RHEL7.7 EC2实例80端口突闭,Spotfire服务无法访问求助
Let's break this down step by step—since your AWS security group already allows port 80, the issue is almost certainly on the EC2 instance itself. Here's the best approach to get port 80 back up for your Spotfire Server (Tomcat):
1. Verify Spotfire Server/Tomcat is Running
First, confirm the core service is actually active. If Tomcat isn't running, port 80 won't be listening at all:
- Check service status:
(If you don't have a dedicatedsystemctl status spotfire-serverspotfire-serverservice, useps aux | grep tomcatto look for Tomcat processes.) - If the service is stopped, start it immediately:
systemctl start spotfire-server - To ensure it starts on boot (prevent future issues):
systemctl enable spotfire-server
2. Check the Local Firewall (firewalld)
Even with AWS security groups, RHEL 7.7 comes with firewalld enabled by default—it might be blocking port 80 internally. You don't need to install it; it should already be present:
- Check if firewalld is running:
systemctl status firewalld - List currently allowed ports to confirm 80 is missing:
firewall-cmd --list-ports - Add port 80 temporarily (for testing):
firewall-cmd --add-port=80/tcp - Make the change permanent so it survives reboots:
firewall-cmd --add-port=80/tcp --permanent firewall-cmd --reload
If firewalld isn't running, check legacy iptables rules as a fallback:
iptables -L -n | grep 80
Look for any REJECT or DROP rules targeting port 80, and adjust them if needed.
3. Confirm Port 80 is Being Listened On
Even if the service is running, it might not be bound to port 80. Verify this with:
ss -tulpn | grep :80
- If no output appears, check Tomcat's
server.xmlconfiguration (usually in/opt/spotfire/tomcat/conf/or similar) to ensure the<Connector>element is set to port 80:<Connector port="80" protocol="HTTP/1.1" connectionTimeout="20000" redirectPort="443"/> - Note: Ports below 1024 require root privileges. If Tomcat is running as a non-root user, you'll need one of these workarounds:
- Use
authbindto allow the non-root user to bind to port 80 - Set up a reverse proxy (like Nginx) to listen on 80 and forward traffic to Tomcat's higher port (e.g., 8080)
- Run Tomcat as root (not recommended for security)
- Use
4. Check SELinux Restrictions
RHEL 7.7 enforces SELinux by default, which might block Tomcat from binding to port 80 even if other settings are correct:
- Temporarily disable SELinux to test if it's the culprit:
Then recheck if port 80 is listening. If it works, you'll need to update SELinux rules to allow Tomcat to use port 80 permanently:setenforce 0
(Port 80 is typically already in thesemanage port -a -t http_port_t -p tcp 80http_port_tset, but this ensures it's registered for Tomcat's context.) - For deeper debugging, check the SELinux audit log for denials:
tail -f /var/log/audit/audit.log | grep denied
Final Notes
Start with the simplest checks (service status, local firewall) before moving to more complex configurations like SELinux or port binding privileges. This should get your Spotfire Server back accessible on port 80 quickly.
内容的提问来源于stack exchange,提问作者Georgi Koemdzhiev

