EC2添加第二块网卡与私有IP后无网络连接问题排查
Let's walk through getting your secondary network interface (ens6) up and running, first on a single instance, then scaling to all your EC2 instances.
1. First, Verify AWS-Level Configuration
Before diving into OS-level settings, make sure the network interface is properly set up in AWS:
- Check Interface Attachment: In the EC2 console, confirm the ens6 interface is listed as Attached to your instance, and it's connected to the GlusterFS subnet (172.10.10.0/24).
- Security Group Rules: Ensure the security group associated with the ens6 interface allows DHCP traffic (UDP port 67/68) so the instance can pull an IP address from the subnet's DHCP pool.
- DHCP Options: Confirm the subnet's DHCP options set includes the necessary DNS servers (AWS default options should work for internal IP assignment).
2. Configure the Secondary Interface on a Single Ubuntu Instance
Ubuntu uses netplan for network configuration (default on newer versions), so we'll update that:
Step 1: Locate the Netplan Config File
Navigate to the netplan directory:
cd /etc/netplan/
You'll typically see a file named 50-cloud-init.yaml (cloud-init manages default network settings for EC2 instances).
Step 2: Edit the Config File
Open the file with a text editor (e.g., nano):
sudo nano 50-cloud-init.yaml
Add the configuration block for ens6 alongside your existing ens5 setup. Use the MAC address of ens6 from your ip link output (02:04:0a:df:1c:3c in your case):
network: ethernets: ens5: dhcp4: true match: macaddress: 02:a1:07:fa:2d:cc set-name: ens5 ens6: dhcp4: true match: macaddress: 02:04:0a:df:1c:3c set-name: ens6 version: 2
Save and exit (for nano: Ctrl+O, Enter, then Ctrl+X).
Step 3: Apply the Configuration
Generate and apply the new netplan settings:
sudo netplan generate sudo netplan apply
Step 4: Verify the Interface Status
Check if ens6 is now up and has an IP:
ip addr show ens6
You should see it in the <BROADCAST,MULTICAST,UP,LOWER_UP> state with an IP from the 172.10.10.0/24 subnet.
3. Batch Configure All EC2 Instances
To roll this out to all your instances efficiently, use AWS Systems Manager Run Command:
Prerequisites
- Ensure all target EC2 instances have the SSM Agent installed (Ubuntu AMIs from AWS Marketplace include this by default).
- Attach an IAM role to the instances with the
AmazonEC2RoleforSSMpolicy (this allows Systems Manager to communicate with the instances).
Step 1: Create a Deployment Script
Use this shell script to automatically detect the MAC addresses of both interfaces and update the netplan config:
#!/bin/bash # Get MAC addresses for ens5 and ens6 ENS5_MAC=$(ip link show ens5 | awk '/ether/{print $2}') ENS6_MAC=$(ip link show ens6 | awk '/ether/{print $2}') # Write updated netplan config cat <<EOF | sudo tee /etc/netplan/50-cloud-init.yaml network: ethernets: ens5: dhcp4: true match: macaddress: $ENS5_MAC set-name: ens5 ens6: dhcp4: true match: macaddress: $ENS6_MAC set-name: ens6 version: 2 EOF # Apply the config sudo netplan generate sudo netplan apply
Step 2: Run the Script via Systems Manager
- Go to the AWS Systems Manager console → Run Command.
- Select Run a command, then choose the
AWS-RunShellScriptdocument. - Paste the script above into the Commands field.
- Under Targets, select all your EC2 instances that need the secondary interface configured.
- Click Run to execute the script across all target instances.
Troubleshooting Tips
- If ens6 still doesn't get an IP, check the subnet's DHCP pool to ensure there are available IP addresses.
- Verify the route table for the GlusterFS subnet has the correct routes (if you need external access, ensure there's a route to an Internet Gateway; for internal-only access, confirm routes to other subnets in the VPC).
- Check system logs with
journalctl -u systemd-networkdto debug netplan/networking issues.
内容的提问来源于stack exchange,提问作者user14389292

