How VPC Reachability Analyzer works - Amazon Virtual Private Cloud

How VPC Reachability Analyzer works

VPC Reachability Analyzer analyzes the path between a source and destination by building a model of the network configuration, and then checking for reachability based on the configuration. It does not send packets or analyze the data plane.

To use Reachability Analyzer, you specify the path for the traffic from a source to a destination. For example, you could specify an internet gateway as the source, an EC2 instance as the destination, 22 as the destination port, and TCP as the protocol. This would allow you to verify that you can connect to the EC2 instance through the internet gateway using SSH.

If there are multiple reachable paths between a source and a destination, Reachability Analyzer identifies and displays the shortest path. You can analyze the path again, specifying an intermediate component, to find an alternative reachable path that traverses the intermediate component.

If the path is not reachable, Reachability Analyzer displays information about the component or combination of components that is blocking the path. There might be additional components blocking the path.

Source and destination resources

The following resources types are supported as sources and destinations:

  • Instances

  • Internet gateways

  • Network interfaces

  • Transit gateways

  • VPC endpoints

  • VPC peering connections

  • VPN gateways

Intermediate components

The following resource types are supported as intermediate components:

  • Load balancers (except for Gateway Load Balancers)

  • NAT gateways

  • VPC peering connections

Path components

The following resource types can appear in reachable paths and in explanations when a path is not reachable:

  • EC2 instances

  • Internet gateways

  • Load balancers (except for Gateway Load Balancers)

  • NAT gateways

  • Network ACLs

  • Network interfaces

  • Prefix lists

  • Route tables

  • Security groups

  • Subnets

  • Target groups

  • Virtual private gateways

  • VPC endpoints

  • VPC gateway endpoints

  • VPC peering connections

  • VPCs

  • VPN connections

Limitations

  • Reachability Analyzer does not support more specific routing. If a path analysis includes a route that is more specific than the VPC local route, the analysis fails.

Resources

Use the following documentation to help you update your network configuration.