【问题标题】:Port 80 blocked80端口被阻塞
【发布时间】:2014-07-02 17:35:06
【问题描述】:

所以过去几个小时我一直在尝试打开我的端口 80,以便我可以访问我的 Apache 服务器。我正在运行 RHEL 6.5,下面是我的 iptables 的配置。

# Generated by iptables-save v1.4.7 on Wed Jul  2 12:59:50 2014
*filter
:INPUT ACCEPT [0:0]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [9:1332]
-A INPUT -m state --state NEW -m tcp -p tcp --dport 80 -j ACCEPT 
## Open 443 port i.e. HTTPS
-A INPUT -m state --state NEW -m tcp -p tcp --dport 443 -j ACCEPT
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -p icmp -j ACCEPT
-A INPUT -i lo -j ACCEPT
-A INPUT -p tcp -m state --state NEW -m tcp --dport 22 -j ACCEPT
-A INPUT -p tcp -m tcp --dport 80 -j ACCEPT
COMMIT
# Completed on Wed Jul  2 12:59:50 2014

我已保存它们并重新启动,但无济于事。我正在使用端口检查器 (http://www.checkmyports.net/) 来检查它是否打开,但事实并非如此。在您将此标记为重复之前,我已经在网上尝试了所有内容。我已经多次重新配置我的 iptables,删除了额外的防火墙,禁用和重新启用,以及多种其他解决方案,但都无济于事。关于我哪里出错的任何想法?谢谢。

ps aux 的输出 | grep 'httpd' :

root     20353  0.0  0.7 175704  3668 ?        Ss   12:59   0:00 /usr/sbin/httpd
apache   20355  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20356  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20357  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20358  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20359  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20360  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20361  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
apache   20362  0.0  0.4 175704  2408 ?        S    12:59   0:00 /usr/sbin/httpd
root     21624  0.0  0.1 103244   856 pts/0    S+   13:55   0:00 grep httpd

netstat -tulpn 的输出:

Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address               Foreign Address             State           PID/Program name   
tcp        0      0 0.0.0.0:111                 0.0.0.0:*                   LISTEN          960/rpcbind         
tcp        0      0 0.0.0.0:22                  0.0.0.0:*                   LISTEN        28361/sshd          
tcp        0      0 0.0.0.0:36088               0.0.0.0:*                   LISTEN      978/rpc.statd       
tcp        0      0 127.0.0.1:25                0.0.0.0:*                   LISTEN      1108/sendmail       
tcp        0      0 :::111                      :::*                        LISTEN      960/rpcbind         
tcp        0      0 :::80                       :::*                        LISTEN      20353/httpd         
tcp        0      0 :::51733                    :::*                        LISTEN      978/rpc.statd       
tcp        0      0 :::22                       :::*                        LISTEN      28361/sshd          
udp        0      0 0.0.0.0:111                 0.0.0.0:*                               960/rpcbind         
udp        0      0 0.0.0.0:39182               0.0.0.0:*                               978/rpc.statd       
udp        0      0 0.0.0.0:68                  0.0.0.0:*                               20708/dhclient      
udp        0      0 0.0.0.0:711                 0.0.0.0:*                               960/rpcbind         
udp        0      0 0.0.0.0:730                 0.0.0.0:*                               978/rpc.statd       
udp        0      0 :::111                      :::*                                    960/rpcbind         
udp        0      0 :::711                      :::*                                    960/rpcbind         
udp        0      0 :::35278                    :::*                                    978/rpc.statd       

【问题讨论】:

  • 如果禁用 iptables 仍然阻止端口 80,则您的路由器防火墙有问题,或者您位于 nat 后面。如果您在 nat 后面,则需要通过它将端口 80 转发到您的网络服务器。
  • 端口 80 流量可能被您的 ISP 阻止。它的常见做法

标签: apache centos port iptables rhel


【解决方案1】:

确保该端口上有运行。

如果您在防火墙上打开了端口 80,但没有在该端口(apache、http)上侦听,则该端口将显示为关闭。

输出是什么

ps aux | grep 'httpd'

和

netstat -tulpn

【讨论】:

  • 添加了这些回复。
【解决方案2】:

您可以尝试完全清除 iptables,让网络访问正常工作,然后重新打开。

我有一个 iptables-clear.sh 脚本来执行此操作。

请注意,这不使用 /etc/init.d 版本的 iptables,您在修复此问题时可能必须关闭它。完成后请记住将其重新打开。

# Flush all tables
iptables -F
iptables -t nat -F

# Default policy to ACCEPT
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPT
iptables -t nat -P PREROUTING ACCEPT
iptables -t nat -P POSTROUTING ACCEPT
iptables -t nat -P OUTPUT ACCEPT

【讨论】:

    猜你喜欢
    • 2021-11-12
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 1970-01-01
    • 2015-01-01
    • 2015-03-09
    • 1970-01-01
    • 1970-01-01
    相关资源
    最近更新 更多