无法从外网访问本地Ubuntu服务器上的PHP应用求助
问题:外网无法访问Apache 81端口的Starfield PHP应用(本地可访问)
环境信息
- Ubuntu 22.04 家庭服务器
- 已安装apache2和PHP:
# which php /usr/bin/php # which apache2 /usr/sbin/apache2 - 为《Starfield》编写的PHP应用部署在
/var/www/html/Starfield/,使用81端口 - 域名DNS解析正常,其他端口服务可正常外网访问
- 本地网络内应用可正常访问,外网访问提示
ERR_CONNECTION_TIMED_OUT,更换80/8080/8085等端口问题依旧
已完成的配置与检查
应用目录权限与文件
root@Asus-Ubuntu:[/var/www/html/Starfield]# ll total 52K drwxr-xr-x 3 www-data www-data 4.0K Sep 17 20:21 ./ drwxr-xr-x 4 root root 4.0K Sep 16 21:26 ../ -rwxr-xr-x 1 www-data www-data 844 Sep 16 21:46 bootstrap.php* -rwxr-xr-x 1 www-data www-data 1.4K Sep 17 00:38 btn_donate_TN.gif* -rwxr-xr-x 1 www-data www-data 2.3K Sep 16 22:55 filter.php* drwxr-xr-x 8 www-data www-data 4.0K Sep 17 10:41 .git/ -rwxr-xr-x 1 www-data www-data 66 Sep 16 21:25 .gitattributes* -rwxr-xr-x 1 www-data www-data 533 Sep 17 19:14 .htaccess* -rw-r--r-- 1 www-data www-data 21 Sep 17 20:21 index2.php -rwxr-xr-x 1 www-data www-data 2.4K Sep 17 00:46 index.php* -rwxr-xr-x 1 www-data www-data 176 Sep 16 21:46 pdo.php* -rwxr-xr-x 1 www-data www-data 1.5K Sep 16 22:15 planets.php* -rwxr-xr-x 1 www-data www-data 608 Sep 17 10:31 util.php*
Apache虚拟主机配置(/etc/apache2/sites-available/000-default.conf)
<VirtualHost *:80> ServerName xxxx ServerAdmin xxxxxx DocumentRoot /var/www/html <Directory "/var/www/html/phpsysinfo"> Order Deny,Allow Deny from all Allow from 192.168.1.0/24 </Directory> ErrorLog ${APACHE_LOG_DIR}/error.log CustomLog ${APACHE_LOG_DIR}/access.log combined </VirtualHost> <VirtualHost *:81> ServerName xxxx ServerAdmin xxxxx DocumentRoot /var/www/html/Starfield <Directory "/var/www/html/Starfield"> Options Indexes FollowSymLinks AllowOverride All Require all granted </Directory> ErrorLog ${APACHE_LOG_DIR}/starfield-error.log CustomLog ${APACHE_LOG_DIR}/starfield-access.log combined </VirtualHost>
路由器端口转发规则
# Service Name External Starting Port Internal Starting Port Internal IP address 1 xxxxxx 3001-3001 3001-3001 192.168.1.27 2 xxxxxx 8096-8096 8096-8096 192.168.1.27 3 xxxxxx 2342-2342 2342-2342 192.168.1.27 4 HTTP 81-81 81-81 192.168.1.27
端口监听状态
# netstat -tulpn | grep :81 tcp6 0 0 :::81 :::* LISTEN 549421/apache2
防火墙状态
# ufw status Status: inactive
Apache全局配置(/etc/apache2/apache2.conf)
ServerName wiatech.xyz Listen 81 DefaultRuntimeDir ${APACHE_RUN_DIR} PidFile ${APACHE_PID_FILE} Timeout 300 KeepAlive On MaxKeepAliveRequests 100 KeepAliveTimeout 5 User ${APACHE_RUN_USER} Group ${APACHE_RUN_GROUP} HostnameLookups Off ErrorLog ${APACHE_LOG_DIR}/error.log LogLevel warn IncludeOptional mods-enabled/*.load IncludeOptional mods-enabled/*.conf Include ports.conf <Directory /> Options FollowSymLinks AllowOverride None Require all denied </Directory> <Directory /usr/share> AllowOverride None Require all granted </Directory> <Directory /var/www/> Options Indexes FollowSymLinks AllowOverride None Require all granted </Directory> AccessFileName .htaccess <FilesMatch "^.ht"> Require all denied </FilesMatch> LogFormat "%v:%p %h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" vhost_combined LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined LogFormat "%h %l %u %t \"%r\" %>s %O" common LogFormat "%{Referer}i -> %U" referer LogFormat "%{User-agent}i" agent IncludeOptional conf-enabled/*.conf IncludeOptional sites-enabled/*.conf
排查与解决方案
确保Apache同时监听IPv4和IPv6
当前netstat仅显示监听IPv6(tcp6),部分网络环境下会导致IPv4外网请求无法到达。修改监听配置:- 打开
/etc/apache2/ports.conf,添加或确认存在Listen 0.0.0.0:81(监听IPv4所有地址)和Listen [::]:81(监听IPv6) - 重启Apache:
systemctl restart apache2 - 再次检查监听:
netstat -tulpn | grep :81,确认同时出现tcp(IPv4)和tcp6条目
- 打开
匹配虚拟主机ServerName
外网访问使用的域名需与<VirtualHost *:81>中的ServerName完全一致,否则Apache无法匹配对应虚拟主机。将配置中的xxxx替换为实际域名,例如:<VirtualHost *:81> ServerName wiatech.xyz # 其他配置保持不变 </VirtualHost>重启Apache生效。
排查.htaccess干扰
应用目录下的.htaccess可能包含限制规则导致外网访问失败:- 临时重命名文件:
mv /var/www/html/Starfield/.htaccess /var/www/html/Starfield/.htaccess.bak - 尝试外网访问,若恢复正常则检查
.htaccess中的规则,移除IP限制或错误的Rewrite规则
- 临时重命名文件:
验证端口外网可达性
使用手机4G网络访问域名:81,或用端口检测工具确认端口是否对外开放。若其他端口正常但81端口不通,可能是ISP屏蔽了该端口,尝试更换高位不常见端口(如20081),同步修改虚拟主机、监听配置和路由器转发规则后测试。检查Apache日志定位问题
查看应用专属日志,确认请求是否到达服务器:tail -f /var/log/apache2/starfield-error.log tail -f /var/log/apache2/starfield-access.log- 若无外网请求记录:确认端口转发规则正确性,或排查ISP端口限制
- 若有错误日志:根据日志提示修复配置或代码问题
内容的提问来源于stack exchange,提问作者Kadwen
相关产品推荐
相关产品推荐

