首页 文章

似乎没有连接到mongo shell的iptables相关

提问于
浏览
-1

刚刚在centos上安装mongodb 6.尝试使用命令“mongo”连接到mongo sh但是收到此错误消息:2015-09-26T07:07:35.309 0000 W NETWORK在5000毫秒后无法连接到127.0.0.1:27017,给出起来 . 2015-09-26T07:07:35.316 0000 E QUERY错误:无法连接到服务器127.0.0.1:27017(127.0.0.1),连接尝试连接尝试失败(src / mongo / shell / mongo.js:179:14 )at(connect):1:6 at src / mongo / shell / mongo.js:179

但是,一旦我停止我的防火墙(iptables停止)我可以访问mongo shell这里是我的iptables:

Chain INPUT (policy DROP)
target     prot opt source               destination         
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:28017 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:8080 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:3306 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:21 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:443 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:80 
ACCEPT     tcp  --  192.168.1.0/24       0.0.0.0/0           tcp dpt:22 
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:22 
ACCEPT     tcp  --  127.0.0.1            0.0.0.0/0           tcp dpt:27017 state NEW,ESTABLISHED 
LOGGING    all  --  0.0.0.0/0            0.0.0.0/0           
ACCEPT     tcp  --  0.0.0.0/0            0.0.0.0/0           tcp dpt:51396 
ACCEPT     all  --  0.0.0.0/0            0.0.0.0/0           state RELATED,ESTABLISHED 

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination         
ACCEPT     tcp  --  0.0.0.0/0            127.0.0.1           tcp spt:27017 state ESTABLISHED 

Chain LOGGING (1 references)
target     prot opt source               destination         
LOG        all  --  0.0.0.0/0            0.0.0.0/0           limit: avg 2/min burst 5 LOG flags 0 level 4 prefix `IPTables-Dropped: ' 
DROP       all  --  0.0.0.0/0            0.0.0.0/0

搜索并尝试了不同的解决方案 . 取下锁,修理;重置iptables,没有任何帮助 .

这些是丢弃数据包的iptables日志

9月26日06:59:38 xxx内核:IPTables-Dropped:IN = lo OUT = MAC = 00:00:00:00:00:00:00:00:00:00:00:00:08:00 SRC = 127.0.0.1 DST = 127.0.0.1 LEN = 60 TOS = 0x00 PREC = 0x00 TTL = 64 ID = 0 DF PROTO = TCP SPT = 27017 DPT = 51396 WINDOW = 32768 RES = 0x00 ACK SYN URGP = 0

9月26日07:04:47 xxx内核:IPTables-Dropped:IN = lo OUT = MAC = 00:00:00:00:00:00:00:00:00:00:00:00:08:00 SRC = 127.0.0.1 DST = 127.0.0.1 LEN = 60 TOS = 0x00 PREC = 0x00 TTL = 64 ID = 0 DF PROTO = TCP SPT = 27017 DPT = 59830 WINDOW = 32768 RES = 0x00 ACK SYN URGP = 0

无法理解为什么它仍然阻挡27017 .

1 回答

  • 0

    在防火墙中打开端口(27017) .

相关问题