You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过CloudShell用私有IP连接EC2实例失败求助

无法通过CloudShell使用私有IP连接EC2实例的排查方案

我尝试通过CloudShell连接EC2实例:使用公有IPv4 DNS可正常建立连接,但使用私有IP时收到错误提示:

connect to host 172.xx.xx.xxx port 22: No route to host

我的目标是解绑公有IP以节省成本,但按指引操作后仍遇问题,SSH debug日志如下:

OpenSSH_8.7p1, OpenSSL 3.0.8 7 Feb 2023
debug1: Reading configuration data /etc/ssh/ssh_config
debug3: /etc/ssh/ssh_config line 55: Including file /etc/ssh/ssh_config.d/50-redhat.conf depth 0
debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf
debug2: checking match for 'final all' host 172.xx.xx.xx originally 172.xx.xx.xx
debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 3: not matched 'final'
debug2: match not found
debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 5: Including file /etc/crypto-policies/back-ends/openssh.config depth 1 (parse only)
debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config
debug3: gss kex names ok: [gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-]
debug3: kex names ok: [curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512]
debug1: configuration requests final Match pass
debug2: resolve_canonicalize: hostname 172.xx.xx.xx is address
debug1: re-parsing configuration
debug1: Reading configuration data /etc/ssh/ssh_config
debug3: /etc/ssh/ssh_config line 55: Including file /etc/ssh/ssh_config.d/50-redhat.conf depth 0
debug1: Reading configuration data /etc/ssh/ssh_config.d/50-redhat.conf
debug2: checking match for 'final all' host 172.xx.xx.xx originally 172.xx.xx.xx
debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 3: matched 'final'
debug2: match found
debug3: /etc/ssh/ssh_config.d/50-redhat.conf line 5: Including file /etc/crypto-policies/back-ends/openssh.config depth 1
debug1: Reading configuration data /etc/crypto-policies/back-ends/openssh.config
debug3: gss kex names ok: [gss-curve25519-sha256-,gss-nistp256-sha256-,gss-group14-sha256-,gss-group16-sha512-]
debug3: kex names ok: [curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group14-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512]
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/home/cloudshell-user/.ssh/known_hosts'
debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/home/cloudshell-user/.ssh/known_hosts2'
debug3: ssh_connect_direct: entering
debug1: Connecting to 172.xx.xx.xx [172.xx.xx.xx] port 22.
debug3: set_sock_tos: set socket 3 IP_TOS 0x48
debug1: connect to address 172.xx.xx.xx port 22: No route to host
ssh: connect to host 172.xx.xx.xx port 22: No route to host

核心排查与解决步骤

1. 确认网络域一致性

CloudShell默认运行在AWS管理的VPC中,若你的EC2实例在自定义VPC,必须:

  • 建立两个VPC的对等连接
  • 双方路由表添加对应私有IP段的转发规则
    如果不在同一网络域,私有IP无法直接互通。

2. 检查安全组规则

  • 入站规则:在CloudShell执行curl ifconfig.me获取当前出口IP,给EC2实例的安全组添加规则:协议TCP、端口22、来源为该IP/32
  • 出站规则:确保EC2安全组允许出站到CloudShell的流量(默认规则通常已覆盖,若有自定义限制需调整)

3. 验证VPC路由表

  • 查看EC2实例所在子网的路由表,确认存在指向CloudShell VPC的路由(对等连接场景),或本地路由覆盖目标私有IP段
  • 若用默认VPC,检查VPC属性是否启用了DNS解析和DNS主机名(虽然直接用IP,但部分网络依赖此配置)

4. 测试IP可达性

在CloudShell执行ping 172.xx.xx.xx:

  • 无法ping通:优先排查路由或安全组问题
  • 能ping通但SSH失败:检查EC2内部防火墙(如iptables -L或firewalld规则)是否拦截22端口

5. 替代方案:用Session Manager免公网连接

如果配置繁琐,直接用AWS Session Manager:

  • 确保EC2实例预装SSM Agent(Amazon Linux 2默认已装)
  • 为EC2实例的IAM角色添加AmazonSSMManagedInstanceCore权限
  • 在EC2控制台选择实例→「连接」→「Session Manager」即可直接建立连接

内容的提问来源于stack exchange,提问作者RafaSashi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.28 17:55:01