局域网内可访问互联网但无法访问同网段HTTP服务器问题求助
Hey there, let's work through this tricky problem together. Since Host C can ping Host A but can't reach its HTTP server (while Host B has no issues), we know the core network connectivity is intact—so we can focus on layer 7 issues, firewall rules, or server configurations. Here's a step-by-step breakdown to fix this:
1. Verify if the HTTP port is reachable from Host C
First, let's confirm if the HTTP port (default 80 for HTTP, 443 for HTTPS) is actually accessible from Host C. Use either of these commands in Host C's terminal:
- For HTTP:
telnet <HostA-IP> 80 - Or a more modern alternative:
nc -zv <HostA-IP> 80
If the command fails (shows "connection refused" or times out), the port is being blocked somewhere. If it succeeds, skip to step 4 to check server or client configurations.
2. Check Host C's (Ubuntu) firewall rules
Ubuntu typically uses ufw as the default firewall. Let's make sure it's not blocking outgoing requests to Host A's HTTP port:
- Check the current firewall status:
sudo ufw status - If
ufwis active, look for rules that might block traffic to Host A. If no rule allows access to port 80/443, add one:- Allow all traffic to port 80:
sudo ufw allow 80/tcp - Or restrict it to only Host A:
sudo ufw allow from <HostA-IP> to any port 80/tcp
- Allow all traffic to port 80:
- After adding the rule, test the HTTP access again.
3. Check Host A's firewall settings
Even though Host B can access the server, Host A's firewall might have a whitelist that only includes Host B's IP. Double-check:
- If Host A is running Windows: Go to Windows Defender Firewall > Advanced Settings and look for inbound rules for HTTP. Ensure Host C's IP is allowed, or the rule allows all local network IPs.
- If Host A is running Linux: Use
sudo iptables -Lor check its firewall tool (likeufworfirewalld) to confirm inbound HTTP traffic isn't restricted to specific IPs.
4. Verify Host A's HTTP server binding configuration
Sometimes servers are configured to only listen on localhost or a specific IP (like Host B's IP), which would block other devices:
- For Apache: Check the
Listendirective in/etc/apache2/ports.conf—it should beListen 0.0.0.0:80(allows all IPs) instead ofListen 127.0.0.1:80or a specific IP. Restart Apache after changing:sudo systemctl restart apache2 - For Nginx: Look at the
listenline in your server block (e.g.,/etc/nginx/sites-available/default)—it should belisten 80;orlisten 0.0.0.0:80;. Restart Nginx:sudo systemctl restart nginx
5. Check for proxy settings on Host C
Ubuntu's system proxy or browser proxy might be redirecting local network requests through an external proxy, causing the failure:
- Go to Settings > Network > Network Proxy and set it to "Disabled".
- In your browser (Chrome/Firefox), check if proxy settings are enabled and disable them temporarily.
6. Use curl to get detailed error messages
Run curl -v http://<HostA-IP> on Host C. The verbose output will tell you exactly where the process fails—whether it's a connection refusal, timeout, or an HTTP error (like 403 Forbidden). This can narrow down if the issue is network-related or server-side.
内容的提问来源于stack exchange,提问作者Ajay Gupta

