apache没有响应从外面(防火墙/ iptables的问题)

CentOS安装了httpd 。 可以用lynx连接到http://localhost并从机器内部连接到http://10.20.30.40 (真正的IP)。 无法从外部连接。 这里是/etc/httpd/conf/httpd.conf的摘录:

 Listen 0.0.0.0:80 <VirtualHost 10.20.30.40:80> DocumentRoot /var/www/vhost1 ErrorLog logs/vhost1-error_log CustomLog logs/vhost1-access_log common </VirtualHost> 

我试图从驻留在同一子网上的机器连接(据我所知)。

没有什么可疑的日志文件。 有什么build议吗?

更新 :当运行iptables -L我有以下行(也许它是相关的): REJECT all -- anywhere anywhere reject-with icmp-host-prohibited

更新N2iptables -vnL输出:

 Chain INPUT (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:53 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:53 0 0 ACCEPT udp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 udp dpt:67 0 0 ACCEPT tcp -- virbr0 * 0.0.0.0/0 0.0.0.0/0 tcp dpt:67 1576K 1643M RH-Firewall-1-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0 Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 ACCEPT all -- * virbr0 0.0.0.0/0 192.168.122.0/24 state RELATED,ESTABLISHED 0 0 ACCEPT all -- virbr0 * 192.168.122.0/24 0.0.0.0/0 0 0 ACCEPT all -- virbr0 virbr0 0.0.0.0/0 0.0.0.0/0 0 0 REJECT all -- * virbr0 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable 0 0 REJECT all -- virbr0 * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-port-unreachable 0 0 RH-Firewall-1-INPUT all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy ACCEPT 354K packets, 58M bytes) pkts bytes target prot opt in out source destination Chain RH-Firewall-1-INPUT (2 references) pkts bytes target prot opt in out source destination 922 823K ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0 19 1412 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0 icmp type 255 0 0 ACCEPT esp -- * * 0.0.0.0/0 0.0.0.0/0 0 0 ACCEPT ah -- * * 0.0.0.0/0 0.0.0.0/0 159K 28M ACCEPT udp -- * * 0.0.0.0/0 224.0.0.251 udp dpt:5353 2869 640K ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:631 0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:631 1239K 1589M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED 8 1064 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22 175K 25M REJECT all -- * * 0.0.0.0/0 0.0.0.0/0 reject-with icmp-host-prohibited 

试试看看是否有帮助:

 sudo /sbin/iptables -A INPUT -p tcp --dport http -j ACCEPT 

如果您事先使用以下内容,则可以轻松恢复:

 /sbin/iptables-save > /tmp/fw 

如果你想完全closuresiptables(尽pipe更好地configuration它),然后使用:

 sudo /sbin/chkconfig iptables off 

否则,将规则保存到/ etc / sysconfig / iptables:

 /sbin/iptables-save > /etc/sysconfig/iptables 

这通常表明您的本地系统或networking上存在防火墙问题。 你的本地iptables防火墙是什么样的?

 # iptables -vnL 

您可以运行以下命令临时禁用本地防火墙:

 # /sbin/service iptables stop 

如果事情在这之后有效,那绝对是一个防火墙问题,你需要把它排除出去。

如果您没有本地防火墙,您的networking上是否有其他地方?

是的,我会说防火墙规则可能不是帮助的东西(虽然这取决于防火墙规则集中的其他内容)。 它也可能(理论上)与您连接的计算机上的传出防火墙或代理configuration问题或月球的相位有关。

完整的防火墙规则集和一些详细的networking故障排除结果将大大缩小问题的严重程度。