Google Compute Instance无法开启443端口的排查求助
Let’s work through this issue step by step—since you’ve confirmed the firewall rule appears in gcloud compute firewall-rules list but nmap reports port 443 as closed, the problem is likely either with your nginx configuration, the local instance firewall, or a mismatch in how the GCP firewall rule is applied.
First, let’s recap the nginx server config you shared:
server { listen 80; server_name example.com; return 301 https://$host$request_uri; } server { listen 443 ssl; server_name example.com; ssl_certificate /etc/nginx/ssl/example.com.crt; ssl_certificate_key /etc/nginx/ssl/example.com.key; ssl_protocols TLSv1.2 TLSv1.3; ssl_ciphers HIGH:!aNULL:!MD5; location / { root /var/www/example.com; index index.html index.htm; } }
Step 1: Verify nginx is actually listening on 443 (all interfaces)
The most common culprit here is nginx not binding to the public-facing interface. Run this command on your instance to check:
ss -tulpn | grep 443
You should see output like this (confirming nginx is listening on all interfaces 0.0.0.0:443):
LISTEN 0 128 0.0.0.0:443 0.0.0.0:* users:(("nginx",pid=1234,fd=6))
If you only see 127.0.0.1:443, nginx is only accepting local connections. Fix this by updating your 443 server block to explicitly listen on all interfaces:
listen 0.0.0.0:443 ssl;
Then reload nginx with sudo systemctl reload nginx.
Step 2: Check for nginx errors or service failures
Even if you think nginx is running, hidden errors (like missing certificates) might prevent it from listening on 443.
- Check the service status:
If it’s inactive or in a failed state, start it withsudo systemctl status nginxsudo systemctl start nginxand note any error messages. - Inspect the nginx error log for issues:
Common issues here:sudo tail -n 20 /var/log/nginx/error.log- Missing certificate files: Verify the paths in
ssl_certificateandssl_certificate_keyare correct withls -l /etc/nginx/ssl/. - Permissions on the private key: Run
sudo chmod 600 /etc/nginx/ssl/example.com.keyto ensure nginx can read it (private keys need strict permissions).
- Missing certificate files: Verify the paths in
Step 3: Validate your GCP Firewall Rule details
A rule showing up in the list doesn’t guarantee it’s applied to your instance. Describe the rule to confirm critical details:
gcloud compute firewall-rules describe YOUR_FIREWALL_RULE_NAME
Ensure these are correct:
- Target Tags: The rule’s
targetTagsmust match the tags assigned to your instance. Check your instance’s tags with:gcloud compute instances describe YOUR_INSTANCE_NAME --format='value(tags.items)' - Source Ranges: The
sourceRangesshould include the IP address you’re running nmap from (use0.0.0.0/0to allow all external traffic, if intended). - Allowed Traffic: The
allowedfield must explicitly listtcp:443(e.g.,IPProtocol: tcp, ports: 443).
Step 4: Check the instance’s local firewall
Most Linux distros include a local firewall (like ufw or firewalld) that can block traffic even if GCP’s firewall allows it.
- For Ubuntu/Debian (ufw):
If there’s no rule allowing 443, add it with:sudo ufw statussudo ufw allow 443/tcp - For CentOS/RHEL (firewalld):
Ifsudo firewall-cmd --list-allhttpsisn’t in theserviceslist, add it permanently:sudo firewall-cmd --add-service=https --permanent && sudo firewall-cmd --reload
Step 5: Confirm you’re scanning the correct IP
Double-check that you’re running nmap against your instance’s public IP address (not the internal private IP). Get the public IP with:
gcloud compute instances describe YOUR_INSTANCE_NAME --format='value(networkInterfaces.accessConfigs.natIP)'
After working through these steps, run nmap again—your 443 port should now show as open if everything is configured correctly.
内容的提问来源于stack exchange,提问作者cclloyd

