无法远程访问AWS EC2实例上的Node.js/Nginx服务求助
It sounds like you’ve already checked some key basics, but let’s walk through a few more targeted steps to figure out why you can’t reach your servers from the browser:
1. Confirm your server is listening on all network interfaces
When curl localhost works but external access doesn’t, a common culprit is that the service is only bound to the loopback address (127.0.0.1) instead of all interfaces (0.0.0.0).
- For Node.js: Double-check your server code—make sure you’re using
app.listen(port, '0.0.0.0')instead oflocalhostor127.0.0.1. - For Nginx: Verify your server block config (usually in
/etc/nginx/sites-available/default) haslisten 80;orlisten 0.0.0.0:80;(not restricted to127.0.0.1).
To confirm, run this command on your EC2 instance to see which IPs your services are listening on:
netstat -tulpn | grep -E '(nginx|node)'
Look for entries where the "Local Address" starts with 0.0.0.0 or :: (for IPv6) instead of 127.0.0.1.
2. Check the instance's local firewall
Even if your security groups are wide open, the EC2 instance’s internal firewall might be blocking incoming traffic.
For Ubuntu/Debian systems: Check the status of
ufw(Uncomplicated Firewall):sudo ufw statusIf it’s active, make sure your ports (e.g., 80 for Nginx, whatever port your Node.js app uses) are allowed. Add them if needed with
sudo ufw allow <port>.For RHEL/CentOS/Amazon Linux: Check
iptablesrules:sudo iptables -LLook for rules that accept incoming traffic on your target ports. If missing, you’ll need to add them or disable
iptablestemporarily to test.
3. Verify your subnet's route table
Having an internet gateway attached to your VPC isn’t enough—your instance’s subnet must have a route that directs external traffic to the gateway.
- Go to the AWS VPC Console, find the subnet your EC2 instance is in.
- Click on its associated route table.
- Ensure there’s a route with Destination: 0.0.0.0/0 and Target: your internet gateway ID. If this route is missing, add it.
4. Test connectivity from your local machine
From your own computer (not the EC2 instance), run these tests to narrow down the issue:
Ping the public IP:
ping <your-ec2-public-ip>- If ping times out: This points to a network routing issue (security groups, route table, or possibly your local ISP blocking ICMP).
- If ping works but the browser doesn’t: Likely a port-specific issue (server not listening on the right interface, local firewall blocking the port).
Telnet to the port:
telnet <your-ec2-public-ip> 80(replace 80 with your Node.js port if testing that)- If you get "Connection refused": The server isn’t listening on that port, or the instance’s local firewall is blocking it.
- If you get a timeout: Network traffic isn’t reaching the instance (security groups or route table problem).
5. Double-check your public IP assignment
Make sure your EC2 instance actually has a public IPv4 address assigned. You can confirm this in the EC2 Console under your instance’s "Details" tab. If you’re using an Elastic IP, ensure it’s correctly associated with your instance (sometimes folks attach it to the wrong instance by accident).
内容的提问来源于stack exchange,提问作者Chandana Deshmukh

