Cassandra节点无法互通:AWS EC2集群端口监听与连通问题求助
Hey there, let's work through this Cassandra connectivity issue step by step—those timeout errors usually boil down to a few common culprits, so let's check each one:
1. First, Confirm Cassandra is Actually Running
It sounds obvious, but if Cassandra isn't started, it won't listen on port 7000 at all. Run these commands to verify:
- Check service status:
sudo systemctl status cassandra - If it's inactive, start it and enable auto-start on boot:
sudo systemctl start cassandra sudo systemctl enable cassandra - You can also check for running Cassandra processes:
ps aux | grep cassandra
2. Fix Cassandra's Configuration File (cassandra.yaml)
The most common misconfig here is the listen_address setting, which controls how nodes communicate with each other. Edit the file (usually at /etc/cassandra/cassandra.yaml):
- Find
listen_addressand set it to your EC2 instance's private IP (like172.31.30.37—don't uselocalhostor0.0.0.0here, since nodes need to reach each other via private IPs). - Double-check the
seedssetting: This should list the private IP(s) of at least one seed node in your cluster (e.g., if your first node is172.31.30.37, all three nodes should have this IP in theirseedslist). - Optional: If you need remote client access, set
rpc_addressto0.0.0.0, but this isn't required for node-to-node communication.
After making changes, restart Cassandra to apply them:
sudo systemctl restart cassandra
3. Unblock Port 7000 on Ubuntu's Local Firewall (ufw)
If Ubuntu's ufw firewall is enabled, it might be blocking incoming/outgoing traffic on port 7000:
- Check firewall status:
sudo ufw status - If it's active, allow TCP traffic on port 7000:
sudo ufw allow 7000/tcp - If you want to allow ping (ICMP) between nodes too, run:
(Replacesudo ufw allow from <your-cluster-private-subnet> to any proto icmp<your-cluster-private-subnet>with your EC2 subnet, like172.31.0.0/16)
4. Critical: Update AWS EC2 Security Group Rules
This is the #1 gotcha for EC2-based clusters—even if your local firewall is open, AWS security groups will block traffic unless explicitly allowed:
- Go to your EC2 console, select one of your Cassandra instances, and navigate to its Security Groups tab.
- Edit the inbound rules to add:
- Type: Custom TCP
- Port Range: 7000
- Source: Select the ID of your cluster's security group (this allows all instances in the same security group to communicate on port 7000)
- If you want ping to work, add another inbound rule:
- Type: All ICMP - IPv4
- Source: Your cluster's security group ID
5. Verify Port Listening & Test Connectivity
Once you've made the above changes, check if Cassandra is now listening on port 7000:
netstat -na | grep 7000 # Or use ss for more detailed info: ss -tulpn | grep cassandra
You should see a line like tcp 0 0 172.31.30.37:7000 0.0.0.0:* LISTEN (matching your instance's private IP).
Then test telnet again from another node:
telnet <target-private-ip> 7000
If it connects, you're good to go! If not, check Cassandra's system logs at /var/log/cassandra/system.log for errors—look for messages about failed binding to port 7000 or configuration issues.
内容的提问来源于stack exchange,提问作者Payal

