Troubleshooting
Use this guide to diagnose connectivity issues between an on-premises data center and an Elastic Compute Service (ECS) instance in a Virtual Private Cloud (VPC).
Background
The troubleshooting steps are as follows:
Troubleshoot routing issues.
Troubleshoot Layer 3/4 (network/transport layer) issues.
Troubleshoot Layer 2 (data link layer) issues.
Troubleshoot Layer 1 (physical layer) issues.
Diagnose network routing issues
If the local access device can ping the IP of the cloud Virtual Border Router (VBR) and a BGP peering session has been established, but your local server still cannot ping the ECS instance in the cloud VPC, troubleshoot the issue by following these steps:
If you use the Express Connect - Peering Connection product to connect the cloud and on-premises environments, check the VBR-to-VPC health check status of the Express Connect.
If you use the Cloud Enterprise Network (CEN) to connect the cloud and on-premises environments, check the health check status of the CEN VBR.
If the routing mode is BGP, ensure that the local gateway has announced your local network segment through BGP.
Ensure that your or your provider's BGP route announcement does not exceed 110 route entries. Beyond this limit, route entries will be discarded, but the BGP peer connection can still be established.
Ensure that your local gateway route table contains a route pointing to the cloud VPC, with the next hop being the IP of the cloud VBR.
Ensure that your VBR route table contains a route pointing to the local network segment, with the next hop being the physical connection interface.
Ensure that your VBR route table contains a route pointing to the cloud VPC, with the next hop being the VPC instance ID.
Ensure that your VPC route table contains a route pointing to the local network segment, with the next hop being the VBR.
Ensure that your ECS security group and network ACL allow inbound and outbound traffic for your local network.
Why can only a specific ECS access the private network/local IDC while other ECS instances cannot?
If only a specific ECS can access the private network or local IDC, this is usually not an issue with the leased line or Cloud Enterprise Network (CEN) connectivity. Instead, the business owner has applied special forwarding restrictions or controls inside the ECS (such as iptables or firewall software) or at the network layer (such as security group, network ACL, or custom route table). We recommend that you first check the access control policy of the ECS and its subnet.
Troubleshoot Layer 3/4 (network/transport layer) issues
If the local access device can ping the IP of the cloud Virtual Border Router (VBR) but the local BGP peering session cannot be established, troubleshoot the issue by following these steps:
Ensure that your BGP has correctly configured the local Autonomous System Number (ASN) and the ASN of Alibaba Cloud.
Ensure that the peer IP at both ends of the BGP peering session is correctly configured.
Ensure that your MD5 authentication key is configured and exactly matches the key in the downloaded router configuration file.
NoteCheck for any extra spaces or characters.
Ensure that there are no firewall or ACL rules that restrict TCP port 179 or ephemeral TCP ports above 1024. These ports are required for BGP to establish a TCP connection between peers.
Check your BGP log for any error or warning messages.
If the BGP peering session is not established after the above steps, submit a ticket for consultation.
After the leased line is connected, the traceroute results are empty or interrupted, but the service is normal. How do I troubleshoot?
Check the route table of the cloud Virtual Border Router (VBR), confirm that the next hop of the destination network segment is correct, and delete old lines or conflicting more specific routes (such as /32 host routes).
Check whether the on-premises IDC device has enabled the ICMP timeout reply function. If not, intermediate nodes will not respond to probe packets, and traceroute will appear empty, but this does not affect actual TCP/UDP services.
Verify the connectivity of the actual service port. If the service is normal, the network layer is correct, and the traceroute anomaly is only caused by the device ICMP configuration.
Troubleshoot Layer 2 (data link layer) issues
The indicator light of the local IDC access device is normal, but the access device cannot ping the IP of the cloud Virtual Border Router (VBR). Troubleshoot the issue by following these steps:
Check whether your interconnected IP address is correctly configured, ensure that the interconnected IP addresses are in the same network segment, and that they are in the correct VLAN.
Ensure that the interconnected IP address is configured on the VLAN sub-interface rather than the physical interface (for example, GigabitEthernet0/0.123 instead of GigabitEthernet0/0).
Verify that the router has the MAC address entry of the cloud VBR node from your Address Resolution Protocol (ARP) table.
Ensure that any device between the cloud VBR and the local IDC access device has VLAN trunk enabled for your 802.1Q VLAN tag.
Verify that the VLAN ID configuration is consistent. When the leased line is still unreachable after modifying the VLAN ID of the Virtual Border Router (VBR), you must check whether the VLAN ID of the cloud VBR and the local IDC access device are exactly the same; if the on-premises side has no VLAN configured, set the VBR VLAN ID to 0.
After changing the VLAN ID configuration, you must synchronously check whether the peer port configuration has been updated, and troubleshoot whether the peer has a network ACL restriction.
Clear your or your provider's ARP table cache.
If ARP is not established after the above steps or you still cannot perform ping on the cloud VBR, submit a ticket for consultation.
Troubleshoot Layer 1 (physical layer) issues
If the indicator light of the local leased line access device is not on, troubleshoot the issue by following these steps:
Check whether the CPE access device in the local IDC is powered on and whether the port is activated.
Confirm with your leased line provider whether the leased line has completed end-to-end access, and ask the leased line provider to provide you with the leased line construction completion certificate and the end-to-end network connectivity test certificate.
Check whether the optical module at both ends of the leased line is normal.
Check whether the distance supported by the optical module parameters is consistent. If the two sides are inconsistent, the port indicator light will not turn on.
Check whether the bandwidth specification supported by the optical module parameters is consistent. If the two sides are inconsistent, the port indicator light will not turn on.
For optical fiber access, you must use a single-mode optical module that supports 1000Base-LX for 1GB Ethernet, 10GBase-LR for 10GB Ethernet, 40GBase-LR for 40GB Ethernet, or 100GBase-LR for 100GB Ethernet to connect to the Alibaba Cloud access device, and the optical module parameters at both ends must be consistent.
Check whether the local CPE has auto-negotiation disabled and has manually configured the port speed and full-duplex mode.
Most network devices on the market, such as Juniper, have auto-negotiation enabled. Manually disable this function.
Contact the line provider to complete the leased line segment test.
On your own, contact the line provider or the local IDC data center provider to perform the in-building cable test between the ODF and the local access device in the local IDC. If a loopback test is required, cooperate with the provider to perform an optical loopback in the local IDC.
On your own, contact the line provider to test the link between the local IDC and the carrier access device. If a loopback test is required, cooperate with the carrier to perform an optical loopback in the local IDC.
The line provider contacts the carrier to complete the internal network link test on the transport network.
On your own, contact the line provider to perform the in-building cable test between the ODF and the Alibaba Cloud access device in the data center where the Alibaba Cloud access point is located.
To test the tail fiber cable on the Alibaba Cloud side, submit a ticket.
To help you understand leased line segment management, the network topology of a traditional leased line connection is shown in the following figure, Please consult the carrier for the actual network topology.