Docker环境下80/443端口外部无法访问的诡异网络问题求助
Docker环境下80/443端口外部无法访问的诡异网络问题求助
各位大佬好,我遇到一个超级棘手的网络问题,挠破头都没搞明白,想请大家帮忙分析下!
情况是这样的:外部没法访问我服务器的80和443端口,但其他任意端口通过Docker转发都完全正常。我服务器上装了UFW,也跑了K3s,但主要服务都是用Docker Compose部署的。
为了排查,我拉了个Nginx测试容器,结果问题变得更奇怪了:
- 用Docker内部IP能访问这个测试容器,但直接
curl -I 127.0.0.1居然返回404:
-> # curl -I 127.0.0.1 HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 20 Sep 2023 00:39:26 GMT Content-Length: 19
- 但从VPN内部的另一个IP(192.168.10.1)访问,却能正常返回200:
-> # curl -I 192.168.10.1 HTTP/1.1 200 OK Server: nginx/1.25.2 Date: Wed, 20 Sep 2023 00:41:32 GMT Content-Type: text/html Content-Length: 615 Last-Modified: Tue, 15 Aug 2023 17:03:04 GMT Connection: keep-alive ETag: "64dbafc8-267" Accept-Ranges: bytes
- 最离谱的是,我把容器停掉之后,
curl -I 127.0.0.1居然还是返回同样的404,而不是预期的“无法连接”错误!预期应该是这样的:
-> # curl -I 127.0.0.1 curl: (7) Failed to connect to 127.0.0.1 port 80 after 0 ms: Couldn't connect to server
更新:更诡异的来了,停掉Docker容器后,访问192.168.10.1也开始返回404了:
-> # curl -I 192.168.10.1 HTTP/1.1 404 Not Found Content-Type: text/plain; charset=utf-8 X-Content-Type-Options: nosniff Date: Wed, 20 Sep 2023 00:51:49 GMT Content-Length: 19
我完全懵了,根本不知道问题出在哪。更让人困惑的是,换成81端口做同样的测试,一切都正常工作!有没有大佬能给点调试思路或者建议?感激不尽!
下面是一些排查命令的输出:
lsof -i:80 输出:
COMMAND PID USER FD TYPE DEVICE SIZE/OFF NODE NAME docker-pr 9815 root 4u IPv4 54638 0t0 TCP *:http (LISTEN) docker-pr 9823 root 4u IPv6 48079 0t0 TCP *:http (LISTEN)
docker ps 输出:
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 975e74d4bdfd nginx:latest "/docker-entrypoint.…" 29 minutes ago Up 29 minutes 0.0.0.0:80->80/tcp, :::80->80/tcp nginx_test_nginx-test_1
ufw status 输出:
Status: active To Action From -- ------ ---- 22/tcp ALLOW Anywhere 80/tcp ALLOW Anywhere 443 ALLOW Anywhere Anywhere ALLOW 192.168.1.0/24 Anywhere ALLOW 192.168.178.0/24 81/tcp ALLOW Anywhere 22/tcp (v6) ALLOW Anywhere (v6) 80/tcp (v6) ALLOW Anywhere (v6) 443 (v6) ALLOW Anywhere (v6) 81/tcp (v6) ALLOW Anywhere (v6) Anywhere on eth0 ALLOW FWD Anywhere on wghub Anywhere on wghub ALLOW FWD Anywhere on wghub Anywhere (v6) on eth0 ALLOW FWD Anywhere (v6) on wghub Anywhere (v6) on wghub ALLOW FWD Anywhere (v6) on wghub
netstat -ltnp 输出:
Active Internet connections (only servers) Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name tcp 0 0 127.0.0.1:10010 0.0.0.0:* LISTEN 1374/containerd tcp 0 0 0.0.0.0:22 0.0.0.0:* LISTEN 631/sshd: /usr/sbin tcp 0 0 0.0.0.0:80 0.0.0.0:* LISTEN 9815/docker-proxy tcp 0 0 127.0.0.53:53 0.0.0.0:* LISTEN 610/systemd-resolve tcp6 0 0 :::22 :::* LISTEN 631/sshd: /usr/sbin tcp6 0 0 :::80 :::* LISTEN 9823/docker-proxy
cat /etc/default/docker 输出:
DOCKER_OPTS="--iptables=false"
更新:附上我的测试用Docker Compose配置:docker-compose.yml
version: '3' services: nginx-test: image: nginx:latest ports: - "80:80"
备注:内容来源于stack exchange,提问作者Limitless Green
相关产品推荐
相关产品推荐

