You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过VPN远程访问PostgreSQL数据库服务器连接超时问题排查

PostgreSQL 14远程连接超时(CentOS 8)排查方案

你遇到的完整错误信息:

could not connect to server: Connection Timed out (0x0000274C/10060). Is the server running on host "xxx.xxx.xxx.xxx" and accepting TCP/IP connections on port 5432 ?

已经修改pg_hba.conf和postgresql.conf但仍超时,按以下步骤逐一排查:

  • 确认PostgreSQL服务状态与监听端口
    先确保服务正常运行:

    systemctl status postgresql-14
    

    再检查是否真的监听所有IP的5432端口:

    ss -tulpn | grep 5432
    

    输出需包含0.0.0.0:5432或[::]:5432,若仅显示127.0.0.1:5432,说明listen_addresses = '*'配置未生效,重启服务后再检查。

  • 检查CentOS 8防火墙规则
    CentOS 8默认使用firewalld,必须开放5432端口:

    firewall-cmd --add-port=5432/tcp --permanent
    firewall-cmd --reload
    

    验证端口是否开放:

    firewall-cmd --list-ports
    

    确保输出包含5432/tcp。

  • 测试VPN网络连通性
    在本地机器先确认能ping通服务器IP:

    ping xxx.xxx.xxx.xxx
    

    再测试5432端口是否可达:

    telnet xxx.xxx.xxx.xxx 5432
    # 或用nc(若已安装)
    nc -zv xxx.xxx.xxx.xxx 5432
    

    若telnet/nc提示无法连接,说明VPN路由存在问题,或服务器端有其他网络拦截。

  • 验证配置文件修改是否生效
    修改配置后必须重启服务才能生效:

    systemctl restart postgresql-14
    

    登录数据库确认监听配置:

    psql -U postgres -c "show listen_addresses;"
    

    输出应为*。再检查pg_hba规则:

    psql -U postgres -c "select * from pg_hba_file_rules;"
    

    确认列表中存在host all all 0.0.0.0/0 md5和host all all ::/0 md5条目。

  • 排查SELinux与云安全组
    检查SELinux状态:

    getenforce
    

    若为Enforcing,临时关闭测试:

    setenforce 0
    

    若能连接,永久允许PostgreSQL网络连接:

    setsebool -P postgresql_can_network_connect on
    

    若服务器在云平台,还需检查云安全组是否允许VPN网段IP访问5432端口。

内容的提问来源于stack exchange,提问作者Michael Halim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 08:10:22