You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

配置Cloudflare后非443 HTTPS端口报523错误,求排查方案

Troubleshooting 523 Origin Unreachable on Non-443 HTTPS Ports with Cloudflare

Let’s break down the most likely causes for this issue—especially since it persists even when Apache is stopped:

1. Cloudflare Free Tier Port Restrictions

First, confirm if the ports you’re testing are allowed on Cloudflare’s free plan. Cloudflare only proxies specific HTTPS ports by default for free users:

  • 443, 2053, 2083, 2087, 2096, 8443

If you’re using any other HTTPS port (like 8080, 8444, etc.), Cloudflare won’t forward traffic to your origin server for those ports. This directly leads to a 523 error because Cloudflare can’t reach an endpoint it’s configured to proxy. To check this, look in your Cloudflare dashboard under Network > Origin Port Rules (or SSL/TLS > Edge Certificates depending on your plan)—note that custom port forwarding is typically a paid feature.

2. Firewall Blocking Cloudflare IP Ranges

Even if your server’s firewall allows the non-443 ports, it might be blocking incoming traffic from Cloudflare’s IP addresses. Cloudflare proxies all traffic through its own IPs, so your origin server needs to accept connections from Cloudflare’s ranges on those ports.

To verify:

  • Temporarily allow all incoming traffic on the problematic port (e.g., sudo ufw allow 8443/tcp if using UFW) and test again. If the error disappears, you’ll need to add Cloudflare’s IP ranges to your firewall rules.
  • Fetch Cloudflare’s IPs with curl https://www.cloudflare.com/ips-v4 and curl https://www.cloudflare.com/ips-v6, then add them to your firewall for the relevant ports.

3. Origin Server Not Listening on Non-443 Ports

When Apache is running, make sure it’s actually configured to listen on the non-443 HTTPS ports. Check your Apache virtual host files for lines like:

<VirtualHost *:8443>
    SSLEngine on
    SSLCertificateFile /path/to/your/cert.pem
    SSLCertificateKeyFile /path/to/your/key.pem
    # Additional site config
</VirtualHost>

Confirm Apache is listening on those ports with sudo netstat -tulpn | grep apache2 (or ss -tulpn | grep httpd on RHEL-based systems). If Apache isn’t listening on those ports, even with Cloudflare set up, you’ll get a 523 because there’s nothing to connect to.

4. Cloudflare Proxy or Rule Conflicts

Double-check your Cloudflare DNS and rule settings:

  • Ensure your domain’s DNS record is set to Proxied (orange cloud), not DNS-only. (443 working suggests this is already correct, but it’s worth confirming.)
  • Look for any Page Rules or Firewall Rules that might block traffic on non-443 ports. For example, a rule that redirects all traffic to 443 could interfere, though that usually returns a redirect instead of 523.

Next Debugging Steps

To narrow it down further:

  • Use Cloudflare’s Diagnostics > Trace Route tool to see where the connection to your origin fails on the problematic port.
  • Test connecting directly to your server’s public IP on the non-443 port from an external network (not your local one) using curl -v https://your-server-ip:port. If this fails, the issue is with your server’s configuration (firewall, Apache listening, etc.), not Cloudflare.

Share your Apache virtual host config or Cloudflare port rules if you want help pinpointing the exact issue.

内容的提问来源于stack exchange,提问作者iReal Worlds

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 03:40:49