tomcat部署成功,但是外网访问不了,请帮忙看一下,谢谢
Retomcat部署成功,但是外网访问不了,请帮忙看一下,谢谢
我的安全组限制是默认的:
公网出(入)设置如下
允许 全部 -1/-1 地址段访问 0.0.0.0/0 1
-------------------------
回 2楼dongshan8的帖子
你好,感谢回复。
我的ECS CentOS主机的iptables是默认设置,没有修改。具体如下:
Chain INPUT (policy ACCEPT)
target prot opt source destination
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
INPUT_direct all -- 0.0.0.0/0 0.0.0.0/0
INPUT_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
INPUT_ZONES all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain FORWARD (policy ACCEPT)
target prot opt source destination
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0 ctstate RELATED,ESTABLISHED
ACCEPT all -- 0.0.0.0/0 0.0.0.0/0
FORWARD_direct all -- 0.0.0.0/0 0.0.0.0/0
FORWARD_IN_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
FORWARD_IN_ZONES all -- 0.0.0.0/0 0.0.0.0/0
FORWARD_OUT_ZONES_SOURCE all -- 0.0.0.0/0 0.0.0.0/0
FORWARD_OUT_ZONES all -- 0.0.0.0/0 0.0.0.0/0
ACCEPT icmp -- 0.0.0.0/0 0.0.0.0/0
REJECT all -- 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
OUTPUT_direct all -- 0.0.0.0/0 0.0.0.0/0
Chain FORWARD_IN_ZONES (1 references)
target prot opt source destination
FWDI_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
FWDI_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
FWDI_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
Chain FORWARD_IN_ZONES_SOURCE (1 references)
target prot opt source destination
Chain FORWARD_OUT_ZONES (1 references)
target prot opt source destination
FWDO_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
FWDO_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
FWDO_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
Chain FORWARD_OUT_ZONES_SOURCE (1 references)
target prot opt source destination
Chain FORWARD_direct (1 references)
target prot opt source destination
Chain FWDI_public (3 references)
target prot opt source destination
FWDI_public_log all -- 0.0.0.0/0 0.0.0.0/0
FWDI_public_deny all -- 0.0.0.0/0 0.0.0.0/0
FWDI_public_allow all -- 0.0.0.0/0 0.0.0.0/0
Chain FWDI_public_allow (1 references)
target prot opt source destination
Chain FWDI_public_deny (1 references)
target prot opt source destination
Chain FWDI_public_log (1 references)
target prot opt source destination
Chain FWDO_public (3 references)
target prot opt source destination
FWDO_public_log all -- 0.0.0.0/0 0.0.0.0/0
FWDO_public_deny all -- 0.0.0.0/0 0.0.0.0/0
FWDO_public_allow all -- 0.0.0.0/0 0.0.0.0/0
Chain FWDO_public_allow (1 references)
target prot opt source destination
Chain FWDO_public_deny (1 references)
target prot opt source destination
Chain FWDO_public_log (1 references)
target prot opt source destination
Chain INPUT_ZONES (1 references)
target prot opt source destination
IN_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
IN_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
IN_public all -- 0.0.0.0/0 0.0.0.0/0 [goto]
Chain INPUT_ZONES_SOURCE (1 references)
target prot opt source destination
Chain INPUT_direct (1 references)
target prot opt source destination
Chain IN_public (3 references)
target prot opt source destination
IN_public_log all -- 0.0.0.0/0 0.0.0.0/0
IN_public_deny all -- 0.0.0.0/0 0.0.0.0/0
IN_public_allow all -- 0.0.0.0/0 0.0.0.0/0
Chain IN_public_allow (1 references)
target prot opt source destination
ACCEPT tcp -- 0.0.0.0/0 0.0.0.0/0 tcp dpt:22 ctstate NEW
Chain IN_public_deny (1 references)
target prot opt source destination
Chain IN_public_log (1 references)
target prot opt source destination
Chain OUTPUT_direct (1 references)
target prot opt source destination
-------------------------
回 2楼dongshan8的帖子
我的trace命令如下:
liuqiangdeMacBook-Pro:~ liuqiang$ traceroute 123.56.202.182
traceroute to 123.56.202.182 (123.56.202.182), 64 hops max, 52 byte packets
1 10.10.240.1 (10.10.240.1) 87.067 ms 3.722 ms 135.010 ms
2 220.181.34.102 (220.181.34.102) 0.905 ms 2.980 ms 1.143 ms
3 220.181.34.97 (220.181.34.97) 9.763 ms 4.593 ms 2.842 ms
4 220.181.34.69 (220.181.34.69) 56.586 ms 11.014 ms 3.323 ms
5 218.30.112.165 (218.30.112.165) 3.346 ms
218.30.112.45 (218.30.112.45) 1.870 ms
218.30.112.69 (218.30.112.69) 5.673 ms
6 218.30.112.138 (218.30.112.138) 4.869 ms
218.30.112.134 (218.30.112.134) 4.111 ms *
7 * * *
8 180.149.140.70 (180.149.140.70) 12.944 ms
180.149.140.74 (180.149.140.74) 4.771 ms
180.149.140.54 (180.149.140.54) 4.971 ms
9 101.200.109.149 (101.200.109.149) 7.473 ms
101.200.109.129 (101.200.109.129) 6.939 ms
101.200.109.145 (101.200.109.145) 15.480 ms
10 101.200.109.133 (101.200.109.133) 8.757 ms
101.200.109.145 (101.200.109.145) 8.226 ms
101.200.109.133 (101.200.109.133) 6.622 ms
11 * * *
12 * * *
13 123.56.202.182 (123.56.202.182) 6.882 ms !Z 13.863 ms !Z 9.646 ms !Z
-------------------------
回 2楼dongshan8的帖子
谢谢,解决了,CentOS7用的是firewalld。把firewalld关掉就可以了
systemctl stop firewalld.service
赞0
踩0