ec2 private subnet can't reach 169.254.169.254 when os is windows server 2019

Viewed 1428

i've got multiple ec2 instances running in a private subnet (only traffic within the vpc is allowed). some of those instances are custom OS, some of those instances run AWS windows server 2012 ami, and some run AWS windows server 2019 ami.

on all machines, except the windows server 2019 - i can retrieve the meta data of the instance by calling "http://169.254.169.254/latest/meta-data". on windows server 2019 - it fails. firewall is down, same route table for all machines, and mostly the only diff between them is that the working instances run EC2Config, and the windows server 2019 run EC2Launch (of course, the OSes are different too).

any idea what can cause this behavior?

thanks!!

2 Answers

Well, i'm not sure why it happend only on some of my instances, but on this forum i've found this script - and running it solved my issue.

in order to be able to run this file all the times (also on instances that the metadata link works), i've added this code at the start of the script - which will stop the script in case the metadata link works:

$httpReq = [System.Net.WebRequest]::Create('http://169.254.169.254/latest/meta-data')
$httpRes = $httpReq.GetResponse()
$httpStts= [int]$httpRes.StatusCode

if ($httpStts -eq 200) {
    Write-Host "No need for script - exiting"

    if($httpRes -ne $null) {
        $httpRes.Close()
    }

    exit
}
# rest of the script goes here

thought to post my solution here so if anyway had my problem, it will help him.

thanks all for the help.

This recently happened to the Windows Server 2019 machine that I have on AWS. From my limited understanding, there were faulty rules in the routing tables as shown by ROUTE PRINT which for me had the following lines:

Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0      172.31.48.1    172.31.51.191     15
  169.254.169.254  255.255.255.255       172.31.0.1    172.31.51.191     30
Persistent Routes:
  Network Address          Netmask  Gateway Address  Metric
  169.254.169.254  255.255.255.255       172.31.0.1      15

This means all traffic is routed thru the correct 172.31.48.1 gateway EXCEPT for 169.254.169.254 which gets routed to a black hole. So, a remedy is needed to override the faulty route. One suggestion is to create a new routing rule for 169.254.169.254. By setting the metric to 10 means this new route will have a higher priority over the faulty routes and will be used instead.

C:\Windows\system32>route add 169.254.169.254 mask 255.255.255.255 172.31.48.1 metric 10
 OK!
Related