AWS EC2(RHEL7.2)实例HTTP请求无响应问题求助
Hey there, let's work through this connectivity problem step by step. Since you can successfully curl http://localhost:12345/ from the EC2 instance itself, we know the Nginx container is running properly and the port mapping works locally—so the issue is almost certainly in the network layers between your local machine and the EC2 instance. Here are the key checks to run:
Verify your EC2 instance has public network access
- Make sure your instance has a public IP address (either an auto-assigned public IP or an Elastic IP attached). If you're using a private IP only, external devices can't reach it directly.
- Test pinging your instance's public IP from your local machine. If ping fails, check if your subnet's route table has a rule pointing to an Internet Gateway (IGW)—without this, the instance can't communicate with the public internet.
Double-check security group rules and association
- Even though you added port 12345 to the inbound rules, confirm the source address is set correctly. If you want open access, use
0.0.0.0/0(for IPv4) and::/0(for IPv6). Restricting to a specific IP range could block your local machine if it's not in that range. - Ensure the correct security group is actually attached to your EC2 instance. It's easy to create a new security group but forget to assign it to the instance—check the "Security groups" tab in your instance's details page to confirm.
- Even though you added port 12345 to the inbound rules, confirm the source address is set correctly. If you want open access, use
Inspect RHEL7.2's local firewall (firewalld/iptables)
- RHEL7 uses firewalld by default, which might be blocking external traffic to port 12345. Test temporarily stopping it with:
If external access works after this, add a permanent rule to allow the port:sudo systemctl stop firewalldsudo firewall-cmd --add-port=12345/tcp --permanent sudo firewall-cmd --reload - If you're using iptables instead, run
sudo iptables -L -nto check for rules that DROP or REJECT traffic on port 12345. Add an allow rule if needed.
- RHEL7 uses firewalld by default, which might be blocking external traffic to port 12345. Test temporarily stopping it with:
Confirm Docker's port mapping is bound to all interfaces
- Run
docker psto check the container's port status. You should see something like0.0.0.0:12345->80/tcpor:::12345->80/tcp. If it shows127.0.0.1:12345->80/tcp, the port is only bound to the local loopback interface—restart the container with the samedocker runcommand (the default-pflag binds to all interfaces, so this is likely a one-off glitch).
- Run
Check VPC Network Access Control Lists (NACLs)
- NACLs act as a subnet-level firewall, and they're stateless (you need to allow both inbound and outbound traffic). Go to the VPC console, find your instance's subnet, and verify:
- Inbound rules allow TCP traffic on port 12345 from
0.0.0.0/0 - Outbound rules allow TCP traffic on ephemeral ports (1024-65535) to
0.0.0.0/0(this lets the instance send responses back to your local machine)
- Inbound rules allow TCP traffic on port 12345 from
- NACLs act as a subnet-level firewall, and they're stateless (you need to allow both inbound and outbound traffic). Go to the VPC console, find your instance's subnet, and verify:
Test with raw tools to narrow down errors
- Instead of relying on a browser, use curl from your local machine to get specific error details:
A "connection refused" error points to a firewall/security group issue, while a timeout suggests the traffic isn't reaching the instance at all.curl http://<your-ec2-public-ip>:12345 -v
- Instead of relying on a browser, use curl from your local machine to get specific error details:
内容的提问来源于stack exchange,提问作者Rocky

