doc-exports/docs/eip/umn/faq_connect_0004.html
fanqinying f14bb7d85a EIP UMN 20241028 version
Reviewed-by: Sarda, Priya <prsarda@noreply.gitea.eco.tsi-dev.otc-service.com>
Co-authored-by: fanqinying <fanqinying@huawei.com>
Co-committed-by: fanqinying <fanqinying@huawei.com>
2024-12-03 10:53:45 +00:00

164 lines
30 KiB
HTML

<a name="faq_connect_0004"></a><a name="faq_connect_0004"></a>
<h1 class="topictitle1">What Should I Do If an EIP Cannot Be Pinged?</h1>
<div id="body8662426"><div class="section" id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_section33522024122612"><h4 class="sectiontitle">Symptom</h4><p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p9653153062612">After you purchase an EIP and bind it to an ECS, the local host or other cloud servers cannot ping the EIP of the ECS.</p>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section1116655241118"><h4 class="sectiontitle">Fault Locating</h4><p id="faq_connect_0004__en-us_topic_0105130172_p17987205213470">The following fault causes are sequenced based on their occurrence probability.</p>
<p id="faq_connect_0004__en-us_topic_0105130172_p997211345215">If the fault persists after you have ruled out a cause, check other causes.</p>
<div class="fignone" id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0118498854_fig257119102320"><span class="figcap"><b>Figure 1 </b>Method of locating the failure to ping an EIP</span><br><span><img id="faq_connect_0004__en-us_topic_0105130172_image67448533518" src="en-us_image_0000001223659800.png"></span></div>
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="faq_connect_0004__en-us_topic_0105130172_table6168184132811" frame="border" border="1" rules="all"><caption><b>Table 1 </b>Method of locating the failure to ping an EIP</caption><thead align="left"><tr id="faq_connect_0004__en-us_topic_0105130172_row31680416283"><th align="left" class="cellrowborder" valign="top" width="28.189999999999998%" id="mcps1.3.2.5.2.3.1.1"><p id="faq_connect_0004__en-us_topic_0105130172_p17639192710215">Possible Causes</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="71.81%" id="mcps1.3.2.5.2.3.1.2"><p id="faq_connect_0004__en-us_topic_0105130172_p1063918274214">Solution</p>
</th>
</tr>
</thead>
<tbody><tr id="faq_connect_0004__en-us_topic_0105130172_row6168941172810"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p174364119463">ICMP access rules are not added to the security group.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p11168104115284">Add ICMP access rules to the security group. For details, see <a href="#faq_connect_0004__en-us_topic_0105130172_section1715910911214">Checking Security Group Rules</a>.</p>
</td>
</tr>
<tr id="faq_connect_0004__en-us_topic_0105130172_row41681741172819"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p716874117282">Ping operations are prohibited on the firewall.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p31691416286">Allow ping operations on the firewall. For details, see <a href="#faq_connect_0004__en-us_topic_0105130172_section774414326138">Checking Firewall Settings</a>.</p>
</td>
</tr>
<tr id="faq_connect_0004__en-us_topic_0105130172_row796182813291"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p1296116289297">Ping operations are prohibited on the ECS.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p7961192852920">Allow ping operations on the ECS. For details, see <a href="#faq_connect_0004__en-us_topic_0105130172_section42301821174115">Checking Whether Ping Operations Have Been Disabled on the ECS</a>.</p>
</td>
</tr>
<tr id="faq_connect_0004__en-us_topic_0105130172_row1596162815296"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p6961152892919">Network ACL is associated.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p1496152892917">If the VPC is associated with a network ACL, check the network ACL rules. For details, see <a href="#faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_section374314592329">Checking ACL Rules</a>.</p>
</td>
</tr>
<tr id="faq_connect_0004__en-us_topic_0105130172_row18169124122820"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p31691418284">A network exception occurred.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p19169541152818">Use another ECS in the same region to check whether the local network is functional. For details, see <a href="#faq_connect_0004__en-us_topic_0105130172_section108152100162">Checking Whether the Network Is Functional</a>.</p>
</td>
</tr>
<tr id="faq_connect_0004__en-us_topic_0105130172_row1920342419296"><td class="cellrowborder" valign="top" width="28.189999999999998%" headers="mcps1.3.2.5.2.3.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p12045243298">Routes are incorrectly configured if multiple NICs are used.</p>
</td>
<td class="cellrowborder" valign="top" width="71.81%" headers="mcps1.3.2.5.2.3.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p1820462462919">If the network is inaccessible due to an extension NIC, the fault is generally caused by incorrect route configurations. To resolve this issue, see <a href="#faq_connect_0004__en-us_topic_0105130172_section175172388145">Checking the ECS Route Configuration If Multiple NICs Are Used</a>.</p>
</td>
</tr>
</tbody>
</table>
</div>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section1715910911214"><a name="faq_connect_0004__en-us_topic_0105130172_section1715910911214"></a><a name="en-us_topic_0105130172_section1715910911214"></a><h4 class="sectiontitle">Checking Security Group Rules</h4><p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p74698814216">ICMP is used for the ping command. Check whether the security group accommodating the <span id="faq_connect_0004__en-us_topic_0105130172_text188715155189">ECS</span> allows ICMP traffic.</p>
<ol id="faq_connect_0004__en-us_topic_0105130172_ol1062118920910"><li id="faq_connect_0004__en-us_topic_0105130172_li899315381790">Log in to the management console.</li><li id="faq_connect_0004__en-us_topic_0105130172_li464234814566">Click <span><img id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0014250631_image1862675853202121" src="en-us_image_0210779229.png"></span> in the upper left corner and select your region and project.</li><li id="faq_connect_0004__en-us_topic_0105130172_li1859019014179">Under <strong id="faq_connect_0004__en-us_topic_0105130172_b1731472219303"><span id="faq_connect_0004__en-us_topic_0105130172_text16825102892510">Computing</span></strong>, choose <strong id="faq_connect_0004__en-us_topic_0105130172_b53141522153014">Elastic Cloud Server</strong>.</li><li id="faq_connect_0004__en-us_topic_0105130172_li34401539214315">On the <strong id="faq_connect_0004__en-us_topic_0105130172_b116104274418">Elastic Cloud Server</strong> page, click the name of the target <span id="faq_connect_0004__en-us_topic_0105130172_text10144144802310">ECS</span>.<p id="faq_connect_0004__en-us_topic_0105130172_p19982029214319">The page providing details about the <span id="faq_connect_0004__en-us_topic_0105130172_text186236591941">ECS</span> is displayed.</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li45534692214355">Click the <strong id="faq_connect_0004__en-us_topic_0105130172_b101784411513">Security Groups</strong> tab, expand the information of the security group, and view security group rules.</li><li id="faq_connect_0004__en-us_topic_0105130172_li2997365821442">Click the security group ID.<p id="faq_connect_0004__en-us_topic_0105130172_p5857465521443"><a name="faq_connect_0004__en-us_topic_0105130172_li2997365821442"></a><a name="en-us_topic_0105130172_li2997365821442"></a>The system automatically switches to the <strong id="faq_connect_0004__en-us_topic_0105130172_b5881737191118">Security Group</strong> page.</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li10861174114534">On the <strong id="faq_connect_0004__en-us_topic_0105130172_b4259884266">Outbound Rules</strong> page, click <strong id="faq_connect_0004__en-us_topic_0105130172_b14259168162614">Add Rule</strong>. In the displayed dialog box, set required parameters to add an outbound rule.
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="faq_connect_0004__en-us_topic_0105130172_table20711140338" frame="border" border="1" rules="all"><caption><b>Table 2 </b>Security group rules</caption><thead align="left"><tr id="faq_connect_0004__en-us_topic_0105130172_row11721740839"><th align="left" class="cellrowborder" valign="top" width="15.57%" id="mcps1.3.3.3.7.3.2.5.1.1"><p id="faq_connect_0004__en-us_topic_0105130172_p9722401533">Transfer Direction</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="17.32%" id="mcps1.3.3.3.7.3.2.5.1.2"><p id="faq_connect_0004__en-us_topic_0105130172_p1724407311">Type</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="21.89%" id="mcps1.3.3.3.7.3.2.5.1.3"><p id="faq_connect_0004__en-us_topic_0105130172_p19729400311">Protocol/Port Range</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="45.22%" id="mcps1.3.3.3.7.3.2.5.1.4"><p id="faq_connect_0004__en-us_topic_0105130172_p9725401936">Destination</p>
</th>
</tr>
</thead>
<tbody><tr id="faq_connect_0004__en-us_topic_0105130172_row57264012318"><td class="cellrowborder" valign="top" width="15.57%" headers="mcps1.3.3.3.7.3.2.5.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p1172164011314">Outbound</p>
</td>
<td class="cellrowborder" valign="top" width="17.32%" headers="mcps1.3.3.3.7.3.2.5.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p15726401538">IPv4</p>
</td>
<td class="cellrowborder" valign="top" width="21.89%" headers="mcps1.3.3.3.7.3.2.5.1.3 "><p id="faq_connect_0004__en-us_topic_0105130172_p107218401539">ICMP/Any</p>
</td>
<td class="cellrowborder" valign="top" width="45.22%" headers="mcps1.3.3.3.7.3.2.5.1.4 "><p id="faq_connect_0004__en-us_topic_0105130172_p1172440138">0.0.0.0/0</p>
<p id="faq_connect_0004__en-us_topic_0105130172_p672540231">0.0.0.0/0 indicates all IP addresses.</p>
</td>
</tr>
</tbody>
</table>
</div>
</li><li id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0029320966_li110100322530">On the <strong id="faq_connect_0004__en-us_topic_0105130172_b14616038181110">Inbound Rules</strong> tab, click <strong id="faq_connect_0004__en-us_topic_0105130172_b176161838201115">Add Rule</strong>. In the displayed dialog box, set required parameters to add an inbound rule.
<div class="tablenoborder"><table cellpadding="4" cellspacing="0" summary="" id="faq_connect_0004__en-us_topic_0105130172_table156272235264" frame="border" border="1" rules="all"><caption><b>Table 3 </b>Security group rules</caption><thead align="left"><tr id="faq_connect_0004__en-us_topic_0105130172_row362852317264"><th align="left" class="cellrowborder" valign="top" width="22.222222222222225%" id="mcps1.3.3.3.8.3.2.5.1.1"><p id="faq_connect_0004__en-us_topic_0105130172_p1662819236265">Transfer Direction</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="13.131313131313133%" id="mcps1.3.3.3.8.3.2.5.1.2"><p id="faq_connect_0004__en-us_topic_0105130172_p20628523132616">Type</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="25.252525252525253%" id="mcps1.3.3.3.8.3.2.5.1.3"><p id="faq_connect_0004__en-us_topic_0105130172_p162812311266">Protocol/Port Range</p>
</th>
<th align="left" class="cellrowborder" valign="top" width="39.3939393939394%" id="mcps1.3.3.3.8.3.2.5.1.4"><p id="faq_connect_0004__en-us_topic_0105130172_p16628323202611">Source</p>
</th>
</tr>
</thead>
<tbody><tr id="faq_connect_0004__en-us_topic_0105130172_row56286239261"><td class="cellrowborder" valign="top" width="22.222222222222225%" headers="mcps1.3.3.3.8.3.2.5.1.1 "><p id="faq_connect_0004__en-us_topic_0105130172_p14239113312264">Inbound</p>
</td>
<td class="cellrowborder" valign="top" width="13.131313131313133%" headers="mcps1.3.3.3.8.3.2.5.1.2 "><p id="faq_connect_0004__en-us_topic_0105130172_p10628023122614">IPv4</p>
</td>
<td class="cellrowborder" valign="top" width="25.252525252525253%" headers="mcps1.3.3.3.8.3.2.5.1.3 "><p id="faq_connect_0004__en-us_topic_0105130172_p462819234268">ICMP/Any</p>
</td>
<td class="cellrowborder" valign="top" width="39.3939393939394%" headers="mcps1.3.3.3.8.3.2.5.1.4 "><p id="faq_connect_0004__en-us_topic_0105130172_p115071006306">0.0.0.0/0</p>
<p id="faq_connect_0004__en-us_topic_0105130172_p350740123019">0.0.0.0/0 indicates all IP addresses.</p>
</td>
</tr>
</tbody>
</table>
</div>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li116512113184">Click <strong id="faq_connect_0004__en-us_topic_0105130172_b279013254135">OK</strong> to complete the security rule configuration.</li></ol>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section774414326138"><a name="faq_connect_0004__en-us_topic_0105130172_section774414326138"></a><a name="en-us_topic_0105130172_section774414326138"></a><h4 class="sectiontitle">Checking Firewall Settings</h4><p id="faq_connect_0004__en-us_topic_0105130172_p1429452284015">If a firewall is enabled on the <span id="faq_connect_0004__en-us_topic_0105130172_text1651091653318">ECS</span>, check whether the firewall blocks the ping operations.</p>
<div class="p" id="faq_connect_0004__en-us_topic_0105130172_p16626181817304"><strong id="faq_connect_0004__en-us_topic_0105130172_b2033715377335">Linux</strong><ol id="faq_connect_0004__en-us_topic_0105130172_ol1055845311436"><li id="faq_connect_0004__en-us_topic_0105130172_li6558453164313">Consider CentOS 7 as an example. Run the following command to check the firewall status:<p id="faq_connect_0004__en-us_topic_0105130172_p831844410518"><a name="faq_connect_0004__en-us_topic_0105130172_li6558453164313"></a><a name="en-us_topic_0105130172_li6558453164313"></a><strong id="faq_connect_0004__en-us_topic_0105130172_b15318144105117">firewall-cmd --state</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p1326884813458">If <strong id="faq_connect_0004__en-us_topic_0105130172_b10676181495317">running</strong> is displayed in the command output, the firewall has been enabled.</p>
</li></ol><ol start="2" id="faq_connect_0004__en-us_topic_0105130172_ol189501215164517"><li id="faq_connect_0004__en-us_topic_0105130172_li179501615104512">Check whether there is any ICMP rule blocking the ping operations.<p id="faq_connect_0004__en-us_topic_0105130172_p7791244231"><a name="faq_connect_0004__en-us_topic_0105130172_li179501615104512"></a><a name="en-us_topic_0105130172_li179501615104512"></a><strong id="faq_connect_0004__en-us_topic_0105130172_b17916413236">iptables -L</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p2053116127275">If the command output shown in <a href="#faq_connect_0004__en-us_topic_0105130172_fig7244357113416">Figure 2</a> is displayed, there is no ICMP rule blocking the ping operations.</p>
<div class="fignone" id="faq_connect_0004__en-us_topic_0105130172_fig7244357113416"><a name="faq_connect_0004__en-us_topic_0105130172_fig7244357113416"></a><a name="en-us_topic_0105130172_fig7244357113416"></a><span class="figcap"><b>Figure 2 </b>Checking firewall rules</span><br><span><img id="faq_connect_0004__en-us_topic_0105130172_image4422479410" src="en-us_image_0250117342.png"></span></div>
<p id="faq_connect_0004__en-us_topic_0105130172_p5988185917351">If the ping operations are blocked by an ICMP rule, run the following commands to modify the rule for unblocking:</p>
<p id="faq_connect_0004__en-us_topic_0105130172_p791544317361"><strong id="faq_connect_0004__en-us_topic_0105130172_b87941254133620">iptables -A INPUT -p icmp --icmp-type echo-request -j ACCEPT</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p2915343143619"><strong id="faq_connect_0004__en-us_topic_0105130172_b67951454183614">iptables -A OUTPUT -p icmp --icmp-type echo-reply -j ACCEPT</strong></p>
</li></ol>
</div>
<div class="p" id="faq_connect_0004__en-us_topic_0105130172_p85318279305"><strong id="faq_connect_0004__en-us_topic_0105130172_b108491313302">Windows</strong><ol id="faq_connect_0004__en-us_topic_0105130172_ol10282151610474"><li id="faq_connect_0004__en-us_topic_0105130172_li1084091310506">Log in to the Windows <span id="faq_connect_0004__en-us_topic_0105130172_text15855529189">ECS</span>, click the Windows icon in the lower left corner of the desktop, and choose <strong id="faq_connect_0004__en-us_topic_0105130172_b1154013327110">Control Panel</strong> &gt; <strong id="faq_connect_0004__en-us_topic_0105130172_b181941636131116">Windows Firewall</strong>.</li><li id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0138887282_li177027438277">Click <strong id="faq_connect_0004__en-us_topic_0105130172_b17394937121115">Turn Windows Firewall on or off</strong>.<p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0138887282_p1770284310272">View and set the firewall status.</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li818485585018">If the firewall is <strong id="faq_connect_0004__en-us_topic_0105130172_b521418431315">On</strong>, go to <a href="#faq_connect_0004__en-us_topic_0105130172_li192824161474">4</a>.</li><li id="faq_connect_0004__en-us_topic_0105130172_li192824161474"><a name="faq_connect_0004__en-us_topic_0105130172_li192824161474"></a><a name="en-us_topic_0105130172_li192824161474"></a>Check the ICMP rule statuses in the firewall.<ol type="a" id="faq_connect_0004__en-us_topic_0105130172_ol26465154285"><li id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0138887282_li1843115331458">In the navigation pane on the <strong id="faq_connect_0004__en-us_topic_0105130172_b133771445121320">Windows Firewall</strong> page, click <strong id="faq_connect_0004__en-us_topic_0105130172_b14382144581320">Advanced settings</strong>.</li><li id="faq_connect_0004__en-us_topic_0105130172_li866173020572">Enable the following rules:<p id="faq_connect_0004__en-us_topic_0105130172_p1538813371577"><a name="faq_connect_0004__en-us_topic_0105130172_li866173020572"></a><a name="en-us_topic_0105130172_li866173020572"></a><strong id="faq_connect_0004__en-us_topic_0105130172_b6907162218182">Inbound Rules</strong>: <strong id="faq_connect_0004__en-us_topic_0105130172_b877313110239">File and Printer Sharing (Echo Request - ICMPv4-In)</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p3699103115575"><strong id="faq_connect_0004__en-us_topic_0105130172_b14980443142318">Outbound Rules</strong>: <strong id="faq_connect_0004__en-us_topic_0105130172_b1272318616245">File and Printer Sharing (Echo Request - ICMPv4-Out)</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p128879121411">If IPv6 is enabled, enable the following rules:</p>
<p id="faq_connect_0004__en-us_topic_0105130172_p58681124711"><strong id="faq_connect_0004__en-us_topic_0105130172_b144968272613">Inbound Rules</strong>: <strong id="faq_connect_0004__en-us_topic_0105130172_b92587108265">File and Printer Sharing (Echo Request - ICMPv6-In)</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p1286813248114"><strong id="faq_connect_0004__en-us_topic_0105130172_b774531916267">Outbound Rules</strong>: <strong id="faq_connect_0004__en-us_topic_0105130172_b2075021914268">File and Printer Sharing (Echo Request - ICMPv6-Out)</strong></p>
<div class="fignone" id="faq_connect_0004__en-us_topic_0105130172_fig178326362544"><span class="figcap"><b>Figure 3 </b>Inbound Rules</span><br><span><img id="faq_connect_0004__en-us_topic_0105130172_image168322360545" src="en-us_image_0250182352.png"></span></div>
<div class="fignone" id="faq_connect_0004__en-us_topic_0105130172_fig5225320554"><span class="figcap"><b>Figure 4 </b>Outbound Rules</span><br><span><img id="faq_connect_0004__en-us_topic_0105130172_image6225620551" src="en-us_image_0250182717.png"></span></div>
</li></ol>
</li></ol>
</div>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section42301821174115"><a name="faq_connect_0004__en-us_topic_0105130172_section42301821174115"></a><a name="en-us_topic_0105130172_section42301821174115"></a><h4 class="sectiontitle">Checking Whether Ping Operations Have Been Disabled on the <span id="faq_connect_0004__en-us_topic_0105130172_text22714541916">ECS</span></h4><p id="faq_connect_0004__en-us_topic_0105130172_p615911372419"><strong id="faq_connect_0004__en-us_topic_0105130172_b539555012416">Windows</strong></p>
<p id="faq_connect_0004__en-us_topic_0105130172_p4753258105312">Enable ping operations using the CLI.</p>
<ol id="faq_connect_0004__en-us_topic_0105130172_ol1618218354917"><li id="faq_connect_0004__en-us_topic_0105130172_li125993812499">Start the <strong id="faq_connect_0004__en-us_topic_0105130172_b19819318131214">Run</strong> dialog box. Enter <strong id="faq_connect_0004__en-us_topic_0105130172_b325823012138">cmd</strong> and press <strong id="faq_connect_0004__en-us_topic_0105130172_b44704359133">Enter</strong>.</li><li id="faq_connect_0004__en-us_topic_0105130172_li1218223144919">Run the following command to enable ping operations:<p id="faq_connect_0004__en-us_topic_0105130172_p198365597494"><a name="faq_connect_0004__en-us_topic_0105130172_li1218223144919"></a><a name="en-us_topic_0105130172_li1218223144919"></a><strong id="faq_connect_0004__en-us_topic_0105130172_b33993135016">netsh firewall set icmpsetting 8</strong></p>
</li></ol>
<p id="faq_connect_0004__en-us_topic_0105130172_p991054215412"><strong id="faq_connect_0004__en-us_topic_0105130172_b13349204824120">Linux</strong></p>
<div class="p" id="faq_connect_0004__en-us_topic_0105130172_p67581627134220">Check the <span id="faq_connect_0004__en-us_topic_0105130172_text15149710171914">ECS</span> kernel parameters.<ol id="faq_connect_0004__en-us_topic_0105130172_ol722915110309"><li id="faq_connect_0004__en-us_topic_0105130172_li11577145132912">Check the <strong id="faq_connect_0004__en-us_topic_0105130172_b1212175941318">net.ipv4.icmp_echo_ignore_all</strong> value in the <strong id="faq_connect_0004__en-us_topic_0105130172_b19163591138">/etc/sysctl.conf</strong> file. Value <strong id="faq_connect_0004__en-us_topic_0105130172_b317135961316">0</strong> indicates that ping operations are allowed, and value <strong id="faq_connect_0004__en-us_topic_0105130172_b121725912133">1</strong> indicates that ping operations are prohibited.</li><li id="faq_connect_0004__en-us_topic_0105130172_li1346662173317">Allow ping operations.<ul id="faq_connect_0004__en-us_topic_0105130172_ul7102344341"><li id="faq_connect_0004__en-us_topic_0105130172_li810217483410">Run the following command to temporarily allow the ping operations:<p id="faq_connect_0004__en-us_topic_0105130172_p161331327342"><a name="faq_connect_0004__en-us_topic_0105130172_li810217483410"></a><a name="en-us_topic_0105130172_li810217483410"></a>#echo 0 &gt;/proc/sys/net/ipv4/icmp_echo_ignore_all</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li1844321212346">Run the following command to permanently allow the ping operations:<p id="faq_connect_0004__en-us_topic_0105130172_p7749122415345"><a name="faq_connect_0004__en-us_topic_0105130172_li1844321212346"></a><a name="en-us_topic_0105130172_li1844321212346"></a>net.ipv4.icmp_echo_ignore_all=0</p>
</li></ul>
</li></ol>
</div>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_section374314592329"><a name="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_section374314592329"></a><a name="en-us_topic_0105130172_en-us_topic_0096302298_section374314592329"></a><h4 class="sectiontitle">Checking ACL Rules</h4><p id="faq_connect_0004__en-us_topic_0105130172_p19468152511410">By default, no ACL is configured for a VPC. If a network ACL is associated with a VPC, check the ACL rules.</p>
<ol id="faq_connect_0004__en-us_topic_0105130172_ol753403917104"><li id="faq_connect_0004__en-us_topic_0105130172_li853473931019">Check whether the subnet of the <span id="faq_connect_0004__en-us_topic_0105130172_text152483360">ECS</span> has been associated with a network ACL.<p id="faq_connect_0004__en-us_topic_0105130172_p410725111267">If an ACL name is displayed, the network ACL has been associated with the ECS.</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li168229277161">Click the ACL name to view its status.</li><li id="faq_connect_0004__en-us_topic_0105130172_li7701418122214">If the network ACL is enabled, add an ICMP rule to allow traffic.<div class="note" id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_note179761105114"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p19869922514">The default network ACL rule denies all incoming and outgoing packets. If a network ACL is disabled, the default rule is still effective.</p>
</div></div>
</li></ol>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section108152100162"><a name="faq_connect_0004__en-us_topic_0105130172_section108152100162"></a><a name="en-us_topic_0105130172_section108152100162"></a><h4 class="sectiontitle">Checking Whether the Network Is Functional</h4><ol id="faq_connect_0004__en-us_topic_0105130172_ol4273151815246"><li id="faq_connect_0004__en-us_topic_0105130172_li183722415244">Use another ECS in the same region to check whether the local network is functional.<p id="faq_connect_0004__en-us_topic_0105130172_p1994410241162"><a name="faq_connect_0004__en-us_topic_0105130172_li183722415244"></a><a name="en-us_topic_0105130172_li183722415244"></a>Use another <span id="faq_connect_0004__en-us_topic_0105130172_text1163122911196">ECS</span> in the same region to ping the affected EIP. If the EIP can be pinged, the VPC is functional. In such a case, rectify the local network fault and ping the affected EIP again.</p>
</li><li id="faq_connect_0004__en-us_topic_0105130172_li116916545251">Check whether the link is accessible.<p id="faq_connect_0004__en-us_topic_0105130172_p2058145515259"><a name="faq_connect_0004__en-us_topic_0105130172_li116916545251"></a><a name="en-us_topic_0105130172_li116916545251"></a>A ping failure is caused by packet loss or long delay, which may be caused by link congestion, link node faults, or heavy load on the ECS.</p>
</li></ol>
</div>
<div class="section" id="faq_connect_0004__en-us_topic_0105130172_section175172388145"><a name="faq_connect_0004__en-us_topic_0105130172_section175172388145"></a><a name="en-us_topic_0105130172_section175172388145"></a><h4 class="sectiontitle">Checking the <span id="faq_connect_0004__en-us_topic_0105130172_text4584163715198">ECS</span> Route Configuration If Multiple NICs Are Used</h4><p id="faq_connect_0004__en-us_topic_0105130172_p11592164684517">Generally, the default route of an OS will preferentially select the primary NIC. If an extension NIC is selected in a route and the network malfunctions, this issue is typically caused by incorrect route configuration.</p>
<ul id="faq_connect_0004__en-us_topic_0105130172_ul1371243722220"><li id="faq_connect_0004__en-us_topic_0105130172_li671203752218">If the <span id="faq_connect_0004__en-us_topic_0105130172_text2865124720382">ECS</span> has multiple NICs, check whether the default route is available.<ol id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_ol318215556917"><li id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_li132249417418">Log in to the <span id="faq_connect_0004__en-us_topic_0105130172_text739715439192">ECS</span> and run the following command to check whether the default route is available:<p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p49772412048"><strong id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_b15976194111411">ip route</strong></p>
<div class="fignone" id="faq_connect_0004__en-us_topic_0105130172_fig7362102412018"><span class="figcap"><b>Figure 5 </b>Default route</span><br><span><img id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_image1325712242053" src="en-us_image_0250105611.png"></span></div>
</li><li id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_li184775918912">If the route is unavailable, run the following command to add it:<p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p789310591997"><a name="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_li184775918912"></a><a name="en-us_topic_0105130172_en-us_topic_0096302298_li184775918912"></a><strong id="faq_connect_0004__en-us_topic_0105130172_b624847161618">ip route add default via XXXX dev eth0</strong></p>
<div class="note" id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_note18894559299"><img src="public_sys-resources/note_3.0-en-us.png"><span class="notetitle"> </span><div class="notebody"><p id="faq_connect_0004__en-us_topic_0105130172_en-us_topic_0096302298_p1489415591694">In the preceding command, <em id="faq_connect_0004__en-us_topic_0105130172_i21294530318551">XXXX</em> specifies a gateway IP address.</p>
</div></div>
</li></ol>
</li></ul>
</div>
<ul id="faq_connect_0004__en-us_topic_0105130172_ul69571545102217"><li id="faq_connect_0004__en-us_topic_0105130172_li17957154515226">If the <span id="faq_connect_0004__en-us_topic_0105130172_text1339924813379">ECS</span> has multiple NICs and the <span id="faq_connect_0004__en-us_topic_0105130172_text6869102322011">EIP</span> is bound to an extension NIC, configure policy routing on the <span id="faq_connect_0004__en-us_topic_0105130172_text1253191703814">ECS</span> for network communication with the extension NIC.</li></ul>
</div>
<div>
<div class="familylinks">
<div class="parentlink"><strong>Parent topic:</strong> <a href="faq_connect.html">Connectivity</a></div>
</div>
</div>