YUM update error EC2 Could not retrieve mirrorlist https...

0

Wherenever I run Sudo YUM update on an new EC2 intance I get this error:

Could not retrieve mirrorlist https://amazonlinux-2-repos-us-west-2.s3.dualstack.us-west-2.amazonaws.com/2/core/latest/x86_64/mirror.list error was
12: Timeout on https://amazonlinux-2-repos-us-west-2.s3.dualstack.us-west-2.amazonaws.com/2/core/latest/x86_64/mirror.list: (28, 'Failed to connect to amazonlinux-2-repos-us-west-2.s3.dualstack.us-west-2.amazonaws.com port 443 after 4982 ms: Connection timed out')```

Here are the things I've already checked:

1. NACL and Security Groups already have inbound Port 80 and port 443 open
2. Outbound NACL and Security Groups is already Open to all TCP
3. Internet Gateway correctly attached
4. Have given this EC2 a Public, elastic IP, and that still didn't work.

Not sure what else I'm missing?
已提问 1 年前1881 查看次数
2 回答
1
已接受的回答

Your inbound NACL is wrong. it dont need inbound 80,443.

It needs inbound ephemeral ports open range 32768-65535 https://docs.aws.amazon.com/vpc/latest/userguide/vpc-network-acls.html

If issue persist, you can use VPC Reachability analyzer to find out where traffic is getting blocked. https://aws.amazon.com/blogs/aws/new-vpc-insights-analyzes-reachability-and-visibility-in-vpcs/

Accept answer if it helps resolving the issue

已回答 1 年前
profile pictureAWS
专家
已审核 1 年前
  • This did it. Thank you. I had to give the s3 Bucket end point full access, rather than some more restricted access to get Yum to update... but it's working now. Thanks for the reply!

1

The instance needs to be in a public subnet where the route table attached to the subnet has a rule routing traffic to the internet gateway. Or in a private subnet where the route table attached to the subnet has a rule routing traffic to a NAT Gateway/Instance.

profile pictureAWS
专家
kentrad
已回答 1 年前
  • The Subnet's Routable has 0.0.0.0/0 Rule to the My Internet Gateway. I double checked my Launch template to ensure that this Route Table is associated with the Subnet that the EC2 instance is attached to when it is created.

您未登录。 登录 发布回答。

一个好的回答可以清楚地解答问题和提供建设性反馈,并能促进提问者的职业发展。

回答问题的准则