Oracle Cloud Ubuntu实例中WireGuard环境下19132端口无法开放的问题求助
Hey there, I totally get the frustration here—trying to get a Minecraft Bedrock server up for friends while stuck behind CGNAT is already a hassle, and then hitting port issues on top of that? Ugh, been there. Let me break down what I’m dealing with and ask for some guidance:
For the past couple of weeks, I’ve been trying to set up a Minecraft Bedrock server on my computer for me and my friends. But since I’m behind CGNAT, port forwarding directly isn’t an option. So I spun up an Ubuntu instance on Oracle Cloud with WireGuard—followed a YouTube tutorial (with only basic Linux knowledge) and got WireGuard working perfectly. I set up ingress rules the same way I did for WireGuard, but when I use a port checker tool, it says port 19132 is closed. I’m stuck and have no clue what to do next—any tips would be really appreciated!
wg0.conf
[Interface] Address = 10.16.0.1/32 ListenPort = 51820 PrivateKey = SNIP PreUp = sysctl -w net.ipv4.ip_forward=1 PostUp = iptables -I INPUT -p udp --dport 51820 -j ACCEPT; iptables -t nat -I POSTROUTING 1 -s 10.16.0.0/24 -o ens3 -j MASQUERADE; iptables -I INPUT 1 -i wg0 -j ACCEPT; iptables -I FORWARD 1 -i ens3 -o wg0 -j ACCEPT; iptables -I FORWARD -i wg0 -o ens3 -j ACCEPT; iptables -I INPUT -p udp --dport 19132 -j ACCEPT PostDown = [未完成内容]
一些可能的排查方向
- 核对Oracle Cloud安全规则:确保你在实例的安全列表(Security List)里明确添加了UDP 19132的Ingress规则,来源范围设为
0.0.0.0/0(或者你需要的特定IP段)。有时候复制WireGuard的规则时容易忘改端口号,这是常见坑点。 - 验证iptables规则是否生效:在Ubuntu实例上运行
iptables -L -n -v和iptables -t nat -L -n -v,仔细检查UDP 19132的ACCEPT规则是不是真的出现在INPUT链里。PostUp脚本里的命令如果有拼写错误(比如端口号打错),规则就不会生效。 - 确认Bedrock服务器的监听状态:在运行Bedrock服务器的机器上,执行
ss -ulpn | grep 19132,看看有没有进程在监听UDP 19132端口。如果服务器没启动、配置错了端口,或者监听的是TCP(Bedrock用的是UDP),那端口检查肯定会显示关闭。 - 检查WireGuard路由与转发规则:确保你的Bedrock服务器在
10.16.0.0/24网段内,并且Ubuntu实例的iptables允许UDP 19132流量在ens3(公网网卡)和wg0(WireGuard网卡)之间转发。你当前的PostUp里有FORWARD规则,但可以确认下是否覆盖了19132的流量走向。 - 测试内部访问:从已连接WireGuard的设备上,直接尝试访问Bedrock服务器的WireGuard IP:19132。有时候公网端口检测工具因为WireGuard隧道的原因没法穿透,但内部访问可能是正常的——如果能连上,说明问题出在公网端口转发的配置上。
- 检查UFW防火墙状态:如果Ubuntu的UFW是开启的,记得添加允许UDP 19132的规则,或者确保你的iptables规则优先级高于UFW。运行
ufw status就能看到当前的防火墙规则。
备注:内容来源于stack exchange,提问作者William Letzepis

