Use this guide to diagnose and fix ping failures from an SAG-1000 device to an Elastic Compute Service (ECS) instance.
Symptoms
A local terminal cannot reach Alibaba Cloud. Pinging an ECS instance from an SAG device fails, even though the SAG device and the ECS instance are associated with the same Cloud Enterprise Network (CEN) instance.
Causes
The failure can stem from any of the following:
The connection between the local terminal and the SAG-1000 device is faulty.
The VPN tunnel between the SAG-1000 device and Alibaba Cloud is faulty.
The target ECS instance is faulty.
The Internet service provider (ISP) network is faulty.
Solution
Work through the following steps to isolate and fix the cause.
Step 1: Check the SAG instance status
Log on to the Smart Access Gateway (SAG) console.
Click the ID of the target SAG instance and check its status.
Disconnected: The SAG device has lost its connection to Alibaba Cloud. See Handle SAG device disconnections to resolve the issue.
Ready: The SAG instance is connected. Proceed to Step 2.
Step 2: Check the connectivity between the SAG-1000 device and the switch
Log on to the switch console and test connectivity between the SAG-1000 device and the switch.
If static routing is configured on both the SAG-1000 device and the switch:
Ping the IP address of each port on the SAG-1000 device through the switch.
If a port IP address is unreachable, see Handle connection failures between an SAG device and a switch to resolve port interconnection issues.
If all port IP addresses are reachable, proceed to Step 3.
If the SAG device is used without a switch:
Check the second and third indicators on the right side of the SAG-1000 device.
| Indicator state | Meaning | Action |
|---|---|---|
| Second indicator is yellow or continuously blinking | The SAG device is faulty | Submit a ticket. |
| Third indicator is yellow or continuously blinking | The VPN tunnel between the SAG device and Alibaba Cloud is unavailable | Submit a ticket. |
| Both indicators are green | The SAG device and VPN tunnel are operating normally | Proceed to Step 3 |
For a full reference of indicator colors and states, see View device indicators.
Step 3: Check the target ECS instance
Verify that the ECS instance itself is reachable by testing connectivity to a different instance:
Ping an ECS instance deployed in a different Virtual Private Cloud (VPC), or assign an Elastic IP address to the target ECS instance and ping it from the internet.
If the alternate instance responds but the target does not, the target ECS instance is faulty. Handle the faults of the current ECS instance.
If no ECS instance responds, proceed to Step 4.
Step 4: Check the ISP network
Ping other public websites through the current ISP network. If you cannot ping other public websites, check whether the ISP network is functioning.