Unable to connect primary endpoint elasticache "Redis" from instance in public subnet of same VPC

Viewed 382

I have AWS elasticache redis setup in private subnet and ec2 instance in public subnet but both have same VPC. However I can't connect with primary endpoint but when I try to connect with readers end point it worked perfectly fine.I am able to telnet reader endpoint from ec2 instance(in public subnet) but can't telnet primary endpoint(in public subnet) .But primary endpoint is accessible and can be successfully connected/telnet from another instance in private subnet.

I have create vpc log flow and notice two things that for reader endpoint I got two rows

2 476153202769 eni-0fb5c5a5352855253 10.0.5.68 10.0.3.140 51108 6379 6 1 52 1642787913 1642787913 ACCEPT OK

2 476153202769 eni-0fb5c5a5352855253 10.0.3.140 10.0.5.68 6379 51108 6 1 52 1642787913 1642787913 ACCEPT OK

but for primary endpoint got only one row

2 476153202769 eni-00d35f69760d0c75c 10.0.5.68 10.0.3.123 44292 6379 6 5 300 1642787951 1642787952 ACCEPT OK

10.0.5.68 is my ec2 pvt address

10.0.3.123 primary endpoint

10.0.3.140 reader endpoint

1 Answers

I believe when you launched your ElasticCache Cluster you attached the default security group. The default security group doesn’t have any authorizations to the cluster endpoint. You need to configure it explicitly to authorize the security group to allow traffic from your EC2 instance.

please refer below link.

screenshot from aws :)

enter image description here

Related