Skip to content

TroubleshootingConnection problems

Fix SSH connection problems: refused, timed out, denied

Solve the common SSH errors: Connection refused, Connection timed out, Permission denied (publickey), host key changed and Too many authentication failures.

  • Beginner
  • 12 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows 11, macOS Tahoe 26

On this page
  1. Before you start
  2. Quick test: is the port reachable?
  3. ssh: connect to host … port 22: Connection timed out
  4. ssh: connect to host … port 22: Connection refused
  5. Permission denied (publickey)
  6. Permission denied, please try again.
  7. WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!
  8. Received disconnect … Too many authentication failures
  9. kex_exchange_identification: read: Connection reset by peer
  10. WARNING: UNPROTECTED PRIVATE KEY FILE!
  11. When to open a ticket
  12. Next steps

SSH errors look alike, but each one points to a different layer: the network path, the SSH service on the server or the login itself. Find the message you see, run the checks and apply the fix. In the examples, replace 203.0.113.10 with your server's address and alex with your user.

Before you start

  • Make sure the server is running: check Services › My Services for its status and Support › Network Status for known incidents.
  • Have a second way in ready, in case you need to fix something on the server: the web console if your service page shows one, or IPMI where your dedicated plan includes it.
  • Get a detailed log of the attempt; most answers are in it:
Bash
ssh -vvv alex@203.0.113.10

Quick test: is the port reachable?

Linux and macOS

Bash
nc -vz 203.0.113.10 22

Windows

PowerShell
Test-NetConnection 203.0.113.10 -Port 22

Succeeded / open means the network path and the SSH service are fine; look at the login errors below. Refused points to the SSH service. Timed out points to the network or a firewall.

ssh: connect to host … port 22: Connection timed out

No answer arrives. Causes, from most to least likely:

  1. Wrong address or port. Compare with Primary IP on the service page. If you moved SSH to another port, connect with ssh -p 2222 [email protected].
  2. A firewall drops the traffic. On the server (ufw, nftables), at your office, or on your network. Try another network, such as a mobile hotspot. If it works there, your own network blocks outgoing SSH.
  3. The server is down or booting. Check its status in the client area; open the web console if your service page shows one.

If you changed the firewall recently, see locked out after a firewall change.

ssh: connect to host … port 22: Connection refused

The server answered, but nothing listens on port 22. From the web console, check the service:

Bash
sudo systemctl status ssh
sudo ss -tlnp | grep -i ssh
sudo sshd -t
  • If the service is stopped, start it with sudo systemctl start ssh. sudo sshd -t prints configuration errors that stop it from starting.
  • If it listens on another port, connect to that port.
  • Ubuntu: SSH is started by ssh.socket. After changing Port, run sudo systemctl daemon-reload and sudo systemctl restart ssh.socket, otherwise the old port stays active.

On RHEL-family systems the service is called sshd.

Permission denied (publickey)

The server only accepts keys, and none of the keys your client offered is in the user's authorized_keys.

  • Check that you use the right user: root and alex have separate key files.
  • Point the client at the right key: ssh -i ~/.ssh/id_ed25519 [email protected].
  • On the server, check owner and permissions; SSH ignores files that others can write:
Bash
ls -ld ~/.ssh
ls -l ~/.ssh/authorized_keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
  • Read the reason in the server log: sudo journalctl -u ssh --since "10 minutes ago".

See SSH keys to add a key.

Permission denied, please try again.

Password logins are allowed, but the user name or password is wrong. Passwords are case-sensitive and nothing appears while you type. If root logins are disabled (PermitRootLogin no), log in as your own user. After several failures your IP address may be banned by Fail2ban or CrowdSec; see below.

WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!

The server presents a different host key than the one your computer stored. This is expected after a reinstall or when an IP address is reused for a new server. If you did not reinstall, treat it as a warning and ask us before you continue. To accept the new key after a reinstall:

Bash
ssh-keygen -R 203.0.113.10

Received disconnect … Too many authentication failures

Your SSH agent offered several keys and the server stopped after the limit (MaxAuthTries). Offer only the right key:

Bash
ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 alex@203.0.113.10

Make it permanent with IdentitiesOnly yes and IdentityFile in ~/.ssh/config.

kex_exchange_identification: read: Connection reset by peer

The connection was cut before the SSH handshake. Common causes: your IP address is banned by Fail2ban or CrowdSec, MaxStartups is exceeded during a scan, or a firewall resets the connection. Check from the web console:

Bash
sudo fail2ban-client status sshd
sudo fail2ban-client set sshd unbanip 198.51.100.7

Replace 198.51.100.7 with your own public IP address. With CrowdSec, list decisions with sudo cscli decisions list and remove yours with sudo cscli decisions delete --ip 198.51.100.7.

WARNING: UNPROTECTED PRIVATE KEY FILE!

Your private key can be read by other users on your computer, so the client refuses to use it.

Linux and macOS

Bash
chmod 600 ~/.ssh/id_ed25519

Windows

PowerShell
icacls $env:USERPROFILE\.ssh\id_ed25519 /inheritance:r /grant:r "$($env:USERNAME):(R)"

When to open a ticket

Open a ticket if the port is closed from every network and the web console does not work either, or if the server does not respond at all. Choose the server under Related Service and include:

  • the output of ssh -vvv (remove nothing but your passwords),
  • an mtr -rwc 50 203.0.113.10 or pathping 203.0.113.10 from your computer,
  • what changed before the problem started.

Next steps

Frequently asked questions

What is the difference between refused and timed out?

Refused means the server answered but nothing listens on that port, so the SSH service is stopped or on another port. Timed out means no answer came back at all: a firewall drops the packets, the server is down or the address is wrong.

How do I see why SSH fails?

Connect with ssh -vvv and read the last lines before the error. On the server, the SSH service log shows why a login was rejected: journalctl -u ssh on Ubuntu and Debian.

I changed the SSH port and now I cannot connect. What now?

Connect with the new port using ssh -p, and make sure the firewall allows it. On Ubuntu, a port change also needs systemctl daemon-reload and a restart of ssh.socket. If you are locked out, use the web console if your service page shows one.

Could my IP address be banned?

Yes, if the server runs Fail2ban or CrowdSec and you failed to log in several times. Connect from another network, or ask someone with access to unban your address.

When should I open a ticket?

When the port is closed from every network you try and the web console also fails, or when the server does not respond to anything. Include the output of ssh -vvv and an mtr or pathping to the server.

Generate Password

Please confirm