AWS EC2 Ubuntu16.04部署Apache2后无法访问问题求助
Alright, let's walk through the most likely reasons your Apache2 default site isn't accessible on your Ubuntu 16.04 EC2 instance—even with port 80 allowed in security groups:
Apache2 isn't actually listening on port 80
Just because Apache is running doesn't mean it's bound to port 80. Verify this with:sudo netstat -tulpn | grep apache2Or if
netstatisn't installed, use:ss -tulpn | grep apache2If you don't see
:80in the output, check Apache's port config at/etc/apache2/ports.conf(ensure it hasListen 80) and the default site config at/etc/apache2/sites-available/000-default.conf(confirm<VirtualHost *:80>is set). Fix any issues, then restart Apache:sudo systemctl restart apache2Ubuntu's UFW firewall is blocking port 80
AWS security groups are great, but Ubuntu's built-in UFW firewall can still block incoming traffic even if the security group allows it. Check UFW's status:sudo ufw statusIf port 80 isn't listed as allowed, add the rule:
sudo ufw allow 80/tcpDouble-check the status to confirm the rule is active.
Your EC2 instance isn't in a public subnet
The public DNS you're using (ec2-3-231-162-52.compute-1.amazonaws.com) maps to a public IP, but your instance needs to be in a public subnet to be reachable from the internet. A public subnet has a route table entry pointing to an Internet Gateway (IGW). If your instance is in a private subnet, you'll need to set up a load balancer or move it to a public subnet to access it directly.The Apache2 default site isn't enabled
While Ubuntu 16.04 usually enables the default site automatically during installation, it's worth verifying:sudo a2query -sIf
000-defaultisn't listed, enable it with:sudo a2ensite 000-default.confThen restart Apache to apply the change.
VPC Network ACLs are blocking traffic
Network ACLs (NACLs) are a second layer of firewall in AWS VPCs. Unlike security groups, they're stateless, so you need to allow both incoming port 80 traffic and outgoing response traffic (typically TCP ports 1024-65535). Head to the AWS VPC console, find the NACL attached to your instance's subnet, and confirm:- Inbound rules allow
0.0.0.0/0on TCP port 80 - Outbound rules allow
0.0.0.0/0on TCP ports 1024-65535
- Inbound rules allow
Apache2 has configuration errors or file permission issues
Even if Apache is running, misconfigurations or permission problems can break access. Check the Apache error log for clues:sudo tail -f /var/log/apache2/error.logCommon issues include syntax errors in config files, or incorrect permissions on the default web root (
/var/www/html). Ensure thewww-datauser has read access to files in this directory:sudo chown -R www-data:www-data /var/www/html
内容的提问来源于stack exchange,提问作者Peter Szabo

