Fix NIC-to-MAC-address mismatches after adding or removing NICs on a multi-NIC Linux ECS instance.
Symptom
Adding or removing a NIC on a multi-NIC Linux ECS instance may cause a mismatch between NIC device names and their media access control (MAC) addresses. This mismatch is called a NIC drift.
ip addr command to view network interface information, the output shows that the MAC addresses for eth1 and eth2 are swapped, as shown in the following output.
[root@xxx ~]# ip addr
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 00:16:3e:06:0b:f8 brd ff:ff:ff:ff:ff:ff
inet 172.16.8.52/24 brd 172.16.8.255 scope global eth0
3: eth1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 00:16:3e:0c:92:df brd ff:ff:ff:ff:ff:ff
inet 172.16.8.54/24 brd 172.16.8.255 scope global eth1
4: eth2: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP qlen 1000
link/ether 00:16:3e:10:bd:1b brd ff:ff:ff:ff:ff:ff
inet 172.16.8.53/24 brd 172.16.8.255 scope global eth2
Cause
NIC information is stored in /etc/udev/rules.d/70-persistent-net.rules. A NIC drift occurs when this file is missing or contains incorrect entries.
Solution
-
Before you perform high-risk operations, such as modifying the configurations or data of an Alibaba Cloud instance, check the disaster recovery and fault tolerance capabilities of the instance to ensure data security. We recommend that you create snapshots in advance. For information about snapshots, see Overview.
-
If you granted specific users the permissions on sensitive information, such as usernames and passwords, or submitted sensitive information in the Alibaba Cloud Management Console, we recommend that you modify the sensitive information at the earliest opportunity.
Edit /etc/udev/rules.d/70-persistent-net.rules to bind each NIC device name to its correct MAC address.
- Connect to the Linux ECS instance.
-
Go to the /etc/udev/rules.d directory:
cd /etc/udev/rules.d -
Open the /etc/udev/rules.d/70-persistent-net.rules file:
vi 70-persistent-net.rules -
Bind each NIC device name to its MAC address:
SUBSYSTEM=="net", ACTION=="add", DRIVERS=="?*", ATTR{address}=="<MAC address of the NIC>", KERNEL=="eth*", NAME="<Device name of the NIC>"For example, to bind eth1 to MAC address 00:16:3e:10:bd:1b:SUBSYSTEM=="net", ACTION=="add", DRIVERS=="?*", ATTR{address}=="00:16:3e:10:bd:1b", KERNEL=="eth*", NAME="eth1" - Verify the NIC configurations in /etc/udev/rules.d/70-persistent-net.rules:
cat 70-persistent-net.rulesThe expected output is:[root@xxx xZ ~]# cd /etc/udev/rules.d/ [root@xxx xZ rules.d]# ls 60-raw.rules 70-persistent-cd.rules 70-persistent-net.rules 75-persistent-net-generator.rules 99-fuse.rules [root@xxx xZ rules.d]# cat 70-persistent-net.rules # This file was automatically generated by the /lib/udev/write_net_rules # program, run by the persistent-net-generator.rules rules file. # # You can modify it, as long as you keep each rule on a single # line, and change only the value of the NAME= key. # elastic network interface SUBSYSTEM=="net", ACTION=="add", DRIVERS=="?*", ATTR{address}=="00:16:3e:10:bd:1b", KERNEL=="eth*", NAME="eth1" SUBSYSTEM=="net", ACTION=="add", DRIVERS=="?*", ATTR{address}=="00:16:3e:0c:92:df", KERNEL=="eth*", NAME="eth2" SUBSYSTEM=="net", ACTION=="add", DRIVERS=="?*", ATTR{address}=="00:16:3e:06:0b:f8", KERNEL=="eth*", NAME="eth0"The output confirms that eth1 maps to MAC address 00:16:3e:10:bd:1b. No NIC drift occurs.