A company is experiencing intermittent connectivity issues to an EC2 instance in a private subnet from an on-premises data center connected via AWS Direct Connect. The network team has verified that the Direct Connect connection itself is stable, and the on-premises router has the correct routes for the VPC CIDR. However, ping and SSH to the instance fail. What is the MOST likely cause of this issue?
- AThe Network Access Control List (NACL) associated with the private subnet is blocking the traffic.
- BThe Security Group attached to the EC2 instance is blocking the incoming traffic.
- CThe Direct Connect Gateway is not associated with the correct Virtual Private Gateway.
- DThe EC2 instance is in a public subnet, and its public IP address is being used.
Show answer & explanationAnswer & explanation
Correct answer: B. The Security Group attached to the EC2 instance is blocking the incoming traffic.
Given that Direct Connect is stable, on-premises routes are correct, and the instance is in a private subnet, the most common issue for failing ping and SSH (which use specific ports) is a restrictive Security Group. Security Groups act as stateful firewalls for instances, and if they don't explicitly allow ICMP for ping or TCP port 22 for SSH from the on-premises IP ranges, the connection will fail. NACLs are stateless and apply at the subnet level, often configured to be more permissive, but Security Groups are usually the first place to check for instance-specific traffic blocking.
Why the other options are wrong
- A. While a NACL could block traffic, Security Groups are often more granularly configured and are a more common point of failure for specific protocols/ports to an instance.
- C. If the Direct Connect Gateway was not associated, no traffic would reach the VPC, not just specific protocols to an instance.
- D. The question states the instance is in a private subnet, so it wouldn't have a public IP being used for Direct Connect access.
AWS Network Troubleshooting Flow
A systematic approach to diagnose and resolve network connectivity issues within an AWS environment, often starting with the most common points of failure.
- Verify network path components (Direct Connect, VPN, VPC, Subnets).
- Check routing tables for correct pathing.
- Inspect Security Groups and NACLs for traffic filtering.
Memory trick: Path, Route, Firewall (NACL then SG), Instance Status.