You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS私有子网间EC2实例能否直接连通?如何实现?

Can EC2 Instances in Two Private Subnets (Same VPC) Communicate Directly?

Hey Philip, great question! The short answer is yes—EC2 instances in two private subnets within the same Amazon VPC can absolutely communicate directly with each other. In fact, this connectivity is enabled by default in most standard VPC setups. Let me break down how it works and what to check if you run into issues:

Why It Works by Default

All subnets (public or private) in the same VPC share the same VPC CIDR range. The main route table (or any custom route table you’ve associated with your private subnets) automatically includes a Local route rule. This rule allows all traffic within the VPC’s CIDR block to flow freely between any IPs in the VPC—so instances in your two private subnets can reach each other via their private IP addresses without needing to go through the internet or a NAT gateway.

Key Configurations to Verify (If Connectivity Fails)

If you find your instances can’t communicate, double-check these common points:

  • Security Group Rules: Ensure the security groups attached to both EC2 instances allow traffic from each other’s subnet CIDR ranges. For example, if your first private subnet uses 10.0.1.0/24 and the second uses 10.0.2.0/24, the security group for instance A should have an inbound rule allowing traffic from 10.0.2.0/24 (for the ports/protocols you need), and vice versa for instance B’s security group.
  • Network Access Control Lists (NACLs): NACLs act as subnet-level firewalls. By default, they allow all inbound and outbound traffic, but if you’ve modified them, make sure they aren’t blocking bidirectional traffic between the two subnets. You’ll need to allow both inbound traffic from the other subnet and outbound traffic to it.
  • Route Table Associations: Confirm that each private subnet is associated with a route table that includes the Local route (targeting your VPC’s full CIDR range). This route is auto-created by AWS when you make the VPC—don’t delete it! If it’s missing for some reason, add a new route with the destination as your VPC CIDR and target set to Local.

How to Test Connectivity

To confirm the instances can talk to each other, log into one of the private subnet instances and run:

  • Test basic ICMP connectivity (ping): ping <private-ip-of-other-instance>
  • Test a specific port (e.g., port 22 for SSH): telnet <private-ip-of-other-instance> 22

If these commands succeed, your instances are communicating directly as expected.


内容的提问来源于stack exchange,提问作者Philip Shangguan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.28 07:24:18