AWS EC2实例无法执行出站网络数据获取操作求助
问题
AWS EC2实例执行git pull、apt-get update等需访问外部服务器的操作均失败,报错显示无法连接Ubuntu镜像源,连接超时。
报错信息
Err:1 http://us-east-2.ec2.archive.ubuntu.com/ubuntu focal-updates/main amd64 python3-distro-info all 0.23ubuntu1.1 Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.106.142), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.102.108), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (3.129.149.36), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.107.13), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.158.54), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.159.198), connection timed out Err:2 http://us-east-2.ec2.archive.ubuntu.com/ubuntu focal-updates/main amd64 ufw all 0.36-6ubuntu1.1 Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: Err:3 http://us-east-2.ec2.archive.ubuntu.com/ubuntu focal-updates/main amd64 distro-info amd64 0.23ubuntu1.1 Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: Err:4 http://us-east-2.ec2.archive.ubuntu.com/ubuntu focal-updates/main amd64 libgpgme11 amd64 1.13.1-7ubuntu2.1 Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: E: Failed to fetch http://us-east-2.ec2.archive.ubuntu.com/ubuntu/pool/main/d/distro-info/python3-distro-info_0.23ubuntu1.1_all.deb Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.106.142), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.102.108), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (3.129.149.36), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.107.13), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.158.54), connection timed out Could not connect to us-east-2.ec2.archive.ubuntu.com:80 (52.15.159.198), connection timed out E: Failed to fetch http://us-east-2.ec2.archive.ubuntu.com/ubuntu/pool/main/u/ufw/ufw_0.36-6ubuntu1.1_all.deb Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: E: Failed to fetch http://us-east-2.ec2.archive.ubuntu.com/ubuntu/pool/main/d/distro-info/distro-info_0.23ubuntu1.1_amd64.deb Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: E: Failed to fetch http://us-east-2.ec2.archive.ubuntu.com/ubuntu/pool/main/g/gpgme1.0/libgpgme11_1.13.1-7ubuntu2.1_amd64.deb Unable to connect to us-east-2.ec2.archive.ubuntu.com:http: E: Unable to fetch some archives, maybe run apt-get update or try with --fix-missing?
安全组配置

解决方案
核心问题是EC2实例的出站流量被限制,无法访问外部服务,按以下步骤修复:
补充安全组出站规则
当前安全组仅放行22端口的出站流量,而apt-get需要80/443端口,Git操作需22或443端口。添加两条出站规则:- 类型:HTTP,协议TCP,端口80,目标
0.0.0.0/0 - 类型:HTTPS,协议TCP,端口443,目标
0.0.0.0/0
- 类型:HTTP,协议TCP,端口80,目标
验证连通性
规则生效后,在实例上执行命令验证:- 测试Ubuntu源:
curl -I http://us-east-2.ec2.archive.ubuntu.com - 测试Git仓库:
git ls-remote git@github.com:your-repo.git(替换为你的仓库地址)
- 测试Ubuntu源:
排查网络ACL
若安全组配置后仍失败,检查子网对应的网络ACL,确保出站规则允许80、443、22端口流量,入方向允许相关响应流量(默认ACL全通,自定义规则需核对)。确认子网类型
若实例在私有子网,需确认路由表已配置指向NAT网关,否则实例无法直接访问公网。
内容的提问来源于stack exchange,提问作者Akhil
相关产品推荐
相关产品推荐

