Troubleshoot an Instance Boot Connection Timeout v2.2 New

View as Markdown

Use this playbook when an assigned machine times out while downloading a tenant operating-system image from a PXE or HTTP server hosted on another instance.

Symptoms and Data to Collect

The console shows an iPXE timeout similar to:

http://192.0.2.20:8080/boot/tenant-os... Connection timed out
(https://ipxe.org/4c0a6092)

Collect the following before changing the network configuration:

  • The failing tenant instance ID.
  • The complete URL from the console, including IP address and port.
  • The source address and interface that the boot client uses to reach the timed-out address, and that interface’s VPC ID.
  • The PXE server instance ID, the interface that owns the timed-out address, and that interface’s VPC ID.

If the instances use different VPCs without peering, the boot path is unreachable. If they use the same VPC or peered VPCs, investigate routing and tenant-defined security controls.

Identify Both VPCs

  1. Show the failing instance:

    nico-admin-cli instance show <tenant-instance-id>

    In the INTERFACES section, match the source address used by the boot client to the corresponding ADDRESSES row and record that row’s VPC ID. An instance can have interfaces in multiple VPCs, so do not use a VPC ID from another interface. If the source interface is not known, determine the boot route before continuing with the peering checks.

  2. Find the instance that owns the IP address in the timed-out URL:

    nico-admin-cli instance show | grep -F '<pxe-server-ip>'
  3. Show that instance. In the INTERFACES section, find the ADDRESSES row containing the timed-out IP address and record that row’s VPC ID:

    nico-admin-cli instance show <pxe-server-instance-id>

Check VPC Peering

If the VPC IDs differ, list the peerings for each VPC:

nico-admin-cli vpc-peering show --vpc-id <tenant-vpc-id>
nico-admin-cli vpc-peering show --vpc-id <pxe-server-vpc-id>
  • If no peering connects the two VPCs, place both instances in one VPC or configure peering. Refer to VPC Peering.
  • If the VPCs are already peered, or the instances use the same VPC, continue with path and policy checks.

Check the Network Path

  1. From an instance in the tenant VPC, test the PXE server IP and port.
  2. Verify routes in both directions between the tenant and PXE server interfaces.
  3. Check network security groups and host firewalls for the protocol and port in the failed URL. Refer to Network Security Groups.
  4. Verify that the HTTP service is listening on the PXE server and bound to the expected address.

Verify Recovery

  1. Confirm that the two instances are in the same VPC or connected by an active VPC peering.
  2. Retry the instance boot.
  3. Confirm that the console downloads the boot image without an iPXE timeout and that the managed host boots the tenant operating system.

The iPXE error reference describes the timeout status reported by the boot client.