IIS技术求助:前端服务器无法连接后端部署的网站
First, let's align on your scenario to make sure I'm addressing the right problem:
You've deployed a site on IIS at backend server
xx.xx.xx.175, which works perfectly vialocalhost:3000directly on the server. But the frontend serverxx.xx.xx.174can't reach it—even after updating IIS bindings, adjusting firewall rules, and runningnetsh http add iplisten.
Since you've already knocked out the common fixes, let's dive into some less obvious checks to narrow down the root cause:
Double-check your IIS site binding's IP scope
- Open IIS Manager, navigate to your site > Bindings. Ensure the binding is set to either
*:3000(listens on all server IPs) or explicitly toxx.xx.xx.175:3000—not justlocalhost:3000. It’s easy to overlook updating this from the default localhost setting when deploying for external access. - Run
netsh http show servicestatein an admin command prompt onxx.xx.xx.175. Look for your site's entry and confirm it’s listening on0.0.0.0:3000orxx.xx.xx.175:3000. If it only shows127.0.0.1:3000, that’s why external servers can’t connect.
- Open IIS Manager, navigate to your site > Bindings. Ensure the binding is set to either
Test raw network connectivity between the two servers
- On the frontend server (
xx.xx.xx.174), open a command prompt and runtelnet xx.xx.xx.175 3000. If this fails, the port is still blocked at the network level—whether by a firewall, network ACL, or intermediate router. - If telnet isn’t installed, use PowerShell:
Test-NetConnection xx.xx.xx.175 -Port 3000. Check theTcpTestSucceededresult; if it’sFalse, prioritize fixing network-level blocking.
- On the frontend server (
Validate firewall rule details on
xx.xx.xx.175- Even if you added a rule, confirm it allows incoming connections on port 3000 for all relevant network profiles (Domain, Private, Public—depending on your server’s network setup). Rules sometimes get restricted to only one profile by mistake.
- Ensure the rule targets the TCP protocol (IIS uses TCP for HTTP) and isn’t limited to specific IPs that exclude
xx.xx.xx.174.
Check if your application is restricted to localhost
- Since your port is 3000 (common for Node.js apps), it’s possible the app itself is configured to listen only on
localhostor127.0.0.1. For example, in Node.js, you’d needapp.listen(3000, '0.0.0.0')instead of justapp.listen(3000)to allow external connections. Double-check your app’s startup configuration.
- Since your port is 3000 (common for Node.js apps), it’s possible the app itself is configured to listen only on
Rule out intermediate network devices
- If these servers are on a corporate network, there might be a reverse proxy, load balancer, or firewall between
xx.xx.xx.174andxx.xx.xx.175blocking port 3000. Reach out to your network admin to confirm if this port is allowed through any intermediate hardware.
- If these servers are on a corporate network, there might be a reverse proxy, load balancer, or firewall between
Inspect IIS URL Rewrite/ARR rules
- If you have URL Rewrite or Application Request Routing (ARR) set up, these could be redirecting or blocking requests from external IPs. Temporarily disable any non-essential rules to see if that resolves the issue.
Capture traffic with Wireshark
- Run Wireshark on either server to capture traffic on port 3000. When you attempt to access the site from
xx.xx.xx.174, check if the request even reachesxx.xx.xx.175. If not, it’s a network problem; if it does reach but gets no response, focus on IIS or application-level issues.
- Run Wireshark on either server to capture traffic on port 3000. When you attempt to access the site from
Let me know which of these checks turns up something—this should help you zero in on the fix.
内容的提问来源于stack exchange,提问作者giff1

