我正在实施Ratchet 的推动示例在我的服务器(websockets)的端口上9090。这些是当前的 iptables 策略:
[root@myserver ~]# iptables -L -n -v
Chain INPUT (policy ACCEPT 309 packets, 22420 bytes)
pkts bytes target prot opt in out source destination
6 380 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9090 flags:0x17/0x02
1765 79738 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:3306 state NEW,ESTABLISHED
831 80329 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:80
37 2866 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:443
1657K 67M ACCEPT all -- * * 0.0.0.0/0 0.0.0.0/0 state RELATED,ESTABLISHED
57 4891 ACCEPT icmp -- * * 0.0.0.0/0 0.0.0.0/0
1645K 99M ACCEPT all -- lo * 0.0.0.0/0 0.0.0.0/0
763 44632 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:22
7 348 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:21
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:21 state NEW,RELATED,ESTABLISHED
6 384 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:1337
0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 state NEW tcp dpt:11211
Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target prot opt in out source destination
Chain OUTPUT (policy ACCEPT 3204K packets, 162M bytes)
pkts bytes target prot opt in out source destination
1881 129K ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp spt:3306 state ESTABLISHED
由于某种原因,我无法从客户端或通过 telnet 访问端口 9090。
浏览器控制台返回以下内容:
WebSocket connection to 'ws://XX.XX.XX.XX:9090/' failed: Error in connection establishment: net::ERR_CONNECTION_REFUSED autobahn.min.js:62
(XX.XX.XX.XX 是我的服务器的 ip)
telnet localhost
返回此:
[root@myserver html]# telnet localhost 9090
Trying 127.0.0.1...
telnet: connect to address 127.0.0.1: Connection refused
更新
我跑了ss-tnlp 版本结果如下:
[root@myserver ~]# ss -tnlp
State Recv-Q Send-Q Local Address:Port Peer Address:Port
LISTEN 0 50 *:3306 *:* users:(("mysqld",1317,10))
LISTEN 0 128 :::11211 :::* users:(("memcached",1361,27))
LISTEN 0 128 *:11211 *:* users:(("memcached",1361,26))
LISTEN 0 128 :::80 :::* users:(("httpd",6378,4),("httpd",6381,4),("httpd",6382,4),("httpd",6383,4),("httpd",6384,4),("httpd",6385,4),("httpd",6386,4),("httpd",6387,4),("httpd",6388,4))
LISTEN 0 32 *:21 *:* users:(("vsftpd",1073,3))
LISTEN 0 128 :::22 :::* users:(("sshd",2661,4))
LISTEN 0 128 *:22 *:* users:(("sshd",2661,3))
LISTEN 0 100 ::1:25 :::* users:(("master",1442,13))
LISTEN 0 100 127.0.0.1:25 *:* users:(("master",1442,12))
LISTEN 0 128 :::443 :::* users:(("httpd",6378,6),("httpd",6381,6),("httpd",6382,6),("httpd",6383,6),("httpd",6384,6),("httpd",6385,6),("httpd",6386,6),("httpd",6387,6),("httpd",6388,6))
答案1
要检查某个进程是否正在监听/使用套接字,请尝试lsof -i:9090
。
正如 fukawi2 所说,也许您的进程没有监听它。或者也许另一个进程监听了它,并阻止您的进程使用它。
答案2
从输出中您可以看到iptables -nvL
您的规则已被命中(输出中有 6 次命中)。
您的ss -tnlp
显示没有进程绑定到端口 9090(Local Address:Port
列),因此传入到 9090 的数据包是传递 iptables,但内核与它们无关(没有进程绑定),因此内核发回一个 TCP RST 数据包,导致您的连接被拒绝错误。
简而言之,您的问题不是 iptables,而是您的进程没有运行,或者没有正确/成功绑定到端口 9090。