Ubuntu开放UFW与iptables后仍无法访问站点后端
提问:OVH服务器80端口无法访问,已禁用OVH防火墙并配置UFW允许规则
我使用的是OVH的独立服务器,已禁用OVH提供的防火墙,sites-available配置文件也设置为允许所有连接。
UFW状态返回如下:
To Action From -- ------ ---- Nginx Full ALLOW Anywhere OpenSSH ALLOW Anywhere Nginx HTTPS ALLOW Anywhere Nginx HTTP ALLOW Anywhere 80/tcp ALLOW Anywhere 80 ALLOW Anywhere 22/tcp ALLOW Anywhere Nginx Full (v6) ALLOW Anywhere (v6) OpenSSH (v6) ALLOW Anywhere (v6) Nginx HTTPS (v6) ALLOW Anywhere (v6) Nginx HTTP (v6) ALLOW Anywhere (v6) 80/tcp (v6) ALLOW Anywhere (v6) 80 (v6) ALLOW Anywhere (v6) 22/tcp (v6) ALLOW Anywhere (v6)
执行iptables -l时返回错误,使用iptables -L查看规则如下:
root@ns5008551:~# iptables -l iptables v1.8.4 (legacy): unknown option "-l" Try `iptables -h' or 'iptables --help' for more information. root@ns5008551:~# iptables -L Chain INPUT (policy DROP) target prot opt source destination ufw-before-logging-input all -- anywhere anywhere ufw-before-input all -- anywhere anywhere ufw-after-input all -- anywhere anywhere ufw-after-logging-input all -- anywhere anywhere ufw-reject-input all -- anywhere anywhere ufw-track-input all -- anywhere anywhere Chain FORWARD (policy DROP) target prot opt source destination ufw-before-logging-forward all -- anywhere anywhere ufw-before-forward all -- anywhere anywhere ufw-after-forward all -- anywhere anywhere ufw-after-logging-forward all -- anywhere anywhere ufw-reject-forward all -- anywhere anywhere ufw-track-forward all -- anywhere anywhere Chain OUTPUT (policy ACCEPT) target prot opt source destination ufw-before-logging-output all -- anywhere anywhere ufw-before-output all -- anywhere anywhere ufw-after-output all -- anywhere anywhere ufw-after-logging-output all -- anywhere anywhere ufw-reject-output all -- anywhere anywhere ufw-track-output all -- anywhere anywhere Chain ufw-after-forward (1 references) target prot opt source destination Chain ufw-after-input (1 references) target prot opt source destination ufw-skip-to-policy-input udp -- anywhere anywhere udp dpt:netbios-ns ufw-skip-to-policy-input udp -- anywhere anywhere udp dpt:netbios-dgm ufw-skip-to-policy-input tcp -- anywhere anywhere tcp dpt:netbios-ssn ufw-skip-to-policy-input tcp -- anywhere anywhere tcp dpt:microsoft-ds ufw-skip-to-policy-input udp -- anywhere anywhere udp dpt:bootps ufw-skip-to-policy-input udp -- anywhere anywhere udp dpt:bootpc ufw-skip-to-policy-input all -- anywhere anywhere ADDRTYPE match dst-type BROADCAST Chain ufw-after-logging-forward (1 references) target prot opt source destination LOG all -- anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] " Chain ufw-after-logging-input (1 references) target prot opt source destination LOG all -- anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] " Chain ufw-after-logging-output (1 references) target prot opt source destination Chain ufw-after-output (1 references) target prot opt source destination Chain ufw-before-forward (1 references) target prot opt source destination ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED ACCEPT icmp -- anywhere anywhere icmp destination-unreachable ACCEPT icmp -- anywhere anywhere icmp time-exceeded ACCEPT icmp -- anywhere anywhere icmp parameter-problem ACCEPT icmp -- anywhere anywhere icmp echo-request ufw-user-forward all -- anywhere anywhere Chain ufw-before-input (1 references) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED ufw-logging-deny all -- anywhere anywhere ctstate INVALID DROP all -- anywhere anywhere ctstate INVALID ACCEPT icmp -- anywhere anywhere icmp destination-unreachable ACCEPT icmp -- anywhere anywhere icmp time-exceeded ACCEPT icmp -- anywhere anywhere icmp parameter-problem ACCEPT icmp -- anywhere anywhere icmp echo-request ACCEPT udp -- anywhere anywhere udp spt:bootps dpt:bootpc ufw-not-local all -- anywhere anywhere ACCEPT udp -- anywhere 224.0.0.251 udp dpt:mdns ACCEPT udp -- anywhere 239.255.255.250 udp dpt:1900 ufw-user-input all -- anywhere anywhere Chain ufw-before-logging-forward (1 references) target prot opt source destination Chain ufw-before-logging-input (1 references) target prot opt source destination Chain ufw-before-logging-output (1 references) target prot opt source destination Chain ufw-before-output (1 references) target prot opt source destination ACCEPT all -- anywhere anywhere ACCEPT all -- anywhere anywhere ctstate RELATED,ESTABLISHED ufw-user-output all -- anywhere anywhere Chain ufw-logging-allow (0 references) target prot opt source destination LOG all -- anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW ALLOW] " Chain ufw-logging-deny (2 references) target prot opt source destination RETURN all -- anywhere anywhere ctstate INVALID limit: avg 3/min burst 10 LOG all -- anywhere anywhere limit: avg 3/min burst 10 LOG level warning prefix "[UFW BLOCK] " Chain ufw-not-local (1 references) target prot opt source destination RETURN all -- anywhere anywhere ADDRTYPE match dst-type LOCAL RETURN all -- anywhere anywhere ADDRTYPE match dst-type MULTICAST RETURN all -- anywhere anywhere ADDRTYPE match dst-type BROADCAST ufw-logging-deny all -- anywhere anywhere limit: avg 3/min burst 10 DROP all -- anywhere anywhere Chain ufw-reject-forward (1 references) target prot opt source destination Chain ufw-reject-input (1 references) target prot opt source destination Chain ufw-reject-output (1 references) target prot opt source destination Chain ufw-skip-to-policy-forward (0 references) target prot opt source destination DROP all -- anywhere anywhere Chain ufw-skip-to-policy-input (7 references) target prot opt source destination DROP all -- anywhere anywhere Chain ufw-skip-to-policy-output (0 references) target prot opt source destination ACCEPT all -- anywhere anywhere Chain ufw-track-forward (1 references) target prot opt source destination Chain ufw-track-input (1 references) target prot opt source destination Chain ufw-track-output (1 references) target prot opt source destination ACCEPT tcp -- anywhere anywhere ctstate NEW ACCEPT udp -- anywhere anywhere ctstate NEW Chain ufw-user-forward (1 references) target prot opt source destination Chain ufw-user-input (1 references) target prot opt source destination ACCEPT tcp -- anywhere anywhere multiport dports http,https /* 'dapp_Nginx%20Full' */ ACCEPT tcp -- anywhere anywhere tcp dpt:ssh /* 'dapp_OpenSSH' */ ACCEPT tcp -- anywhere anywhere tcp dpt:https /* 'dapp_Nginx%20HTTPS' */ ACCEPT tcp -- anywhere anywhere tcp dpt:http /* 'dapp_Nginx%20HTTP' */ ACCEPT tcp -- anywhere anywhere tcp dpt:http ACCEPT tcp -- anywhere anywhere tcp dpt:http ACCEPT udp -- anywhere anywhere udp dpt:80 ACCEPT tcp -- anywhere anywhere tcp dpt:ssh Chain ufw-user-limit (0 references) target prot opt source destination LOG all -- anywhere anywhere limit: avg 3/min burst 5 LOG level warning prefix "[UFW LIMIT BLOCK] " REJECT all -- anywhere anywhere reject-with icmp-port-unreachable Chain ufw-user-limit-accept (0 references) target prot opt source destination ACCEPT all -- anywhere anywhere Chain ufw-user-logging-forward (0 references) target prot opt source destination Chain ufw-user-logging-input (0 references) target prot opt source destination Chain ufw-user-logging-output (0 references) target prot opt source destination Chain ufw-user-output (1 references) target prot opt source destination root@ns5008551:~#
我无法确定还有什么因素在阻止连接,希望能得到帮助,谢谢!我的预期是在浏览器中输入网站IP:80后可以访问站点。
回答
1. 验证Nginx服务与监听状态
先排除服务本身的问题:
# 检查Nginx是否正常运行 systemctl status nginx # 查看80端口的监听情况 ss -tulpn | grep :80
- 如果Nginx未运行,执行
systemctl start nginx启动;若启动失败,查看日志journalctl -xeu nginx定位错误。 - 如果80端口无监听记录,检查Nginx的server配置文件(
/etc/nginx/sites-available/下的对应文件),确认存在listen 80;或listen [::]:80;的配置,且没有被注释。
2. 本地测试站点可用性
在服务器内部发起请求,确认站点能正常响应:
curl http://127.0.0.1:80 curl http://<你的服务器公网IP>:80
- 若本地curl能获取响应,说明问题出在网络传输环节;若本地也无响应,重点排查Nginx配置(比如server块的server_name匹配、文件权限、错误页面配置)。
3. 排查UFW规则冲突
虽然UFW状态显示允许80端口,但重复的规则可能导致隐性问题,可临时禁用UFW测试:
ufw disable
禁用后尝试外部访问,若能正常访问,说明UFW规则存在问题,重置并重新配置:
ufw reset ufw default deny incoming ufw default allow outgoing ufw allow ssh ufw allow 80/tcp ufw allow 443/tcp ufw enable
4. 检查是否存在其他防火墙工具
部分系统会同时运行nftables,它会与UFW/iptables冲突,执行以下命令检查:
systemctl status nftables
若nftables处于运行状态,停止并禁用:
systemctl stop nftables systemctl disable nftables
5. 再次确认OVH硬件防火墙状态
OVH的硬件防火墙变更可能存在延迟,登录OVH控制面板,进入服务器的防火墙模块:
- 确认所有入站规则已删除
- 确认防火墙整体处于「禁用」状态
- 等待5-10分钟后再次测试访问
6. 抓包分析连接状态
如果以上步骤均无效,通过抓包确认流量是否到达服务器:
tcpdump -i any port 80 -n
在终端执行该命令后,从外部访问服务器IP:80,观察抓包结果:
- 无任何数据包:流量未到达服务器,排查OVH网络路由、本地网络防火墙或运营商限制
- 收到SYN包但无SYN-ACK:服务器接收请求但未响应,排查Nginx监听状态、内核参数(比如
net.ipv4.tcp_syncookies) - 发送SYN-ACK但客户端未收到:排查服务器出站规则、网络MTU设置或运营商问题
内容的提问来源于stack exchange,提问作者Harjit Saini
相关产品推荐
相关产品推荐

