AWS Ubuntu实例上Django服务器无法访问问题求助
Hey there, let's work through this connectivity issue step by step—you’ve already checked the core basics, so let’s dive into the often-overlooked details that could be blocking your public access:
1. Verify AWS Network ACLs (Subnet-Level Firewall)
Security groups are instance-level, but Network ACLs (NACLs) act as a subnet-level firewall that can override your security group rules. Even if your security group allows 8000, a restrictive NACL will block traffic:
- Head to the AWS EC2 Console → VPC Dashboard → Network ACLs
- Find the NACL attached to your EC2 instance’s subnet
- Ensure inbound rules allow
0.0.0.0/0on TCP port 8000 - Ensure outbound rules allow ephemeral ports (1024-65535) for TCP—this lets your server send responses back to the client
Note: NACLs are stateless, so you need explicit allow rules for both inbound and outbound traffic.
2. Check if Your EC2 Instance Uses the Correct Firewall Tool
Not all AWS AMIs use ufw—for example, Amazon Linux 2/3 uses firewalld by default. Running ufw commands won’t affect a firewalld-enabled system:
- Check if firewalld is active:
sudo systemctl status firewalld - If it’s running, add the 8000 port rule and reload:
sudo firewall-cmd --add-port=8000/tcp --permanent sudo firewall-cmd --reload - Verify open ports with:
sudo firewall-cmd --list-ports
3. Confirm Local Connectivity to Django
Make sure the Django service is actually responding, not just listening on the port:
- On your EC2 instance, run:
curl http://localhost:8000 - If this returns a Django error page or your app content, the service is working. If it times out or fails, your Django service might be stuck (try running
python manage.py runserverin foreground mode to see real-time error logs).
4. Validate Your VPC Route Table
If your EC2 instance is in a VPC, its subnet’s route table must have a route to the Internet Gateway (IGW) for public access:
- Go to EC2 Console → Instances → Select your instance → Check the "Subnet ID" under "Networking"
- Go to VPC Dashboard → Route Tables → Find the table associated with that subnet
- Look for a route entry where
Destinationis0.0.0.0/0andTargetis an IGW (starts withigw-). If this route is missing, your instance can’t reach the public internet.
5. Ensure Your EC2 Instance Has a Public IP
Double-check that your instance has a valid public IP assigned:
- In the EC2 instance details, look for "Public IPv4 address"—if it’s blank, you might need to:
- Assign an Elastic IP (static public IP) to the instance
- Or enable "Auto-assign public IP" for the subnet (if you’re launching new instances)
6. Rule Out ISP or Local Network Restrictions
Sometimes your local ISP blocks unusual ports like 8000. Test access from a different network (e.g., mobile data) or use a tool like telnet from another server to check port connectivity:
telnet xxx.xxx.xxx.xxx 8000
If this connects, the issue is likely with your local network; if it times out, the problem is still on the AWS side.
内容的提问来源于stack exchange,提问作者Pavan Kumar T S

