Page MenuHomeVyOS Platform

blackbox-exporter ICMP probes fail silently in default configuration due to missing net.ipv4.ping_group_range permission
Closed, ResolvedPublicBUG

Description

When, set service monitoring prometheus blackbox-exporter modules icmp is configured, ICMP probes silently fail with probe_success=0 in Prometheus metrics.

The blackbox exporter runs under the node_exporter system user. The VyOS kernel default for net.ipv4.ping_group_range is '1 0'.
This permits only the privileged group to create ICMP sockets. The node_exporter user therefore cannot send ICMP packets, and probes fail.

Configuration:

set service monitoring prometheus blackbox-exporter listen-address 0.0.0.0
set service monitoring prometheus blackbox-exporter port 9115
set service monitoring prometheus blackbox-exporter modules icmp name ping4 preferred-ip-protocol ipv4

Then scrape the probe endpoint from Prometheus:

/probe?target=8.8.8.8&module=ping4

Expected result: probe_success 1
Actual result: probe_success 0 with no error logged

Possible Solutions:

  1. Automatically configure sysctl when any modules icmp entry is present (during commit) and apply net.ipv4.ping_group_range = 0 2147483647, removing it when no ICMP modules remain configured. (Reference: https://github.com/prometheus/blackbox_exporter#permissions)
  2. Add AmbientCapabilities=CAP_NET_RAW and CapabilityBoundingSet=CAP_NET_RAW to blackbox_exporter.service.j2 conditionally when ICMP modules are present.

Details

Version
1.5.0-S1
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

natali-rs1985 changed the task status from Open to In progress.Jul 1 2026, 12:26 PM
natali-rs1985 claimed this task.
natali-rs1985 changed Is it a breaking change? from Unspecified (possibly destroys the router) to Perfectly compatible.
natali-rs1985 moved this task from Need Triage to Completed on the VyOS Rolling board.