无法通过SSH连接Google Cloud Compute Engine虚拟机实例
我正在按照《配置含虚拟机实例组后端的区域外部HTTP(S)负载均衡》文档操作,尝试通过浏览器SSH连接Google Cloud上的Compute Engine虚拟机实例,但连接失败。
已创建的防火墙规则详情
1. fw-allow-ssh规则
执行gcloud compute firewall-rules describe fw-allow-ssh返回内容:
allowed: - IPProtocol: tcp ports: - '22' creationTimestamp: '2022-09-13T07:55:49.187-07:00' description: '' direction: INGRESS disabled: false id: '3158638846670612250' kind: compute#firewall logConfig: enable: false name: fw-allow-ssh network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/default priority: 1000 selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-ssh sourceRanges: - 0.0.0.0/0 targetTags: - load-balanced-backend
2. fw-allow-health-check规则
执行gcloud compute firewall-rules describe fw-allow-health-check返回内容:
allowed: - IPProtocol: tcp ports: - '80' creationTimestamp: '2022-09-12T21:29:49.688-07:00' description: '' direction: INGRESS disabled: false id: '2007525931317311954' kind: compute#firewall logConfig: enable: false name: fw-allow-health-check network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/lb-network priority: 1000 selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-health-check sourceRanges: - 130.211.0.0/22 - 35.191.0.0/16 targetTags: - load-balanced-backend
3. fw-allow-proxies规则
执行gcloud compute firewall-rules describe fw-allow-proxies返回内容:
allowed: - IPProtocol: tcp ports: - '80' - '443' - '8080' creationTimestamp: '2022-09-12T21:33:19.582-07:00' description: '' direction: INGRESS disabled: false id: '3828652160003716832' kind: compute#firewall logConfig: enable: false name: fw-allow-proxies network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/lb-network priority: 1000 selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-proxies sourceRanges: - 10.129.0.0/23 targetTags: - load-balanced-backend
连接时的错误信息
尝试通过浏览器SSH连接时,先出现以下提示:
Cloud IAP for TCP forwarding is not currently supported for google.com projects; attempting to use the legacy relays instead. If you are connecting to a non google.com project, continue reading. Please consider adding a firewall rule to allow ingress from the Cloud IAP for TCP forwarding netblock to the SSH port of your machine to start using Cloud IAP for TCP forwarding for better performance.
随后显示:
We are unable to connect to the VM on port 22.

问题原因及解决方法
核心问题:防火墙规则与实例网络不匹配
你的fw-allow-ssh规则关联的是default网络,但负载均衡相关的防火墙规则(fw-allow-health-check、fw-allow-proxies)都关联lb-network。如果你的虚拟机实例运行在lb-network中,这条SSH规则不会对其生效,导致端口22无法接收流量。
具体解决步骤
确认实例所在网络
执行以下命令查看虚拟机实例所属网络:gcloud compute instances describe [INSTANCE_NAME] --format="value(networkInterfaces[0].network)"替换
[INSTANCE_NAME]为你的实例名称。调整SSH防火墙规则
若实例确实在lb-network中,二选一执行:- 修改现有
fw-allow-ssh规则的网络:gcloud compute firewall-rules update fw-allow-ssh --network lb-network - 新建针对
lb-network的SSH规则:gcloud compute firewall-rules create fw-allow-ssh-lb \ --network lb-network \ --allow tcp:22 \ --source-ranges 0.0.0.0/0 \ --target-tags load-balanced-backend
- 修改现有
推荐:启用Cloud IAP TCP转发
若要使用更稳定的Cloud IAP进行SSH连接,添加允许IAP IP段的规则:gcloud compute firewall-rules create fw-allow-iap-ssh \ --network lb-network \ --allow tcp:22 \ --source-ranges 35.235.240.0/20 \ --target-tags load-balanced-backend额外排查点
- 检查实例是否已添加
load-balanced-backend标签:gcloud compute instances describe [INSTANCE_NAME] --format="value(tags.items)" - 确认实例状态为
RUNNING,内部IP正常分配。 - 确保你的Google账号拥有该实例的
compute.instances.osLogin或compute.instances.admin权限。
- 检查实例是否已添加
内容的提问来源于stack exchange,提问作者Nosail

