You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无法通过SSH连接Google Cloud Compute Engine虚拟机实例

无法通过浏览器SSH连接Google Cloud Compute Engine实例的问题排查

我正在按照《配置含虚拟机实例组后端的区域外部HTTP(S)负载均衡》文档操作,尝试通过浏览器SSH连接Google Cloud上的Compute Engine虚拟机实例,但连接失败。

已创建的防火墙规则详情

1. fw-allow-ssh规则

执行gcloud compute firewall-rules describe fw-allow-ssh返回内容:

allowed:
- IPProtocol: tcp
  ports:
  - '22'
creationTimestamp: '2022-09-13T07:55:49.187-07:00'
description: ''
direction: INGRESS
disabled: false
id: '3158638846670612250'
kind: compute#firewall
logConfig:
  enable: false
name: fw-allow-ssh
network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/default
priority: 1000
selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-ssh
sourceRanges:
- 0.0.0.0/0
targetTags:
- load-balanced-backend

2. fw-allow-health-check规则

执行gcloud compute firewall-rules describe fw-allow-health-check返回内容:

allowed:
- IPProtocol: tcp
  ports:
  - '80'
creationTimestamp: '2022-09-12T21:29:49.688-07:00'
description: ''
direction: INGRESS
disabled: false
id: '2007525931317311954'
kind: compute#firewall
logConfig:
  enable: false
name: fw-allow-health-check
network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/lb-network
priority: 1000
selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-health-check
sourceRanges:
- 130.211.0.0/22
- 35.191.0.0/16
targetTags:
- load-balanced-backend

3. fw-allow-proxies规则

执行gcloud compute firewall-rules describe fw-allow-proxies返回内容:

allowed:
- IPProtocol: tcp
  ports:
  - '80'
  - '443'
  - '8080'
creationTimestamp: '2022-09-12T21:33:19.582-07:00'
description: ''
direction: INGRESS
disabled: false
id: '3828652160003716832'
kind: compute#firewall
logConfig:
  enable: false
name: fw-allow-proxies
network: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/networks/lb-network
priority: 1000
selfLink: https://www.googleapis.com/compute/v1/projects/possible-post-360304/global/firewalls/fw-allow-proxies
sourceRanges:
- 10.129.0.0/23
targetTags:
- load-balanced-backend

连接时的错误信息

尝试通过浏览器SSH连接时,先出现以下提示:

Cloud IAP for TCP forwarding is not currently supported for google.com projects; attempting to use the legacy relays instead. If you are connecting to a non google.com project, continue reading. Please consider adding a firewall rule to allow ingress from the Cloud IAP for TCP forwarding netblock to the SSH port of your machine to start using Cloud IAP for TCP forwarding for better performance.

随后显示:

We are unable to connect to the VM on port 22.

从浏览器SSH连接虚拟机实例

问题原因及解决方法

核心问题:防火墙规则与实例网络不匹配

你的fw-allow-ssh规则关联的是default网络,但负载均衡相关的防火墙规则(fw-allow-health-check、fw-allow-proxies)都关联lb-network。如果你的虚拟机实例运行在lb-network中,这条SSH规则不会对其生效,导致端口22无法接收流量。

具体解决步骤

  1. 确认实例所在网络
    执行以下命令查看虚拟机实例所属网络:

    gcloud compute instances describe [INSTANCE_NAME] --format="value(networkInterfaces[0].network)"
    

    替换[INSTANCE_NAME]为你的实例名称。

  2. 调整SSH防火墙规则
    若实例确实在lb-network中,二选一执行:

    • 修改现有fw-allow-ssh规则的网络:
      gcloud compute firewall-rules update fw-allow-ssh --network lb-network
      
    • 新建针对lb-network的SSH规则:
      gcloud compute firewall-rules create fw-allow-ssh-lb \
        --network lb-network \
        --allow tcp:22 \
        --source-ranges 0.0.0.0/0 \
        --target-tags load-balanced-backend
      
  3. 推荐:启用Cloud IAP TCP转发
    若要使用更稳定的Cloud IAP进行SSH连接,添加允许IAP IP段的规则:

    gcloud compute firewall-rules create fw-allow-iap-ssh \
      --network lb-network \
      --allow tcp:22 \
      --source-ranges 35.235.240.0/20 \
      --target-tags load-balanced-backend
    
  4. 额外排查点

    • 检查实例是否已添加load-balanced-backend标签:
      gcloud compute instances describe [INSTANCE_NAME] --format="value(tags.items)"
      
    • 确认实例状态为RUNNING,内部IP正常分配。
    • 确保你的Google账号拥有该实例的compute.instances.osLogin或compute.instances.admin权限。

内容的提问来源于stack exchange,提问作者Nosail

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.19 20:50:24