如何在AWS EC2 Windows实例开启多端口以部署多网站
Hey there! Let's figure out why your sites on ports 81 and 82 aren't reachable from outside, even though port 80 works and local access is fine. This is a super common gotcha with AWS, so let's walk through the key checks step by step:
Re-validate your AWS Security Group Inbound Rules
Even with your screenshot, let's confirm a few critical details:- Make sure there are explicit rules allowing TCP traffic on ports 81 and 82 from your desired source (use
0.0.0.0/0for public access, or a specific IP range if you want restricted access). - Double-check that this security group is actually attached to your EC2 instance—it's easy to accidentally apply rules to a different security group and miss this.
- Don't mix up inbound/outbound rules: outbound usually defaults to all traffic allowed, but inbound requires explicit allowances for non-standard ports.
- Make sure there are explicit rules allowing TCP traffic on ports 81 and 82 from your desired source (use
Check your EC2 instance's local firewall
Local access works, but the instance itself might be blocking external traffic on 81/82. Here's how to verify:- For Linux instances: Run these commands to check active firewall rules:
If you don't see rules allowing inbound traffic on 81/82, add them (e.g.,sudo ufw status # If using UFW sudo iptables -L -n | grep -E '81|82' # For iptablessudo ufw allow 81/tcp). - For Windows instances: Open Windows Defender Firewall > Advanced Settings, and confirm there's an inbound rule allowing TCP traffic on 81 and 82.
- For Linux instances: Run these commands to check active firewall rules:
Verify your web server's listening configuration
Ensure your web server (Nginx, Apache, IIS, etc.) is listening on the correct ports and bound to a public-facing address, not just localhost:- Use this command to check which ports are actively listening and their bound addresses (Linux):
(Windows equivalent:netstat -tulpn | grep -E '81|82'netstat -ano | findstr "81 82") - Look for entries where the address is
0.0.0.0:81or your public IP123.34.56.90:81—if it's only127.0.0.1:81, the server will only respond to local requests. Adjust your web server config to listen on all interfaces.
- Use this command to check which ports are actively listening and their bound addresses (Linux):
Check VPC Network ACLs (if applicable)
If your EC2 is in a VPC, Network ACLs (NACLs) act as a VPC-level firewall. Unlike security groups, NACLs are stateless, so you need to allow both inbound traffic on 81/82 and outbound return traffic (usually ephemeral ports 1024-65535).- Head to the VPC console, find your subnet's NACL, and confirm inbound rules allow TCP 81/82, and outbound rules allow the return traffic.
Test from a different external network
Sometimes local ISPs or corporate firewalls block non-standard ports like 81/82. Try accessing the sites using mobile data or a different network to rule out this possibility.
内容的提问来源于stack exchange,提问作者Gaurav Badyal

