Hmmm ... found this on my HOME workstation ... /etc/permissions.easy: /usr/bin/ping root:root 0755 +capabilities cap_net_raw=ep /usr/bin/ping6 root:root 0755 +capabilities cap_net_raw=ep # mtr is linked against ncurses. For dialout only. /usr/sbin/mtr root:dialout 0750 +capabilities cap_net_raw=ep ... and with /etc/sysconfig/security PERMISSION_SECURITY="easy local" it work here as expected, that is my suggestion at comment #7 is already done ;)