You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

树莓派Nginx端口80外部无法连接,Certbot无法续期HTTPS证书

端口80外部无法连接导致Certbot续期SSL证书失败的排查与解决

问题背景

树莓派部署Nginx搭建个人网站,本地检测Nginx已在80端口运行,但外部连接被拒绝,导致Certbot执行http-01挑战时超时失败,无法续期或扩展SSL证书。局域网内通过https://<树莓派IP地址>可正常访问网站,说明Nginx及网站本身运行状态正常。

已完成的排查操作

  • DNS配置验证:执行ping getty.nz可正常获取响应,确认DNS A记录指向正确的公网IP
  • Nginx配置校验:执行sudo nginx -t返回配置语法及有效性验证通过
    $ sudo nginx -t
    nginx: the configuration file /etc/nginx/nginx.conf syntax is ok
    nginx: configuration file /etc/nginx/nginx.conf test is successful
    
  • 防火墙规则验证:通过ufw已配置放行22、80、443端口,状态显示规则已激活
    $ sudo ufw status
    Status: active
    
    To                         Action      From
    --                         ------      ----
    443                        ALLOW       Anywhere                  
    80                         ALLOW       Anywhere                  
    22                         ALLOW       Anywhere                  
    443 (v6)                   ALLOW       Anywhere (v6)             
    80 (v6)                    ALLOW       Anywhere (v6)             
    22 (v6)                    ALLOW       Anywhere (v6)   
    
  • 端口监听状态验证:ss命令显示Nginx已正常监听0.0.0.0:80、0.0.0.0:443及对应IPv6端口,无监听范围限制
    $ sudo ss -lntp 
    State     Recv-Q    Send-Q       Local Address:Port        Peer Address:Port    Process                                                      
    LISTEN    0         244              127.0.0.1:5432             0.0.0.0:*        users:(("postgres",pid=502,fd=6))                           
    LISTEN    0         128                0.0.0.0:22               0.0.0.0:*        users:(("sshd",pid=399,fd=3))                               
    LISTEN    0         511                0.0.0.0:80               0.0.0.0:*        users:(("nginx",pid=1932,fd=10),("nginx",pid=415,fd=10))     
    LISTEN    0         511                0.0.0.0:443              0.0.0.0:*        users:(("nginx",pid=1932,fd=9),("nginx",pid=415,fd=9))       
    LISTEN    0         128                   [::]:22                  [::]:*        users:(("sshd",pid=399,fd=4))                               
    LISTEN    0         511                   [::]:80                  [::]:*        users:(("nginx",pid=1932,fd=11),("nginx",pid=415,fd=11))     
    LISTEN    0         511                   [::]:443                 [::]:*        users:(("nginx",pid=1932,fd=8),("nginx",pid=415,fd=8))       
    LISTEN    0         244                  [::1]:5432                [::]:*        users:(("postgres",pid=502,fd=5)) 
    
  • Certbot错误详情:执行sudo certbot --nginx扩展证书时,http-01挑战超时,服务器返回连接失败提示(疑似防火墙拦截)
    $ sudo certbot --nginx
    Saving debug log to /var/log/letsencrypt/letsencrypt.log
    Plugins selected: Authenticator nginx, Installer nginx
    
    Which names would you like to activate HTTPS for?
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    1: getty.nz
    2: rss.getty.nz
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Select the appropriate numbers separated by commas and/or spaces, or leave input
    blank to select all options shown (Enter 'c' to cancel): 
    
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    You have an existing certificate that contains a portion of the domains you
    requested (ref: /etc/letsencrypt/renewal/getty.nz.conf)
    
    It contains these names: getty.nz
    
    You requested these names for the new certificate: getty.nz, rss.getty.nz.
    
    Do you want to expand and replace this existing certificate with the new
    certificate?
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    (E)xpand/(C)ancel: E
    Renewing an existing certificate for getty.nz and rss.getty.nz
    Performing the following challenges:
    http-01 challenge for getty.nz
    http-01 challenge for rss.getty.nz
    Waiting for verification...
    Challenge failed for domain getty.nz
    Challenge failed for domain rss.getty.nz
    http-01 challenge for getty.nz
    http-01 challenge for rss.getty.nz
    Cleaning up challenges
    Some challenges have failed.
    
    IMPORTANT NOTES:
     - The following errors were reported by the server:
    
       Domain: getty.nz
       Type:   connection
       Detail: 122.61.157.36: Fetching
       http://getty.nz/.well-known/acme-challenge/7KasvsA5z6yvpzXlOv5hzmT_u7lOgtzlaoEY6DAMmic:
       Timeout during connect (likely firewall problem)
    
       Domain: rss.getty.nz
       Type:   connection
       Detail: 122.61.157.36: Fetching
       http://rss.getty.nz/.well-known/acme-challenge/cqhf7anWcw1_you9q90y18UVdCfjAJeEg88tNeDoWig:
       Timeout during connect (likely firewall problem)
    
       To fix these errors, please make sure that your domain name was
       entered correctly and the DNS A/AAAA record(s) for that domain
       contain(s) the right IP address. Additionally, please check that
       your computer has a publicly routable IP address and that no
       firewalls are preventing the server from communicating with the
       client. If you're using the webroot plugin, you should also verify
       that you are serving files from the webroot path you provided.
    

解决方向与操作步骤

1. 路由器端口转发及防火墙检查

  • 确认路由器已配置外部80、443端口转发到树莓派的局域网IP,且转发规则未被禁用
  • 检查路由器是否开启NAT环回(Hairpin NAT):部分家庭路由器默认关闭此功能,会导致局域网内访问公网域名正常,但外部无法连接
  • 验证路由器自带防火墙是否拦截80/443端口入站流量:需手动添加放行规则,允许外部IP访问这两个端口

2. 运营商端口限制排查

  • 部分家庭宽带运营商会封锁80、443端口,可临时修改Nginx监听端口为非标准端口(如8080、8443),同步配置路由器转发对应端口,再通过http://getty.nz:8080测试外部连接
  • 若修改端口后可正常访问,说明运营商封锁了标准端口,可选择:
    • 联系运营商申请解封80/443端口
    • 切换到Certbot的DNS-01挑战方式续期证书(无需开放80/443端口)

3. 树莓派系统层面额外防火墙校验

  • 检查iptables规则是否拦截流量:执行sudo iptables -L -n,确认存在允许80、443端口入站的规则
  • 排查安全软件(如fail2ban)是否误拦截Let's Encrypt验证服务器的IP地址,可临时禁用软件后重试Certbot操作

4. 临时使用DNS-01挑战完成证书续期

若端口问题无法快速解决,可切换到DNS-01挑战绕过端口限制,命令示例:

sudo certbot renew --authenticator dns-<你的DNS服务商插件> --installer nginx

需提前安装对应DNS服务商的Certbot插件(如Cloudflare、阿里云等),并配置API密钥完成域名所有权验证。


内容的提问来源于stack exchange,提问作者Razorfoot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 13:30:54