> This page is for NVIDIA Infra Controller.

> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.nvidia.com/infra-controller/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.nvidia.com/infra-controller/_mcp/server.

# Troubleshoot an Instance Boot Connection Timeout <Badge intent="info">v2.2</Badge> <Badge intent="launch" minimal>New</Badge>

Use this playbook when an assigned machine times out while downloading a tenant
operating-system image from a PXE or HTTP server hosted on another instance.

## Symptoms and Data to Collect

The console shows an iPXE timeout similar to:

```text
http://192.0.2.20:8080/boot/tenant-os... Connection timed out
(https://ipxe.org/4c0a6092)
```

Collect the following before changing the network configuration:

- The failing tenant instance ID.
- The complete URL from the console, including IP address and port.
- The source address and interface that the boot client uses to reach the
  timed-out address, and that interface's VPC ID.
- The PXE server instance ID, the interface that owns the timed-out address,
  and that interface's VPC ID.

If the instances use different VPCs without peering, the boot path is
unreachable. If they use the same VPC or peered VPCs, investigate routing and
tenant-defined security controls.

## Identify Both VPCs

1. Show the failing instance:

   ```bash
   nico-admin-cli instance show <tenant-instance-id>
   ```

   In the `INTERFACES` section, match the source address used by the boot
   client to the corresponding `ADDRESSES` row and record that row's `VPC ID`.
   An instance can have interfaces in multiple VPCs, so do not use a VPC ID
   from another interface. If the source interface is not known, determine the
   boot route before continuing with the peering checks.

1. Find the instance that owns the IP address in the timed-out URL:

   ```bash
   nico-admin-cli instance show | grep -F '<pxe-server-ip>'
   ```

1. Show that instance. In the `INTERFACES` section, find the `ADDRESSES` row
   containing the timed-out IP address and record that row's `VPC ID`:

   ```bash
   nico-admin-cli instance show <pxe-server-instance-id>
   ```

## Check VPC Peering

If the VPC IDs differ, list the peerings for each VPC:

```bash
nico-admin-cli vpc-peering show --vpc-id <tenant-vpc-id>
nico-admin-cli vpc-peering show --vpc-id <pxe-server-vpc-id>
```

- If no peering connects the two VPCs, place both instances in one VPC or
  configure peering. Refer to
  [VPC Peering](/infra-controller/documentation/operations-day-2/managing-vp-cs/vpc-peering).
- If the VPCs are already peered, or the instances use the same VPC, continue
  with path and policy checks.

## Check the Network Path

1. From an instance in the tenant VPC, test the PXE server IP and port.
1. Verify routes in both directions between the tenant and PXE server
   interfaces.
1. Check network security groups and host firewalls for the protocol and port
   in the failed URL. Refer to
   [Network Security Groups](/infra-controller/documentation/operations-day-2/network-security-groups).
1. Verify that the HTTP service is listening on the PXE server and bound to the
   expected address.

## Verify Recovery

1. Confirm that the two instances are in the same VPC or connected by an active
   VPC peering.
1. Retry the instance boot.
1. Confirm that the console downloads the boot image without an iPXE timeout
   and that the managed host boots the tenant operating system.

The [iPXE error reference](https://ipxe.org/4c0a6092) describes the timeout
status reported by the boot client.