You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

安装CSF防火墙后Docker容器本地连接异常求助

问题场景与现象
  • 服务器运行WHM,已安装Docker并部署listmonk,容器状态正常:
CONTAINER ID   IMAGE                      COMMAND                  CREATED        STATUS                   PORTS                                       NAMES
0eb46a14e3c2   listmonk/listmonk:latest   "./listmonk"             20 hours ago   Up 9 minutes             0.0.0.0:9000->9000/tcp, :::9000->9000/tcp   listmonk_app
43b308157ebe   postgres:13-alpine         "docker-entrypoint.s…"   20 hours ago   Up 9 minutes (healthy)   0.0.0.0:9432->5432/tcp, :::9432->5432/tcp   listmonk_db
  • 原本通过Cloudflare Tunnel实现https://listmonk.ygprodeck.com访问http://localhost:9000正常,安装ConfigServer Security and Firewall(CSF)后,因未将9000端口加入TCP_IN/TCP_OUT(需求为不暴露端口),导致Cloudflare Tunnel连接容器超时。
  • 服务器本地执行curl -v http://127.0.0.1:9000报错:
* Rebuilt URL to: http://127.0.0.1:9000/
*   Trying 127.0.0.1...
* TCP_NODELAY set
* Connected to 127.0.0.1 (127.0.0.1) port 9000 (#0)
> GET / HTTP/1.1
> Host: 127.0.0.1:9000
> User-Agent: curl/7.61.1
> Accept: */*
>
* Recv failure: Connection reset by peer
* Closing connection 0
curl: (56) Recv failure: Connection reset by peer
已尝试的无效方案
  • 禁用CSF可解决问题,但会暴露端口,不符合需求;
  • 尝试Apache反向代理,出现相同连接重置问题;
  • 将docker0加入ETH_DEVICE_SKIP,但会把9000端口暴露给公网,不可行。
配置文件信息

采用listmonk官方生产环境安装方式,相关配置如下:

docker-compose.yml

version: "3.7"

x-app-defaults: &app-defaults
  restart: unless-stopped
  image: listmonk/listmonk:latest
  ports:
    - "9000:9000"
  networks:
    - listmonk
  environment:
    - TZ=Etc/UTC

x-db-defaults: &db-defaults
  image: postgres:13-alpine
  ports:
  networks:
    - listmonk
  environment:
    - POSTGRES_PASSWORD=<REMOVED>
    - POSTGRES_USER=<REMOVED>
    - POSTGRES_DB=<REMOVED>
  restart: unless-stopped
  healthcheck:
    test: ["CMD-SHELL", "pg_isready -U listmonk"]  
    interval: 10s
    timeout: 5s
    retries: 6

services:
  db:
    <<: *db-defaults
    container_name: listmonk_db
    volumes:
      - type: volume
        source: listmonk-data
        target: /var/lib/postgresql/data

  app:
    <<: *app-defaults
    container_name: listmonk_app
    depends_on:
      - db
    volumes:
      - ./config.toml:/listmonk/config.toml
      
  demo-db:
    container_name: listmonk_demo_db
    <<: *db-defaults

  demo-app:
    <<: *app-defaults
    container_name: listmonk_demo_app
    command: [sh, -c, "yes | ./listmonk --install --config config-demo.toml && ./listmonk --config config-demo.toml"]
    depends_on:
      - demo-db

networks:
  listmonk:

volumes:
  listmonk-data:    

config.toml

[app]
# Interface and port where the app will run its webserver.  The default value
# of localhost will only listen to connections from the current machine. To
# listen on all interfaces use '0.0.0.0'. To listen on the default web address
# port, use port 80 (this will require running with elevated permissions).
address = "0.0.0.0:9000"

# BasicAuth authentication for the admin dashboard. This will eventually
# be replaced with a better multi-user, role-based authentication system.
# IMPORTANT: Leave both values empty to disable authentication on admin
# only where an external authentication is already setup.
admin_username = "<REMOVED>"
admin_password = "<REMOVED>"

# Database.
[db]
host = "listmonk_db"
port = 5432
user = "<REMOVED>"
password = "<REMOVED>"

# Ensure that this database has been created in Postgres.
database = "listmonk"

ssl_mode = "disable"
max_open = 25
max_idle = 25
max_lifetime = "300s"

# Optional space separated Postgres DSN params. eg: "application_name=listmonk gssencmode=disable"
params = ""

内容的提问来源于stack exchange,提问作者GenesisBits

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 20:56:04