通过CloudShell用私有IP连接EC2实例失败求助
无法通过CloudShell使用私有IP连接EC2实例的排查方案
我尝试通过CloudShell连接EC2实例:使用公有IPv4 DNS可正常建立连接,但使用私有IP时收到错误提示:
connect to host 172.xx.xx.xxx port 22: No route to host
我的目标是解绑公有IP以节省成本,但按指引操作后仍遇问题,SSH debug日志如下:
OpenSSH_8.7p1, OpenSSL 3.0.8 7 Feb 2023 debug1: Reading configuration data /etc/ssh/ssh_config debug3: /etc/ssh/ssh_config line 55: Including file /etc/ssh/ssh_config.d/50-redhat.conf depth 0 debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf debug2: checking match for 'final all' host 172.xx.xx.xx originally 172.xx.xx.xx debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 3: not matched 'final' debug2: match not found debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 5: Including file /etc/crypto-policies/back-ends/openssh.config depth 1 (parse only) debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config debug3: gss kex names ok: [gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-] debug3: kex names ok: [curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512] debug1: configuration requests final Match pass debug2: resolve_canonicalize: hostname 172.xx.xx.xx is address debug1: re-parsing configuration debug1: Reading configuration data /etc/ssh/ssh_config debug3: /etc/ssh/ssh_config line 55: Including file /etc/ssh/ssh_config.d/50-redhat.conf depth 0 debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf debug2: checking match for 'final all' host 172.xx.xx.xx originally 172.xx.xx.xx debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 3: matched 'final' debug2: match found debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 5: Including file /etc/crypto-policies/back-ends/openssh.config depth 1 debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config debug3: gss kex names ok: [gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-] debug3: kex names ok: [curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512] debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/cloudshell-user/.ssh/known_hosts' debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/cloudshell-user/.ssh/known_hosts2' debug3: ssh_connect_direct: entering debug1: Connecting to 172.xx.xx.xx [172.xx.xx.xx] port 22. debug3: set_sock_tos: set socket 3 IP_TOS 0x48 debug1: connect to address 172.xx.xx.xx port 22: No route to host ssh: connect to host 172.xx.xx.xx port 22: No route to host
核心排查与解决步骤
1. 确认网络域一致性
CloudShell默认运行在AWS管理的VPC中,若你的EC2实例在自定义VPC,必须:
- 建立两个VPC的对等连接
- 双方路由表添加对应私有IP段的转发规则
如果不在同一网络域,私有IP无法直接互通。
2. 检查安全组规则
- 入站规则:在CloudShell执行
curl ifconfig.me获取当前出口IP,给EC2实例的安全组添加规则:协议TCP、端口22、来源为该IP/32 - 出站规则:确保EC2安全组允许出站到CloudShell的流量(默认规则通常已覆盖,若有自定义限制需调整)
3. 验证VPC路由表
- 查看EC2实例所在子网的路由表,确认存在指向CloudShell VPC的路由(对等连接场景),或本地路由覆盖目标私有IP段
- 若用默认VPC,检查VPC属性是否启用了DNS解析和DNS主机名(虽然直接用IP,但部分网络依赖此配置)
4. 测试IP可达性
在CloudShell执行ping 172.xx.xx.xx:
- 无法ping通:优先排查路由或安全组问题
- 能ping通但SSH失败:检查EC2内部防火墙(如
iptables -L或firewalld规则)是否拦截22端口
5. 替代方案:用Session Manager免公网连接
如果配置繁琐,直接用AWS Session Manager:
- 确保EC2实例预装SSM Agent(Amazon Linux 2默认已装)
- 为EC2实例的IAM角色添加
AmazonSSMManagedInstanceCore权限 - 在EC2控制台选择实例→「连接」→「Session Manager」即可直接建立连接
内容的提问来源于stack exchange,提问作者RafaSashi
相关产品推荐
相关产品推荐

