# Fix SSH connection problems: refused, timed out, denied

> Solve the common SSH errors: Connection refused, Connection timed out, Permission denied (publickey), host key changed and Too many authentication failures.

Difficulty: Beginner\
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows 11, macOS Tahoe 26

SSH errors look alike, but each one points to a different layer: the network path, the SSH service on the server or the login itself. Find the message you see, run the checks and apply the fix. In the examples, replace `203.0.113.10` with your server's address and `alex` with your user.

## Before you start

- Make sure the server is running: check **Services › My Services** for its status and **Support › Network Status** for known incidents.
- Have a second way in ready, in case you need to fix something on the server: the web console if your service page shows one, or IPMI where your dedicated plan includes it.
- Get a detailed log of the attempt; most answers are in it:

```bash
ssh -vvv alex@203.0.113.10
```

## Quick test: is the port reachable?

**Linux and macOS**

```bash
nc -vz 203.0.113.10 22
```
**Windows**

```powershell
Test-NetConnection 203.0.113.10 -Port 22
```

**Succeeded / open** means the network path and the SSH service are fine; look at the login errors below. **Refused** points to the SSH service. **Timed out** points to the network or a firewall.

## `ssh: connect to host … port 22: Connection timed out`

No answer arrives. Causes, from most to least likely:

1. **Wrong address or port.** Compare with **Primary IP** on the service page. If you moved SSH to another port, connect with `ssh -p 2222 alex@203.0.113.10`.
2. **A firewall drops the traffic.** On the server (ufw, nftables), at your office, or on your network. Try another network, such as a mobile hotspot. If it works there, your own network blocks outgoing SSH.
3. **The server is down or booting.** Check its status in the client area; open the web console if your service page shows one.

If you changed the firewall recently, see [locked out after a firewall change](/guides/locked-out-after-firewall-change).

## `ssh: connect to host … port 22: Connection refused`

The server answered, but nothing listens on port 22. From the web console, check the service:

```bash
sudo systemctl status ssh
sudo ss -tlnp | grep -i ssh
sudo sshd -t
```

- If the service is stopped, start it with `sudo systemctl start ssh`. `sudo sshd -t` prints configuration errors that stop it from starting.
- If it listens on another port, connect to that port.
- **Ubuntu:** SSH is started by `ssh.socket`. After changing `Port`, run `sudo systemctl daemon-reload` and `sudo systemctl restart ssh.socket`, otherwise the old port stays active.

On RHEL-family systems the service is called `sshd`.

## `Permission denied (publickey)`

The server only accepts keys, and none of the keys your client offered is in the user's `authorized_keys`.

- Check that you use the right user: `root` and `alex` have separate key files.
- Point the client at the right key: `ssh -i ~/.ssh/id_ed25519 alex@203.0.113.10`.
- On the server, check owner and permissions; SSH ignores files that others can write:

```bash
ls -ld ~/.ssh
ls -l ~/.ssh/authorized_keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
```

- Read the reason in the server log: `sudo journalctl -u ssh --since "10 minutes ago"`.

See [SSH keys](/guides/ssh-keys) to add a key.

## `Permission denied, please try again.`

Password logins are allowed, but the user name or password is wrong. Passwords are case-sensitive and nothing appears while you type. If root logins are disabled (`PermitRootLogin no`), log in as your own user. After several failures your IP address may be banned by Fail2ban or CrowdSec; see below.

## `WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!`

The server presents a different host key than the one your computer stored. This is expected after a reinstall or when an IP address is reused for a new server. If you did not reinstall, treat it as a warning and ask us before you continue. To accept the new key after a reinstall:

```bash
ssh-keygen -R 203.0.113.10
```

## `Received disconnect … Too many authentication failures`

Your SSH agent offered several keys and the server stopped after the limit (`MaxAuthTries`). Offer only the right key:

```bash
ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 alex@203.0.113.10
```

Make it permanent with `IdentitiesOnly yes` and `IdentityFile` in `~/.ssh/config`.

## `kex_exchange_identification: read: Connection reset by peer`

The connection was cut before the SSH handshake. Common causes: your IP address is banned by Fail2ban or CrowdSec, `MaxStartups` is exceeded during a scan, or a firewall resets the connection. Check from the web console:

```bash
sudo fail2ban-client status sshd
sudo fail2ban-client set sshd unbanip 198.51.100.7
```

Replace `198.51.100.7` with your own public IP address. With CrowdSec, list decisions with `sudo cscli decisions list` and remove yours with `sudo cscli decisions delete --ip 198.51.100.7`.

## `WARNING: UNPROTECTED PRIVATE KEY FILE!`

Your private key can be read by other users on your computer, so the client refuses to use it.

**Linux and macOS**

```bash
chmod 600 ~/.ssh/id_ed25519
```
**Windows**

```powershell
icacls $env:USERPROFILE\.ssh\id_ed25519 /inheritance:r /grant:r "$($env:USERNAME):(R)"
```

## When to open a ticket

Open a ticket if the port is closed from every network and the web console does not work either, or if the server does not respond at all. Choose the server under **Related Service** and include:

- the output of `ssh -vvv` (remove nothing but your passwords),
- an `mtr -rwc 50 203.0.113.10` or `pathping 203.0.113.10` from your computer,
- what changed before the problem started.

## Next steps

- Prevent lockouts: [SSH hardening](/guides/ssh-hardening) and [Fail2ban and CrowdSec](/guides/fail2ban-crowdsec).
- Nothing responds at all? [Server unreachable](/guides/server-unreachable).

## Frequently asked questions

### What is the difference between refused and timed out?

Refused means the server answered but nothing listens on that port, so the SSH service is stopped or on another port. Timed out means no answer came back at all: a firewall drops the packets, the server is down or the address is wrong.

### How do I see why SSH fails?

Connect with ssh -vvv and read the last lines before the error. On the server, the SSH service log shows why a login was rejected: journalctl -u ssh on Ubuntu and Debian.

### I changed the SSH port and now I cannot connect. What now?

Connect with the new port using ssh -p, and make sure the firewall allows it. On Ubuntu, a port change also needs systemctl daemon-reload and a restart of ssh.socket. If you are locked out, use the web console if your service page shows one.

### Could my IP address be banned?

Yes, if the server runs Fail2ban or CrowdSec and you failed to log in several times. Connect from another network, or ask someone with access to unban your address.

### When should I open a ticket?

When the port is closed from every network you try and the web console also fails, or when the server does not respond to anything. Include the output of ssh -vvv and an mtr or pathping to the server.

---

Source: <https://hyperdc.com/guides/troubleshooting/ssh-connection-problems>\
Updated: 2026-10-09
