iPhone访问WordPress实例时IP被拦截的原因排查求助
端口临时拦截问题排查
环境配置
运行Arch Linux的Linode服务器,部署WordPress并使用Linux Server IO Swag容器,服务正常。已安装UFW和Tailscale,所有SSH流量通过Tailnet传输,UFW规则如下:
Status: active To Action From -- ------ ---- Anywhere on tailscale0 ALLOW Anywhere 80 ALLOW Anywhere 443 ALLOW Anywhere Anywhere (v6) on tailscale0 ALLOW Anywhere (v6)
问题现象
使用iPhone(Firefox for iOS)访问WordPress实例时,iPhone的公网IP会被临时拦截,测试过程如下:
- 初始端口扫描:
nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 21:50 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.034s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp open http 443/tcp open https Nmap done: 1 IP address (1 host up) scanned in 0.15 seconds
- iPhone访问指向同一服务器的另一个域名(路由到WordPress),约2秒后再次扫描:
nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 21:51 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.034s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp closed http 443/tcp closed https Nmap done: 1 IP address (1 host up) scanned in 0.11 seconds
VPN测试差异
- iPhone开启Mullvad VPN后,可找到WordPress实例,但点击1个链接后仍会被拦截;
- 笔记本电脑开启Mullvad VPN则可正常访问,测试过程:
[freek@freex ~]$ nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 21:54 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.033s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp closed http 443/tcp closed https Nmap done: 1 IP address (1 host up) scanned in 0.12 seconds [freek@freex ~]$ wg-quick up mullvad-se3 wg-quick must be run as root. Please enter the password for freek to continue: [#] ip link add mullvad-se3 type wireguard [#] wg setconf mullvad-se3 /dev/fd/63 [#] ip -4 address add 10.66.88.174/32 dev mullvad-se3 [#] ip -6 address add fc00:bbbb:bbbb:bb01::3:58ad/128 dev mullvad-se3 [#] ip link set mtu 1420 up dev mullvad-se3 [#] resolvconf -a mullvad-se3 -m 0 -x [#] wg set mullvad-se3 fwmark 51820 [#] ip -6 route add ::/0 dev mullvad-se3 table 51820 [#] ip -6 rule add not fwmark 51820 table 51820 [#] ip -6 rule add table main suppress_prefixlength 0 [#] nft -f /dev/fd/63 [#] ip -4 route add 0.0.0.0/0 dev mullvad-se3 table 51820 [#] ip -4 rule add not fwmark 51820 table 51820 [#] ip -4 rule add table main suppress_prefixlength 0 [#] sysctl -q net.ipv4.conf.all.src_valid_mark=1 [#] nft -f /dev/fd/63 [freek@freex ~]$ nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 21:54 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.050s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp open http 443/tcp open https Nmap done: 1 IP address (1 host up) scanned in 0.25 seconds
笔记本正常访问站点约10-20分钟后,私网IP对应的端口会重新开放。
禁用UFW后的测试结果
禁用UFW后问题仍存在,访问WordPress实例时持续扫描端口的结果如下:
nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 22:03 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.036s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp open http 443/tcp open https Nmap done: 1 IP address (1 host up) scanned in 0.16 seconds [freek@freex ~]$ nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 22:03 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.16s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp closed http 443/tcp filtered https Nmap done: 1 IP address (1 host up) scanned in 4.50 seconds [freek@freex ~]$ nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 22:03 CET Note: Host seems down. If it is really up, but blocking our ping probes, try -Pn Nmap done: 1 IP address (0 hosts up) scanned in 3.04 seconds [freek@freex ~]$ nmap -p 443,80 anacreon.domain.nl Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-05 22:03 CET Nmap scan report for anacreon.domain.nl (139.144.66.219) Host is up (0.27s latency). Other addresses for anacreon.domain.nl (not scanned): 2a01:7e01::f03c:93ff:fea2:10ab PORT STATE SERVICE 80/tcp closed http 443/tcp closed https Nmap done: 1 IP address (1 host up) scanned in 2.27 seconds
注:端口曾显示为filtered状态,且WordPress实例前启用了nginx基本认证。
疑问与排查需求
- 除UFW外未安装其他防火墙、fail2ban等工具,UFW规则也允许80/443端口流量,为何会出现临时拦截?
- iPhone正常访问为何会触发拦截?
- 有哪些进一步排查的建议?
内容的提问来源于stack exchange,提问作者Freek
相关产品推荐
相关产品推荐

