 Python 解释器(比如同时装了 python2.7、python3.6、python3.9),而 /usr/sbin/firewalld 或 /usr/bin/firewall-cmd 的 shebang 行写成 #!/usr/bin/python,就可能调用到不兼容的版本。
用编辑器打开这两个文件:
vi /usr/sbin/firewalld
vi /usr/bin/firewall-cmd
把首行改成明确路径,例如:
- RHEL/CentOS 7 → 改为
#!/usr/bin/python2.7 - RHEL 8+ / Rocky 9 → 改为
#!/usr/bin/python3(并确认python3-gobject已安装)
改完保存,再试 systemctl start firewalld。











