I want to troubleshoot network connectivity issues between Amazon Virtual Private Cloud (Amazon VPC) resources in different AWS accounts.
Resolution
To troubleshoot network connectivity issues between Amazon VPC resources that are in different accounts, use Reachability Analyzer.
Reachability Analyzer checks for misconfigurations in the following components:
- Security groups
- Network access control lists (network ACLs)
- Route tables
Configure organizational access for Reachability Analyzer
Complete the following steps:
- Open the AWS Network Manager console.
Note: Make sure that you use your AWS Organizations account.
- In the navigation pane, under Monitoring and troubleshooting, under Reachability Analyzer, choose Settings.
- To allow Reachability Analyzer to operate across all accounts in your organization, for the Trusted Access setting, choose Turn on trusted access.
- In the IAM role deployments status section, confirm that the Console role status for each member account shows Succeeded.
Note: Deployment might take several minutes. Refresh until all accounts succeed.
- In the Delegated administrators section, choose Register delegated administrator.
- Select the account that you want to register, and then choose Register delegated administrator.
Note: The delegated administrator account has permissions to perform Reachability Analyzer operations across accounts.
Create and analyze a cross-account path
To define paths and run analyses from sources and destinations from any account in your organization, use the AWS management account for your organization. To define paths and run analyses from sources and destinations from any account in your organization other than the management account, use the delegated administrator account.
To analyze network connectivity between two Amazon Elastic Compute Cloud (Amazon EC2) instances in different accounts through a transit gateway, create and analyze the path. For Source Type and Destination Type, choose Instances.
After the path analysis completes, review the results. The analysis shows whether the source can reach the destination based on your network configurations.
If the path is unreachable, then Reachability Analyzer provides detailed reasons and explanation codes to help you identify and remediate network configurations or permissions issues.
Related information
Visualize and diagnose network reachability across AWS accounts using Reachability Analyzer
How do I use Amazon VPC Reachability Analyzer to troubleshoot connectivity issues with an Amazon VPC resource?
Cross-account analyses for Reachability Analyzer