如何允许指定外部IP访问本地TCP端口及取消授权(Redis场景)
Alright, let's walk through exactly how to grant a specific external IP access to your local Redis instance, then how to revoke that access later. We'll cover both the firewall (the critical first layer) and Redis's own config since Redis locks down local access by default.
First, we need to adjust two core components: Redis's network settings, and your server's firewall to whitelist the target external IP.
1. Update Redis Configuration to Accept External Connections
Redis is configured to only listen on 127.0.0.1 (localhost) out of the box. We need to modify this to let it accept connections from your server's public network interface:
- Open the Redis config file with sudo privileges (path may vary slightly, e.g.,
/etc/redis/redis.confor/etc/redis/6379.conf):sudo nano /etc/redis/redis.conf - Find the
bindline (it might be commented out or set to127.0.0.1). Change it to:
This makes Redis listen on all network interfaces. If you prefer tighter control, replacebind 0.0.0.00.0.0.0with your server's public IP instead. - Look for
protected-modeand set it tono(only if you aren't setting a Redis password—highly recommend setting a password regardless, see the notes below):protected-mode no - Save and close the file (in nano: press
Ctrl+O, hitEnter, thenCtrl+X). - Restart Redis to apply changes:
sudo systemctl restart redis-server
2. Add Firewall Rule to Whitelist the Specific External IP
Next, we'll update the firewall to only let the target external IP connect to Redis's default port (6379). Below are steps for the two most common Linux firewalls:
For UFW Users (Ubuntu/Debian)
- Add the allow rule, replacing
<EXTERNAL_IP>with the actual IP you want to grant access:sudo ufw allow from <EXTERNAL_IP> to any port 6379 - Reload UFW to apply the rule:
sudo ufw reload - Verify the rule exists:
You should see a line likesudo ufw statusALLOW <EXTERNAL_IP> 6379/tcp.
For IPTables Users (General Linux)
- Add the input rule to accept traffic from the target IP on port 6379:
sudo iptables -A INPUT -p tcp -s <EXTERNAL_IP> --dport 6379 -j ACCEPT - Save the rules to make them persist after reboot (command varies by distro):
- Ubuntu/Debian:
sudo netfilter-persistent save - CentOS/RHEL:
sudo service iptables save
- Ubuntu/Debian:
- Verify the rule:
sudo iptables -L INPUT -v
To remove the access, reverse the steps above—first delete the firewall rule, then lock Redis back down to local-only connections.
1. Remove the Firewall Rule
For UFW Users
- Either delete the rule by its number (first list numbered rules):
Then run:sudo ufw status numberedsudo ufw delete <RULE_NUMBER> - Or delete it directly using the original rule syntax:
sudo ufw delete allow from <EXTERNAL_IP> to any port 6379 - Reload UFW to apply changes:
sudo ufw reload
For IPTables Users
- First list the input rules with line numbers:
sudo iptables -L INPUT --line-numbers - Delete the rule corresponding to the allowed IP (replace
<LINE_NUMBER>):sudo iptables -D INPUT <LINE_NUMBER> - Save the updated rules to persist:
- Ubuntu/Debian:
sudo netfilter-persistent save - CentOS/RHEL:
sudo service iptables save
- Ubuntu/Debian:
2. Restore Redis to Local-Only Access
- Reopen the Redis config file:
sudo nano /etc/redis/redis.conf - Change the
bindline back to:bind 127.0.0.1 - Set
protected-modeback toyesif you disabled it earlier:protected-mode yes - Save and close the file, then restart Redis:
sudo systemctl restart redis-server
Important Notes
- Always set a Redis password: In the config file, find
requirepassand set it to a strong, unique password (e.g.,requirepass YourStrongRedisPassword123!). This adds a second layer of protection even if the firewall rule is misconfigured. - Test the connection: From the external node, run
redis-cli -h <YOUR_SERVER_PUBLIC_IP> -p 6379to test access. If you set a password, useAUTH YourStrongRedisPassword123!after connecting, or include-a YourStrongRedisPassword123!in the initial command. - Static IP check: Ensure the external IP you're whitelisting is static—if it changes, the firewall rule will stop working.
内容的提问来源于stack exchange,提问作者Blender

