You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PHP内置Web服务器局域网无法访问:防火墙状态排查及问题咨询

问题与排查方案

现有配置信息

UFW防火墙状态

sudo ufw status       
Status: active

To                         Action      From
--                         ------      ----
8080                       ALLOW       Anywhere                  
8080 (v6)                  ALLOW       Anywhere (v6)             

8080                       ALLOW OUT   Anywhere                  
8080 (v6)                  ALLOW OUT   Anywhere (v6)

iptables规则

sudo iptables -L
Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         

Chain DOCKER (0 references)
target     prot opt source               destination         

Chain DOCKER-ISOLATION-STAGE-1 (0 references)
target     prot opt source               destination         

Chain DOCKER-ISOLATION-STAGE-2 (0 references)
target     prot opt source               destination         

Chain DOCKER-USER (0 references)
target     prot opt source               destination         

Chain ufw-after-forward (0 references)
target     prot opt source               destination         

Chain ufw-after-input (0 references)
target     prot opt source               destination         

Chain ufw-after-logging-forward (0 references)
target     prot opt source               destination         

Chain ufw-after-logging-input (0 references)
target     prot opt source               destination         

Chain ufw-after-logging-output (0 references)
target     prot opt source               destination         

Chain ufw-after-output (0 references)
target     prot opt source               destination         

Chain ufw-before-forward (0 references)
target     prot opt source               destination         

Chain ufw-before-input (0 references)
target     prot opt source               destination         

Chain ufw-before-logging-forward (0 references)
target     prot opt source               destination         

Chain ufw-before-logging-input (0 references)
target     prot opt source               destination         

Chain ufw-before-logging-output (0 references)
target     prot opt source               destination         

Chain ufw-before-output (0 references)
target     prot opt source               destination         

Chain ufw-reject-forward (0 references)
target     prot opt source               destination         

Chain ufw-reject-input (0 references)
target     prot opt source               destination         

Chain ufw-reject-output (0 references)
target     prot opt source               destination         

Chain ufw-track-forward (0 references)
target     prot opt source               destination         

Chain ufw-track-input (0 references)
target     prot opt source               destination         

Chain ufw-track-output (0 references)
target     prot opt source               destination

用户问题

我执行php -S 0.0.0.0:8080启动PHP内置Web服务器,本机可以通过0.0.0.0:8080、192.168.0.150:8080或127.0.0.1:8080正常访问,但局域网内的手机或其他电脑无法通过192.168.0.150:8080访问。想问:

  1. 当前防火墙配置是否正常?
  2. 有没有办法排查是否存在其他防火墙?
  3. 路由器层面是否会影响(我认为局域网内应该无关,但仍有疑问)

解答与排查步骤

1. 当前防火墙配置是否正常?

从给出的UFW状态和iptables规则来看,防火墙配置是正常的:

  • UFW已经明确允许8080端口的入站/出站流量,来源覆盖任意地址;
  • iptables的INPUT链策略为ACCEPT,且没有额外拦截规则,不会阻挡8080端口的请求。

2. 排查是否存在其他防火墙或拦截因素

可以按以下步骤逐一验证:

  • 确认PHP服务器监听地址:执行netstat -tulpn | grep 8080,确保输出显示监听0.0.0.0:8080(而非仅127.0.0.1:8080),如果只监听本地回环,局域网设备自然无法访问;
  • 检查其他防火墙工具:执行systemctl status firewalld,查看firewalld是否在运行,若运行则需添加8080端口允许规则,或直接关闭测试;
  • 临时关闭UFW测试:执行sudo ufw disable,再用局域网设备访问,排除UFW规则可能存在的隐性问题;
  • 检查系统安全工具:比如fail2ban等,查看是否有针对8080端口或局域网IP的拦截规则。

3. 路由器层面是否会影响?

局域网内访问一般不受路由器影响,但存在几种例外情况:

  • AP隔离(客户端隔离):部分路由器默认开启此功能,会阻止局域网内设备互相访问,需进入路由器后台关闭该选项;
  • 网段不一致:确认本机和其他设备在同一网段(比如都是192.168.0.x),若手机连2.4G WiFi、电脑连5G WiFi但网段不同,也会导致无法访问;
  • 路由器防火墙规则:少数路由器会设置局域网内端口拦截规则,可暂时关闭路由器防火墙测试是否恢复正常。

额外排查步骤

  • 测试网络连通性:在局域网设备上执行ping 192.168.0.150,若ping不通,说明IP地址有误、本机开启了ICMP拦截,或网络本身不通;
  • 测试端口连通性:用telnet 192.168.0.150 8080或curl http://192.168.0.150:8080,查看是否能建立连接,判断是网络问题还是服务本身的问题。

内容的提问来源于stack exchange,提问作者alex

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 05:07:43