Azure虚拟机上CDH Manager Web门户无法访问问题排查求助
Let’s work through this step by step—since you already configured the Azure NSG, the issue is likely on the VM itself or a subtle NSG misconfiguration. Here's what to check:
1. Verify CDH Manager Service is Running First
If the service isn’t up, nothing will listen on 7180. Log into your RHEL VM via SSH and run:
systemctl status cloudera-scm-server
If it shows inactive or failed, start it with:
systemctl start cloudera-scm-server
For startup failures, debug using the service logs:
tail -f /var/log/cloudera-scm-server/cloudera-scm-server.log
Common culprits here are database connection issues (CDH uses PostgreSQL by default) or missing system dependencies.
2. Check VM Internal Firewall (firewalld/iptables)
Azure NSG rules are great, but RHEL’s local firewall might still block the port.
For firewalld (default on newer RHEL):
Check if 7180 is allowed:
firewall-cmd --list-all
If 7180/tcp doesn’t appear in the ports section, add it permanently:
firewall-cmd --add-port=7180/tcp --permanent firewall-cmd --reload
For iptables (older RHEL versions):
List current rules:
iptables -L
Add an accept rule for 7180:
iptables -A INPUT -p tcp --dport 7180 -j ACCEPT service iptables save
3. Confirm CDH Manager is Binding to All Network Interfaces
Sometimes CDH Manager only listens on localhost (127.0.0.1), which blocks external connections. Check which IP the service is bound to:
ss -tulpn | grep 7180
If the output shows 127.0.0.1:7180 instead of 0.0.0.0:7180, update the CDH config:
- Edit the default config file:
vi /etc/default/cloudera-scm-server - Add or modify this line (replace
<VM_PUBLIC_IP>with your VM’s public IP, or private IP if accessing from the Azure VNet):CMF_JAVA_OPTS="-Djava.rmi.server.hostname=<VM_PUBLIC_IP> -Dcom.sun.management.jmxremote.host=<VM_PUBLIC_IP>" - Restart the service:
Recheck the listening port with thesystemctl restart cloudera-scm-serversscommand—it should now show0.0.0.0:7180.
4. Double-Check Azure NSG Configuration Details
Even if you added a rule, small mistakes can break it:
- Ensure the rule is Inbound (not Outbound).
- Protocol is set to TCP (CDH Manager uses TCP for 7180).
- Source is
0.0.0.0/0(any origin) or your specific IP range. - Priority is set lower than default deny rules (e.g., 100–999—lower numbers mean higher priority).
- Confirm the NSG is attached to your VM’s subnet or the VM itself (NSGs don’t work if unlinked to the right resource).
- Make sure you’re accessing the VM’s public IP address (not private IP) unless you’re on the same Azure VNet.
5. Check SELinux Enforcement
SELinux can block network traffic even if firewalls are open. Check its status:
getenforce
If it returns Enforcing, temporarily disable it to test:
setenforce 0
Try accessing 7180 again. If it works, choose one of these permanent fixes:
- Set SELinux to permissive: Edit
/etc/selinux/configand changeSELINUX=enforcingtoSELINUX=permissive, then reboot. - Or allow port 7180 through SELinux (more secure):
semanage port -a -t http_port_t -p tcp 7180
Go through these steps one by one—most of the time, the issue is either the local firewall, a stopped service, or CDH binding to localhost.
内容的提问来源于stack exchange,提问作者Vignesh

