在 CentOS 中,如果启用了 SELinux,除了 firewalld / iptables 放行端口外,还需要让 SELinux 允许该端口。下面是常见做法。
getenforce
Enforcing:生效中(需要配置)Permissive:仅记录不拦截Disabled:未启用(无需配置)semanage port -l | grep http
例如查看 80 / 8080:
semanage port -l | grep 80
semanage port -a -t http_port_t -p tcp 8080
说明:
http_port_t:Web 服务常用类型8080:你要放行的端口-p tcp:协议| 服务 | 类型 |
|---|---|
| HTTP | http_port_t |
| HTTPS | http_port_t |
| SSH | ssh_port_t |
| MySQL | mysqld_port_t |
| Redis | redis_port_t |
| 自定义 | http_port_t 或自定义 |
示例(SSH):
semanage port -a -t ssh_port_t -p tcp 2222
安装工具:
yum install -y policycoreutils-python-utils
semanage port -l | grep 8080
# 1. 防火墙
firewall-cmd --permanent --add-port=8080/tcp
firewall-cmd --reload
# 2. SELinux
semanage port -a -t http_port_t -p tcp 8080
# 3. 重启服务
systemctl restart nginx
setenforce 0
仅用于排查问题。
如果你能告诉我:
我可以给你精确命令。