You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

访问Azure虚拟机中Elasticsearch集群时出现No route to host错误求助

问题场景

Azure Linux虚拟机(私有IP:10.176.83.156)部署Elasticsearch 8.12.2集群,虚拟机内部可正常访问,但通过VPN从本地机器访问时失败,已添加NSG入站规则,请求协助排查。

Elasticsearch配置(elasticsearch.yml)

cluster.name: Test-cluster
node.name: node-1
path.data: /var/lib/elasticsearch
path.logs: /var/log/elasticsearch
network.host: 0.0.0.0
http.port: 9200
xpack.security.enabled: true

xpack.security.enrollment.enabled: true

# Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents
xpack.security.http.ssl:
  enabled: true
  keystore.path: certs/http.p12

# Enable encryption and mutual authentication between cluster nodes
xpack.security.transport.ssl:
  enabled: true
  verification_mode: certificate
  keystore.path: certs/transport.p12
  truststore.path: certs/transport.p12
# Create a new cluster with the current node only
# Additional nodes can still join the cluster later
cluster.initial_master_nodes: ["l01q23705150001"]

# Allow HTTP API connections from anywhere
# Connections are encrypted and require user authentication
http.host: 0.0.0.0

虚拟机内部访问情况

执行以下命令可正常返回Elasticsearch信息:

curl -u elastic:NYC59UxNJ3FRNZUpNhKa https://10.176.83.156:9200 -k

返回结果:

{
  "name" : "l01q23705150001",
  "cluster_name" : "elasticsearch",
  "cluster_uuid" : "wOepv5C_T3md3a0K6f1yOw",
  "version" : {
    "number" : "8.12.2",
    "build_flavor" : "default",
    "build_type" : "rpm",
    "build_hash" : "48a287ab9497e852de30327444b0809e55d46466",
    "build_date" : "2024-02-19T10:04:32.774273190Z",
    "build_snapshot" : false,
    "lucene_version" : "9.9.2",
    "minimum_wire_compatibility_version" : "7.17.0",
    "minimum_index_compatibility_version" : "7.0.0"
  },
  "tagline" : "You Know, for Search"
}

本地VPN访问错误

执行命令:

curl -u elastic:NYC59UxNJ3FRNZUpNhKa https://10.176.83.156:9200 -k

返回错误:

curl: (7) Failed to connect to 10.192.85.168 port 9200: No route to host
排查步骤
  • IP地址映射问题:本地curl目标IP是10.176.83.156,但错误提示连接10.192.85.168,需检查本地DNS解析、VPN路由配置或hosts文件,确认Elasticsearch私有IP未被错误映射。
  • VPN链路有效性:验证VPN是否成功建立,尝试访问同VNet内其他虚拟机的私有IP,若也无法访问,说明VPN链路存在问题,需检查Azure VPN网关配置、本地VPN客户端的路由推送规则。
  • 虚拟机本地防火墙拦截:Linux系统自带防火墙(如firewalld/ufw)可能阻断9200端口,执行以下命令检查并开放:
    # 查看firewalld状态
    sudo firewall-cmd --state
    # 临时开放9200 TCP端口
    sudo firewall-cmd --add-port=9200/tcp --zone=public
    # 永久生效并重载规则
    sudo firewall-cmd --add-port=9200/tcp --zone=public --permanent
    sudo firewall-cmd --reload
    
  • NSG入站规则细节验证:
    • 确认规则优先级高于拒绝类规则(数值越小优先级越高)
    • 源地址范围包含VPN客户端所在网段(若未设置为0.0.0.0/0)
    • 目标端口为9200,协议为TCP,动作为“允许”
  • Elasticsearch监听端口验证:确认Elasticsearch确实监听所有网卡的9200端口:
    ss -tulpn | grep 9200
    
    正常输出应包含0.0.0.0:9200或:::9200
  • 虚拟机路由表检查:在虚拟机上执行ip route查看路由配置,确认私有IP所在子网的路由条目正常,无异常路由导致无法响应VPN请求。

内容的提问来源于stack exchange,提问作者mystack

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.29 00:27:34