TroubleshootingConnection problems
Fix SSH connection problems: refused, timed out, denied
Solve the common SSH errors: Connection refused, Connection timed out, Permission denied (publickey), host key changed and Too many authentication failures.
- Beginner
- 12 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13, Windows 11, macOS Tahoe 26
This guide is not available in your language yet, so it is shown in English.
On this page
- Before you start
- Quick test: is the port reachable?
- ssh: connect to host … port 22: Connection timed out
- ssh: connect to host … port 22: Connection refused
- Permission denied (publickey)
- Permission denied, please try again.
- WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!
- Received disconnect … Too many authentication failures
- kex_exchange_identification: read: Connection reset by peer
- WARNING: UNPROTECTED PRIVATE KEY FILE!
- When to open a ticket
- Next steps
SSH errors look alike, but each one points to a different layer: the network path, the SSH service on the server or the login itself. Find the message you see, run the checks and apply the fix. In the examples, replace 203.0.113.10 with your server's address and alex with your user.
Before you start
- Make sure the server is running: check Services › My Services for its status and Support › Network Status for known incidents.
- Have a second way in ready, in case you need to fix something on the server: the web console if your service page shows one, or IPMI where your dedicated plan includes it.
- Get a detailed log of the attempt; most answers are in it:
ssh -vvv alex@203.0.113.10Quick test: is the port reachable?
Linux and macOS
nc -vz 203.0.113.10 22Windows
Test-NetConnection 203.0.113.10 -Port 22Succeeded / open means the network path and the SSH service are fine; look at the login errors below. Refused points to the SSH service. Timed out points to the network or a firewall.
ssh: connect to host … port 22: Connection timed out
No answer arrives. Causes, from most to least likely:
- Wrong address or port. Compare with Primary IP on the service page. If you moved SSH to another port, connect with
ssh -p 2222 [email protected]. - A firewall drops the traffic. On the server (ufw, nftables), at your office, or on your network. Try another network, such as a mobile hotspot. If it works there, your own network blocks outgoing SSH.
- The server is down or booting. Check its status in the client area; open the web console if your service page shows one.
If you changed the firewall recently, see locked out after a firewall change.
ssh: connect to host … port 22: Connection refused
The server answered, but nothing listens on port 22. From the web console, check the service:
sudo systemctl status ssh
sudo ss -tlnp | grep -i ssh
sudo sshd -t- If the service is stopped, start it with
sudo systemctl start ssh.sudo sshd -tprints configuration errors that stop it from starting. - If it listens on another port, connect to that port.
- Ubuntu: SSH is started by
ssh.socket. After changingPort, runsudo systemctl daemon-reloadandsudo systemctl restart ssh.socket, otherwise the old port stays active.
On RHEL-family systems the service is called sshd.
Permission denied (publickey)
The server only accepts keys, and none of the keys your client offered is in the user's authorized_keys.
- Check that you use the right user:
rootandalexhave separate key files. - Point the client at the right key:
ssh -i ~/.ssh/id_ed25519 [email protected]. - On the server, check owner and permissions; SSH ignores files that others can write:
ls -ld ~/.ssh
ls -l ~/.ssh/authorized_keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys- Read the reason in the server log:
sudo journalctl -u ssh --since "10 minutes ago".
See SSH keys to add a key.
Permission denied, please try again.
Password logins are allowed, but the user name or password is wrong. Passwords are case-sensitive and nothing appears while you type. If root logins are disabled (PermitRootLogin no), log in as your own user. After several failures your IP address may be banned by Fail2ban or CrowdSec; see below.
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!
The server presents a different host key than the one your computer stored. This is expected after a reinstall or when an IP address is reused for a new server. If you did not reinstall, treat it as a warning and ask us before you continue. To accept the new key after a reinstall:
ssh-keygen -R 203.0.113.10Received disconnect … Too many authentication failures
Your SSH agent offered several keys and the server stopped after the limit (MaxAuthTries). Offer only the right key:
ssh -o IdentitiesOnly=yes -i ~/.ssh/id_ed25519 alex@203.0.113.10Make it permanent with IdentitiesOnly yes and IdentityFile in ~/.ssh/config.
kex_exchange_identification: read: Connection reset by peer
The connection was cut before the SSH handshake. Common causes: your IP address is banned by Fail2ban or CrowdSec, MaxStartups is exceeded during a scan, or a firewall resets the connection. Check from the web console:
sudo fail2ban-client status sshd
sudo fail2ban-client set sshd unbanip 198.51.100.7Replace 198.51.100.7 with your own public IP address. With CrowdSec, list decisions with sudo cscli decisions list and remove yours with sudo cscli decisions delete --ip 198.51.100.7.
WARNING: UNPROTECTED PRIVATE KEY FILE!
Your private key can be read by other users on your computer, so the client refuses to use it.
Linux and macOS
chmod 600 ~/.ssh/id_ed25519Windows
icacls $env:USERPROFILE\.ssh\id_ed25519 /inheritance:r /grant:r "$($env:USERNAME):(R)"When to open a ticket
Open a ticket if the port is closed from every network and the web console does not work either, or if the server does not respond at all. Choose the server under Related Service and include:
- the output of
ssh -vvv(remove nothing but your passwords), - an
mtr -rwc 50 203.0.113.10orpathping 203.0.113.10from your computer, - what changed before the problem started.
Next steps
- Prevent lockouts: SSH hardening and Fail2ban and CrowdSec.
- Nothing responds at all? Server unreachable.
Frequently asked questions
What is the difference between refused and timed out?
Refused means the server answered but nothing listens on that port, so the SSH service is stopped or on another port. Timed out means no answer came back at all: a firewall drops the packets, the server is down or the address is wrong.
How do I see why SSH fails?
Connect with ssh -vvv and read the last lines before the error. On the server, the SSH service log shows why a login was rejected: journalctl -u ssh on Ubuntu and Debian.
I changed the SSH port and now I cannot connect. What now?
Connect with the new port using ssh -p, and make sure the firewall allows it. On Ubuntu, a port change also needs systemctl daemon-reload and a restart of ssh.socket. If you are locked out, use the web console if your service page shows one.
Could my IP address be banned?
Yes, if the server runs Fail2ban or CrowdSec and you failed to log in several times. Connect from another network, or ask someone with access to unban your address.
When should I open a ticket?
When the port is closed from every network you try and the web console also fails, or when the server does not respond to anything. Include the output of ssh -vvv and an mtr or pathping to the server.