误执行iptables规则致AWS EC2服务器SSH连接中断,如何恢复?
Fixing SSH Access to EC2 After Setting
iptables -P INPUT DROP Without Allowing Port 22 We’ve all been there—testing iptables rules and accidentally locking ourselves out by setting the default INPUT policy to DROP without whitelisting SSH first. Here are the actionable ways to regain access:
1. Use the EC2 Serial Console (Quickest if Enabled)
If your instance has the EC2 Serial Console enabled (default for most new instances), this is the fastest path:
- Head to the AWS EC2 Console, select your locked instance, and click Connect.
- Switch to the Serial Console tab, then click Connect.
- In the terminal that opens, log in with your instance’s default username (e.g.,
ec2-userfor RHEL/CentOS,ubuntufor Ubuntu). You may need to use the SSH key pair’s passphrase if you set one. - Run these commands to restore access:
# First allow all incoming traffic temporarily iptables -P INPUT ACCEPT # Then add a permanent rule for SSH (optional but recommended) iptables -A INPUT -p tcp --dport 22 -j ACCEPT # Save the rules so they persist after reboot (varies by OS) # For Ubuntu/Debian: iptables-save > /etc/iptables/rules.v4 # For CentOS/RHEL: service iptables save - You should now be able to SSH back into the instance normally.
2. Fix via Instance User Data (Works for EBS-Backed Instances)
If the Serial Console isn’t an option, you can modify the instance’s user data to run a fix script on reboot:
- Stop the instance (only do this if it’s EBS-backed—instance-store instances will lose data on stop).
- Go to Actions > Instance Settings > Edit User Data.
- Paste a script tailored to your OS:
- For Ubuntu/Debian:
#!/bin/bash iptables -P INPUT ACCEPT iptables-save > /etc/iptables/rules.v4 - For CentOS/RHEL:
#!/bin/bash iptables -P INPUT ACCEPT service iptables save
- For Ubuntu/Debian:
- Save the user data, then start the instance. The script will run on boot, resetting your iptables policy.
- Once you’re back in via SSH, remember to edit the user data again to remove the script (so it doesn’t run on future reboots unnecessarily).
3. Create an AMI and Launch a Fixed Instance
If the above methods fail, you can create a snapshot-based AMI and launch a new instance with a fix:
- Stop the locked instance, then create an AMI from it (Actions > Image and templates > Create image).
- Launch a new instance using this AMI. When configuring the instance, add the same iptables-fix script to the user data (as in Method 2).
- The new instance will boot with the iptables policy reset, allowing SSH access. You can then migrate data from the old instance’s EBS volume or just use the new instance.
4. Use AWS Systems Manager (If Preconfigured)
If you already set up SSM Agent on the instance and attached an IAM role with SSM permissions:
- Go to the AWS Systems Manager Console, navigate to Session Manager, and click Start session.
- Select your locked instance and connect.
- Run the same iptables commands from Method 1 to restore SSH access.
内容的提问来源于stack exchange,提问作者Keselme
相关产品推荐
相关产品推荐

