访问Azure虚拟机中Elasticsearch集群时出现No route to host错误求助
问题场景
Azure Linux虚拟机(私有IP:10.176.83.156)部署Elasticsearch 8.12.2集群,虚拟机内部可正常访问,但通过VPN从本地机器访问时失败,已添加NSG入站规则,请求协助排查。
Elasticsearch配置(elasticsearch.yml)
cluster.name: Test-cluster node.name: node-1 path.data: /var/lib/elasticsearch path.logs: /var/log/elasticsearch network.host: 0.0.0.0 http.port: 9200 xpack.security.enabled: true xpack.security.enrollment.enabled: true # Enable encryption for HTTP API client connections, such as Kibana, Logstash, and Agents xpack.security.http.ssl: enabled: true keystore.path: certs/http.p12 # Enable encryption and mutual authentication between cluster nodes xpack.security.transport.ssl: enabled: true verification_mode: certificate keystore.path: certs/transport.p12 truststore.path: certs/transport.p12 # Create a new cluster with the current node only # Additional nodes can still join the cluster later cluster.initial_master_nodes: ["l01q23705150001"] # Allow HTTP API connections from anywhere # Connections are encrypted and require user authentication http.host: 0.0.0.0
虚拟机内部访问情况
执行以下命令可正常返回Elasticsearch信息:
curl -u elastic:NYC59UxNJ3FRNZUpNhKa https://10.176.83.156:9200 -k
返回结果:
{ "name" : "l01q23705150001", "cluster_name" : "elasticsearch", "cluster_uuid" : "wOepv5C_T3md3a0K6f1yOw", "version" : { "number" : "8.12.2", "build_flavor" : "default", "build_type" : "rpm", "build_hash" : "48a287ab9497e852de30327444b0809e55d46466", "build_date" : "2024-02-19T10:04:32.774273190Z", "build_snapshot" : false, "lucene_version" : "9.9.2", "minimum_wire_compatibility_version" : "7.17.0", "minimum_index_compatibility_version" : "7.0.0" }, "tagline" : "You Know, for Search" }
本地VPN访问错误
执行命令:
curl -u elastic:NYC59UxNJ3FRNZUpNhKa https://10.176.83.156:9200 -k
返回错误:
curl: (7) Failed to connect to 10.192.85.168 port 9200: No route to host
排查步骤
- IP地址映射问题:本地curl目标IP是
10.176.83.156,但错误提示连接10.192.85.168,需检查本地DNS解析、VPN路由配置或hosts文件,确认Elasticsearch私有IP未被错误映射。 - VPN链路有效性:验证VPN是否成功建立,尝试访问同VNet内其他虚拟机的私有IP,若也无法访问,说明VPN链路存在问题,需检查Azure VPN网关配置、本地VPN客户端的路由推送规则。
- 虚拟机本地防火墙拦截:Linux系统自带防火墙(如
firewalld/ufw)可能阻断9200端口,执行以下命令检查并开放:# 查看firewalld状态 sudo firewall-cmd --state # 临时开放9200 TCP端口 sudo firewall-cmd --add-port=9200/tcp --zone=public # 永久生效并重载规则 sudo firewall-cmd --add-port=9200/tcp --zone=public --permanent sudo firewall-cmd --reload - NSG入站规则细节验证:
- 确认规则优先级高于拒绝类规则(数值越小优先级越高)
- 源地址范围包含VPN客户端所在网段(若未设置为
0.0.0.0/0) - 目标端口为
9200,协议为TCP,动作为“允许”
- Elasticsearch监听端口验证:确认Elasticsearch确实监听所有网卡的9200端口:
正常输出应包含ss -tulpn | grep 92000.0.0.0:9200或:::9200 - 虚拟机路由表检查:在虚拟机上执行
ip route查看路由配置,确认私有IP所在子网的路由条目正常,无异常路由导致无法响应VPN请求。
内容的提问来源于stack exchange,提问作者mystack
相关产品推荐
相关产品推荐

