Amazon EC2实例无法访问80端口运行的Node服务器求助
Hey there, let’s work through this step by step to get your Node.js server on port 80 accessible over the internet. I’ve debugged this exact scenario dozens of times, so here’s what to check:
First off, if your server is only listening on localhost (127.0.0.1), it’ll only respond to internal requests—external traffic can’t reach it.
To verify, run this command on your instance:
ss -tulpn | grep :80
Look for a line that says LISTEN with an address like 0.0.0.0:80 or :::80 (for IPv6). If you see 127.0.0.1:80, you need to update your Node code to listen on all interfaces:
// Change from this: app.listen(80); // To this: app.listen(80, '0.0.0.0', () => { console.log('Server running on port 80, accessible externally'); });
Restart your Node server after making this change.
Even if your cloud security group allows port 80, your instance’s internal firewall might be blocking traffic.
For Ubuntu/Debian systems, check UFW status:
ufw statusIf you don’t see
80/tcplisted as allowed, add it:ufw allow 80/tcp ufw reloadFor CentOS/RHEL/Rocky Linux, check firewalld:
firewall-cmd --list-portsIf 80/tcp is missing, add it permanently:
firewall-cmd --add-port=80/tcp --permanent firewall-cmd --reload
Double-check that you’re using the correct public IP to access the server. Some cloud instances require an Elastic Public IP (EIP) assigned to them—not just associating an Internet Gateway (IGW) with the VPC.
Also, confirm the instance has a default route pointing to the IGW:
ip route
You should see a line like default via <IGW-IP> dev <network-interface>. If not, your instance can’t send traffic out to the internet, which means external requests can’t get a response.
Use a tool like telnet or nc from another machine (or your local computer) to test if port 80 is open:
# Using nc nc -zv <your-public-ip> 80 # Using telnet telnet <your-public-ip> 80
If you get a "connection refused" or "timeout" error, go back to steps 1-3—something’s still blocking traffic. If it connects, the issue might be with your Node server’s response logic (but you said the internal state is normal, so this is less likely).
It’s easy to miss a detail here:
- Ensure your security group has an inbound rule allowing
0.0.0.0/0(or your specific IP range) forTCP port 80. - Confirm the security group is actually attached to your instance—sometimes users edit the right group but forget to associate it with the VM.
- Check rule priorities: If there’s a deny rule above your allow rule, it’ll block traffic regardless of the allow rule.
Some cloud providers have extra hoops for port 80:
- For example, AWS requires that your instance has a public IP (or EIP) and that the subnet’s route table includes the IGW.
- In China-based cloud services, you might need to complete an ICP filing to use port 80 for public websites.
- Some providers block port 80 by default—you may need to request access or use a reverse proxy on a different port (like 8080) if that’s the case.
Start with step 1, since that’s the most common mistake, and work your way down. Let me know which step uncovers the issue!
内容的提问来源于stack exchange,提问作者mcpolandc

