AWS新手咨询:t2.micro实例安全组规则未生效排查方向
Hey there! Let's break down the key things to check when non-authorized IPs can still reach your web app—security group changes take effect immediately, so that 1-hour wait isn't necessary. Here's your troubleshooting checklist:
Verify the correct security group is attached to your instance
It's easy to edit a security group but forget to associate it with your t2.micro, or leave the instance in another security group that has open rules. Head to the EC2 console, select your instance, and check the Security groups tab to confirm all attached groups have the restricted IP rules you intended.Double-check your security group inbound rules
- Did you accidentally use
0.0.0.0/0(open to all IPs) instead of your specific authorized IP with/32suffix? - Is the port matching what your web app uses? (e.g., 80 for HTTP, 443 for HTTPS, or a custom port)
- Is the protocol set to TCP? Most web apps rely on TCP, not UDP.
- Did you accidentally use
Check your VPC Network ACLs (NACLs)
NACLs act as a subnet-level firewall. Even if your security group is tight, a misconfigured NACL might allow all inbound traffic to your web port. Navigate to the VPC console, find the subnet your instance is in, and review the NACL's inbound rules to ensure they don't override your security group restrictions.Inspect the instance's local firewall
Linux instances might haveiptablesrules, and Windows instances have their own built-in firewall, that could be allowing wide access. Log into your instance:- For Linux, run
iptables -Lto list current rules and check if there's a rule allowing all IPs to your web port. - For Windows, open Windows Defender Firewall settings and verify inbound rules for your web app's port.
- For Linux, run
Check for load balancers or reverse proxies
If your app is behind an Application Load Balancer (ALB) or Network Load Balancer (NLB), the security group rules on the EC2 instance might not be the main gatekeeper. You'll need to check:- The load balancer's security group (it should restrict traffic to authorized IPs)
- The security group rules allowing traffic from the load balancer to your EC2 instance
Rule out CDN/caching effects
If you're using a CDN like CloudFront, cached content might still be accessible, or the CDN's distribution settings could be allowing unrestricted access. Verify the CDN's origin access controls and distribution restrictions.
Security group updates don't require any waiting period—they apply as soon as you save them. Start with the first two checks, since those are the most common pitfalls for new AWS users!
内容的提问来源于stack exchange,提问作者Alex

