Troubleshoot an Instance Boot Connection Timeout v2.2 New
Troubleshoot an Instance Boot Connection Timeout v2.2 New
Use this playbook when an assigned machine times out while downloading a tenant operating-system image from a PXE or HTTP server hosted on another instance.
Symptoms and Data to Collect
The console shows an iPXE timeout similar to:
Collect the following before changing the network configuration:
- The failing tenant instance ID.
- The complete URL from the console, including IP address and port.
- The source address and interface that the boot client uses to reach the timed-out address, and that interface’s VPC ID.
- The PXE server instance ID, the interface that owns the timed-out address, and that interface’s VPC ID.
If the instances use different VPCs without peering, the boot path is unreachable. If they use the same VPC or peered VPCs, investigate routing and tenant-defined security controls.
Identify Both VPCs
-
Show the failing instance:
In the
INTERFACESsection, match the source address used by the boot client to the correspondingADDRESSESrow and record that row’sVPC ID. An instance can have interfaces in multiple VPCs, so do not use a VPC ID from another interface. If the source interface is not known, determine the boot route before continuing with the peering checks. -
Find the instance that owns the IP address in the timed-out URL:
-
Show that instance. In the
INTERFACESsection, find theADDRESSESrow containing the timed-out IP address and record that row’sVPC ID:
Check VPC Peering
If the VPC IDs differ, list the peerings for each VPC:
- If no peering connects the two VPCs, place both instances in one VPC or configure peering. Refer to VPC Peering.
- If the VPCs are already peered, or the instances use the same VPC, continue with path and policy checks.
Check the Network Path
- From an instance in the tenant VPC, test the PXE server IP and port.
- Verify routes in both directions between the tenant and PXE server interfaces.
- Check network security groups and host firewalls for the protocol and port in the failed URL. Refer to Network Security Groups.
- Verify that the HTTP service is listening on the PXE server and bound to the expected address.
Verify Recovery
- Confirm that the two instances are in the same VPC or connected by an active VPC peering.
- Retry the instance boot.
- Confirm that the console downloads the boot image without an iPXE timeout and that the managed host boots the tenant operating system.
The iPXE error reference describes the timeout status reported by the boot client.