Mendiagnosis masalah menggunakan pemecah masalah Kontrol Layanan VPC
Tetap teratur dengan koleksi
Simpan dan kategorikan konten berdasarkan preferensi Anda.
Halaman ini menjelaskan cara menggunakan pemecah masalah Kontrol Layanan VPC untuk memahami dan mendiagnosis masalah yang dicatat oleh log Kontrol Layanan VPC.
Log Kontrol Layanan VPC menyertakan detail tentang permintaan ke resource yang dilindungi dan
alasan Kontrol Layanan VPC menolak permintaan tersebut. Namun, detail ini tidak selalu
mudah terlihat dan Anda mungkin menghabiskan banyak waktu untuk memahami log.
Anda dapat menggunakan pemecah masalah Kontrol Layanan VPC untuk mendiagnosis penolakan
dari perimeter layanan. Untuk mengetahui informasi tentang alasan pelanggaran, lihat Permintaan proses debug yang diblokir oleh Kontrol Layanan VPC.
Anda juga dapat menggunakan pemecah masalah untuk mendiagnosis penolakan dari perimeter layanan
yang menggunakan konfigurasi uji coba.
Sebelum memulai
Untuk memecahkan masalah pelanggaran Kontrol Layanan VPC, pastikan Anda memiliki peran IAM VPC Service Controls Troubleshooter Viewer (roles/accesscontextmanager.vpcScTroubleshooterViewer) di tingkat organisasi. Peran ini tidak
memungkinkan Anda mengubah perimeter atau tingkat akses.
Mengakses pemecah masalah Kontrol Layanan VPC
Pemecah masalah hanya tersedia di konsol Google Cloud .
Anda dapat mengakses pemecah masalah menggunakan Logs Explorer atau halaman Kontrol Layanan VPC.
Menggunakan Logs Explorer
Dengan menggunakan Logs Explorer, Anda dapat berpindah langsung dari entri log untuk penolakan Kontrol Layanan VPC ke pemecah masalah.
Untuk mengakses pemecah masalah dari entri log, lakukan hal berikut:
Buka halaman Logs Explorer di konsol Google Cloud .
[[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-08-18 UTC."],[],[],null,["# Diagnose issues by using the VPC Service Controls troubleshooter\n\nThis page describes how you can use the VPC Service Controls troubleshooter to\nunderstand and diagnose issues that VPC Service Controls logs.\n\nVPC Service Controls logs include details about requests to protected resources and\nthe reason why VPC Service Controls denied the request. However, these details aren't\nalways easily apparent and you might spend considerable time understanding the logs.\nYou can use the VPC Service Controls troubleshooter to diagnose denials\nfrom a service perimeter. For information on violation reasons, see [Debugging requests blocked by VPC Service Controls](/vpc-service-controls/docs/troubleshooting#debugging).\n\nYou can also use the troubleshooter to diagnose denials from a service perimeter\nthat uses a dry-run configuration.\n\nBefore you begin\n----------------\n\nTo troubleshoot a VPC Service Controls violation, make sure that you have\nthe VPC Service Controls Troubleshooter Viewer IAM role\n(`roles/accesscontextmanager.vpcScTroubleshooterViewer`) at the organization level. This role doesn't\nlet you modify perimeters or access levels.\n\nAccessing the VPC Service Controls troubleshooter\n-------------------------------------------------\n\nThe troubleshooter is available only in the Google Cloud console.\nYou can access the troubleshooter using either the [Logs Explorer](/logging/docs/view/logs-explorer-summary)\nor the VPC Service Controls page.\n\n### Using the Logs Explorer\n\nBy using the [Logs Explorer](/logging/docs/view/logs-explorer-summary), you can move directly from a\nlog entry for a VPC Service Controls denial to the troubleshooter.\n\nTo access the troubleshooter from a log entry, do the following:\n\n1. Go to the **Logs Explorer** page in the Google Cloud console.\n\n [Go to Logs Explorer](https://console.cloud.google.com/logs/query)\n2. In the Logs Explorer, use the denial's [unique ID to access the log\n entry](/vpc-service-controls/docs/retrieve-troubleshoot-errors#unique-id).\n\n3. In the **Query Results** box, in the row for the denial that you want to\n troubleshoot, click **VPC Service Controls** , and then click **Troubleshoot\n denial**.\n\n### Using the VPC Service Controls page\n\nFrom the **VPC Service Controls** page, you can troubleshoot a denial using\nits unique ID.\n\nBefore you begin, [obtain the unique ID](/vpc-service-controls/docs/retrieve-troubleshoot-errors#unique-id) for the denial that you want\nto troubleshoot.\n\nTo access the troubleshooter from the **VPC Service Controls**\npage, do the following:\n\n1. In the Google Cloud console navigation menu, click **Security** , and then\n click **VPC Service Controls**.\n\n [Go to VPC Service Controls](https://console.cloud.google.com/security/service-perimeter)\n2. If you are prompted, select your organization. You can access the **VPC Service Controls**\n page only at the organization level.\n\n3. On the **VPC Service Controls** page, click **Troubleshoot**.\n\n4. On the **VPC Service Controls Troubleshooter** page, in the\n **Unique identifier** box, enter the unique ID for the denial that you want\n to troubleshoot.\n\n5. Click **Troubleshoot**.\n\nWhat's next\n-----------\n\n- [Understanding VPC Service Controls audit logs](/vpc-service-controls/docs/audit-logging)\n- Learn how [VPC Service Controls unique identifier helps troubleshoot\n issues related to service perimeters](https://cloud.google.com/blog/products/identity-security/unique-identifier-helps-troubleshooting-vpc-service-controls-perimeter).\n- [Diagnose an access denial event using the VPC Service Controls violation\n analyzer](/vpc-service-controls/docs/violation-analyzer) ([Preview](/products#product-launch-stages))."]]