Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mlinko
Contributor

Amazon AWS Connection not working

Dear all,

we have a following phenomen, if we try to access the following link:

s3-infra-prod-tf-management-euc1.s3.amazonaws.com

every second or third call to the web link (it works if we execute outside of the company) - also curls are "rejected" please see below:

curl -v --resolve s3-infra-prod-tf-management-euc1.s3.amazonaws.com:443:3.5.137.83 https://s3-infra-prod-tf-management-euc1.s3.amazonaws.com
* Added s3-infra-prod-tf-management-euc1.s3.amazonaws.com:443:3.5.137.83 to DNS cache
* Hostname s3-infra-prod-tf-management-euc1.s3.amazonaws.com was found in DNS cache
* Trying 3.5.137.83:443...
* Connected to s3-infra-prod-tf-management-euc1.s3.amazonaws.com (3.5.137.83) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* CAfile: /etc/pki/tls/certs/ca-bundle.crt
* TLSv1.0 (OUT), TLS header, Certificate Status (22):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
* TLSv1.2 (IN), TLS header, Certificate Status (22):
* TLSv1.3 (IN), TLS handshake, Server hello (2):
* TLSv1.2 (IN), TLS header, Finished (20):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Certificate (11):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, CERT verify (15):
* TLSv1.2 (IN), TLS header, Unknown (23):
* TLSv1.3 (IN), TLS handshake, Finished (20):
* TLSv1.2 (OUT), TLS header, Finished (20):
* TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
* TLSv1.2 (OUT), TLS header, Unknown (23):
* TLSv1.3 (OUT), TLS handshake, Finished (20):
* SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256
* ALPN, server accepted to use http/1.1
* Server certificate:
* subject: CN=*.s3.eu-central-1.amazonaws.com
* start date: Sep 16 00:00:00 2025 GMT
* expire date: Sep 9 23:59:59 2026 GMT
* subjectAltName: host "s3-infra-prod-tf-management-euc1.s3.amazonaws.com" matched cert's "*.s3.amazonaws.com"
* issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M04
* SSL certificate verify ok.
* TLSv1.2 (OUT), TLS header, Unknown (23):
> GET / HTTP/1.1
> Host: s3-infra-prod-tf-management-euc1.s3.amazonaws.com
> User-Agent: curl/7.76.1
> Accept: */*
>
* TLSv1.2 (IN), TLS header, Unknown (23):
* Mark bundle as not supporting multiuse
< HTTP/1.1 403 Forbidden
< x-amz-bucket-region: eu-central-1
< x-amz-request-id: QQXNH0G5QDRSSFG4
< x-amz-id-2: a4NAoL5Uo03NN19kira6jX0mwroqL8tMUWknztkjPPuicBkaq+ZHRwzGb/FknlBZ1qlbB8M6BC/v6PA3IQ1ua2Oq6t+0tcH1
< Content-Type: application/xml
< Transfer-Encoding: chunked
< Date: Wed, 12 Aug 2026 10:05:08 GMT
< Server: AmazonS3
<
* TLSv1.2 (IN), TLS header, Unknown (23):
<?xml version="1.0" encoding="UTF-8"?>
* Connection #0 to host s3-infra-prod-tf-management-euc1.s3.amazonaws.com left intact
<Error><Code>AccessDenied</Code><Message>Access Denied</Message><RequestId>QQXNH0G5QDRSSFG4</RequestId><HostId>a4NAoL5Uo03NN19kira6jX0mwroqL8tMUWknztkjPPuicBkaq+ZHRwzGb/FknlBZ1qlbB8M6BC/v6PA3IQ1ua2Oq6t+0tcH1</HostId></Error>


curl -v --resolve s3-infra-prod-tf-management-euc1.s3.amazonaws.com:443:3.5.137.83 https://s3-infra-prod-tf-management-euc1.s3.amazonaws.com
* Added s3-infra-prod-tf-management-euc1.s3.amazonaws.com:443:3.5.137.83 to DNS cache
* Hostname s3-infra-prod-tf-management-euc1.s3.amazonaws.com was found in DNS cache
* Trying 3.5.137.83:443...
* Connected to s3-infra-prod-tf-management-euc1.s3.amazonaws.com (3.5.137.83) port 443 (#0)
* ALPN, offering h2
* ALPN, offering http/1.1
* CAfile: /etc/pki/tls/certs/ca-bundle.crt
* TLSv1.0 (OUT), TLS header, Certificate Status (22):
* TLSv1.3 (OUT), TLS handshake, Client hello (1):
^C

------------------END of the communication---------------------

Tcpdump shows the following - check the attached print screen.

 

We have tried the curl from different firewalls or devices in the same network. I know that it is hard to "debug" on only the text, but maybe someone had a similar issue and found a solution.

Thank you!

KR
Rok

Screenshot 2026-08-12 130606.png

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

From the curl output, it looks like the remote end is issuing a 403 message, implying there is connectivity, but the remote server is rejecting.
The "Access Denied" in the output is also a clear sign this is the case. 

Where are you executing the curl and tcpdump from relative to the gateway?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events