【发布时间】:2019-10-15 18:52:58
【问题描述】:
我正在尝试使用 express 创建节点服务器。我做了以下事情:
npm init
npm i express
并从 express 复制此示例代码:
const express = require('express')
const app = express()
app.get('/', function (req, res) {
res.send('Hello World!')
})
app.listen(80, function () {
console.log('Example app listening on port 80!')
})
在本地主机上,这有效。在我来自 OVH 的 VPS 上,我得到了 this issue,我解决了这个问题:
setcap 'cap_net_bind_service=+ep' $(which node)
我还有以下防火墙配置:
# Vider les tables actuelles
iptables -t filter -F
# Vider les règles personnelles
iptables -t filter -X
# Interdire toute connexion entrante et sortante
iptables -t filter -P INPUT DROP
iptables -t filter -P FORWARD DROP
iptables -t filter -P OUTPUT DROP
# ---
# Ne pas casser les connexions etablies
iptables -A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
# Autoriser loopback
iptables -t filter -A INPUT -i lo -j ACCEPT
iptables -t filter -A OUTPUT -o lo -j ACCEPT
# ICMP (Ping)
iptables -t filter -A INPUT -p icmp -j ACCEPT
iptables -t filter -A OUTPUT -p icmp -j ACCEPT
# ---
# SSH In
iptables -t filter -A INPUT -p tcp --dport 22 -j ACCEPT
# SSH Out
iptables -t filter -A OUTPUT -p tcp --dport 22 -j ACCEPT
# DNS In/Out
iptables -t filter -A OUTPUT -p tcp --dport 53 -j ACCEPT
iptables -t filter -A OUTPUT -p udp --dport 53 -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 53 -j ACCEPT
iptables -t filter -A INPUT -p udp --dport 53 -j ACCEPT
# NTP Out
iptables -t filter -A OUTPUT -p udp --dport 123 -j ACCEPT
# HTTP + HTTPS Out
iptables -t filter -A OUTPUT -p tcp --dport 80 -j ACCEPT
iptables -t filter -A OUTPUT -p tcp --dport 443 -j ACCEPT
# HTTP + HTTPS In
iptables -t filter -A INPUT -p tcp --dport 80 -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 443 -j ACCEPT
# FTP Out
iptables -t filter -A OUTPUT -p tcp --dport 20:21 -j ACCEPT
# FTP In
modprobe ip_conntrack_ftp # ligne facultative avec les serveurs OVH
iptables -t filter -A INPUT -p tcp --dport 20:21 -j ACCEPT
iptables -t filter -A INPUT -m state --state ESTABLISHED,RELATED -j ACCEPT
我想我的快递代码没问题。但是,当我尝试向我的网站发出请求时,即使使用服务器的直接 IP,我在服务器上也没有得到任何答复和任何痕迹。
但是netstat -tulpn | grep LISTEN 告诉我 Node 正在侦听端口 80...
如果我在 3000 端口上进行所有操作,一切正常...
我有 Node 版本 12.11.1。
我完全不知道下一步该怎么做才能理解问题......
【问题讨论】:
-
您是否使用普通用户运行它??因为1024以下的所有端口都需要root用户
-
你能telnet到服务器吗:telnet
80 并检查连接是否从你的本地机器发生。 (只是为了确保在服务器之前没有其他防火墙。) -
如果你关闭所有的防火墙,一旦你知道它在没有防火墙的情况下也能工作,然后逐步添加规则。
-
另外,不要使用 express 的 app.listen,而是使用普通的 http 模块:
var http = require('http'); http.createServer(app).listen(80);这样你就知道不是 express 搞砸了。 -
@CoolAJ86 好的,我认为这肯定是防火墙规则,但我不知道如何解决这个问题。我目前的规则更像是:放下所有东西,然后打开需要的东西。但现在我看不出缺少什么。