6

For some reason I can't open port 443 on my google compute instance. I have HTTPS server enabled on the instance, and using gcloud compute firewall-rules list returns the rules below:

NAME                    NETWORK  DIRECTION  PRIORITY  ALLOW                         DENY
default-allow-http      default  INGRESS    1000      tcp:80
default-allow-https     default  INGRESS    1000      tcp:443
default-allow-icmp      default  INGRESS    65534     icmp
default-allow-internal  default  INGRESS    65534     tcp:0-65535,udp:0-65535,icmp
default-allow-rdp       default  INGRESS    65534     tcp:3389
default-allow-ssh       default  INGRESS    65534     tcp:22

Yet when I check to see if the port is open using something like nmap it says it's closed.

PORT     STATE  SERVICE
22/tcp   open   ssh
443/tcp  closed https

Edit: Here's my nginx conf file for that site. https://gist.github.com/cclloyd/e7f1183f3a018dbc32cd7c55e15375cf

cclloyd
  • 583
  • 1
  • 13
  • 24

1 Answers1

5

Check if application running

You need to check if there is actually an application, running on your instance, that listening to 443 port.

sudo netstat -plnt

E.g. if there is nginx service running, and configured to listen 443 port, you will see something like this

Proto Local Address           Foreign Address         State       PID/Program name
tcp   0.0.0.0:443             0.0.0.0:*               LISTEN      2742/nginx -g daemo

Check firewall rules association

You also can check that your firewall rule and your instance has appropriate tags:

Check firewall rule targetTags:

$ gcloud compute firewall-rules describe default-allow-https --format="value(targetTags)"

Should output "https-server"

Check instance tags:

$ gcloud compute instances describe %INSTANCE_NAME% --format="value(tags.items)"

Should output "https-server" as well.

Scalar
  • 66
  • 1
  • 1
    Both of those gcloud commands return the correct value, yet it doesn't seem to work. I added my nginx conf file to my original post just to check, and nginx is up and running right now. When I run netstat on the cloud instance it only shows port 80, 22, and 3306. No 443. – cclloyd Feb 04 '18 at 22:29