You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Google Compute Instance无法开启443端口的排查求助

Troubleshooting Closed 443 Port on Google Compute Instance

Let’s work through this issue step by step—since you’ve confirmed the firewall rule appears in gcloud compute firewall-rules list but nmap reports port 443 as closed, the problem is likely either with your nginx configuration, the local instance firewall, or a mismatch in how the GCP firewall rule is applied.

First, let’s recap the nginx server config you shared:

server {
    listen 80;
    server_name example.com;
    return 301 https://$host$request_uri;
}

server {
    listen 443 ssl;
    server_name example.com;

    ssl_certificate /etc/nginx/ssl/example.com.crt;
    ssl_certificate_key /etc/nginx/ssl/example.com.key;

    ssl_protocols TLSv1.2 TLSv1.3;
    ssl_ciphers HIGH:!aNULL:!MD5;

    location / {
        root /var/www/example.com;
        index index.html index.htm;
    }
}

Step 1: Verify nginx is actually listening on 443 (all interfaces)

The most common culprit here is nginx not binding to the public-facing interface. Run this command on your instance to check:

ss -tulpn | grep 443

You should see output like this (confirming nginx is listening on all interfaces 0.0.0.0:443):

LISTEN 0      128          0.0.0.0:443        0.0.0.0:*    users:(("nginx",pid=1234,fd=6))

If you only see 127.0.0.1:443, nginx is only accepting local connections. Fix this by updating your 443 server block to explicitly listen on all interfaces:

listen 0.0.0.0:443 ssl;

Then reload nginx with sudo systemctl reload nginx.

Step 2: Check for nginx errors or service failures

Even if you think nginx is running, hidden errors (like missing certificates) might prevent it from listening on 443.

  • Check the service status:
    sudo systemctl status nginx
    
    If it’s inactive or in a failed state, start it with sudo systemctl start nginx and note any error messages.
  • Inspect the nginx error log for issues:
    sudo tail -n 20 /var/log/nginx/error.log
    
    Common issues here:
    • Missing certificate files: Verify the paths in ssl_certificate and ssl_certificate_key are correct with ls -l /etc/nginx/ssl/.
    • Permissions on the private key: Run sudo chmod 600 /etc/nginx/ssl/example.com.key to ensure nginx can read it (private keys need strict permissions).

Step 3: Validate your GCP Firewall Rule details

A rule showing up in the list doesn’t guarantee it’s applied to your instance. Describe the rule to confirm critical details:

gcloud compute firewall-rules describe YOUR_FIREWALL_RULE_NAME

Ensure these are correct:

  • Target Tags: The rule’s targetTags must match the tags assigned to your instance. Check your instance’s tags with:
    gcloud compute instances describe YOUR_INSTANCE_NAME --format='value(tags.items)'
    
  • Source Ranges: The sourceRanges should include the IP address you’re running nmap from (use 0.0.0.0/0 to allow all external traffic, if intended).
  • Allowed Traffic: The allowed field must explicitly list tcp:443 (e.g., IPProtocol: tcp, ports: 443).

Step 4: Check the instance’s local firewall

Most Linux distros include a local firewall (like ufw or firewalld) that can block traffic even if GCP’s firewall allows it.

  • For Ubuntu/Debian (ufw):
    sudo ufw status
    
    If there’s no rule allowing 443, add it with:
    sudo ufw allow 443/tcp
    
  • For CentOS/RHEL (firewalld):
    sudo firewall-cmd --list-all
    
    If https isn’t in the services list, add it permanently:
    sudo firewall-cmd --add-service=https --permanent && sudo firewall-cmd --reload
    

Step 5: Confirm you’re scanning the correct IP

Double-check that you’re running nmap against your instance’s public IP address (not the internal private IP). Get the public IP with:

gcloud compute instances describe YOUR_INSTANCE_NAME --format='value(networkInterfaces.accessConfigs.natIP)'

After working through these steps, run nmap again—your 443 port should now show as open if everything is configured correctly.

内容的提问来源于stack exchange,提问作者cclloyd

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:40:43