安全组配置正确仍无法连接EC2:SSH建立连接后超时求助
EC2 SSH连接建立后卡住超时问题
问题描述
创建了一台EC2实例,使用SSH连接时,提示“debug1: Connection established.”后卡住并超时。已确认可以通过22端口telnet到该实例,说明服务器可达且安全组配置正确,但SSH仍超时。
SSH调试日志
ssh -i "devops.pem" ec2-user@ec2-3-91-100-189.compute-1.amazonaws.com -vvvv OpenSSH_8.6p1, LibreSSL 3.3.6 debug1: Reading configuration data /Users/test/.ssh/config debug1: /Users/test/.ssh/config line 1: Applying options for * debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 21: include /etc/ssh/ssh_config.d/* matched no files debug1: /etc/ssh/ssh_config line 54: Applying options for * debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts' -> '/Users/test/.ssh/known_hosts' debug3: expanded UserKnownHostsFile '~/.ssh/known_hosts2' -> '/Users/test/.ssh/known_hosts2' debug1: Authenticator provider $SSH_SK_PROVIDER did not resolve; disabling debug1: auto-mux: Trying existing master debug1: Control socket "/Users/test/.ssh/master-ec2-user@ec2-3-91-100-189.compute-1.amazonaws.com:22" does not exist debug1: Connecting to ec2-3-91-100-189.compute-1.amazonaws.com port 22. debug1: Connection established. debug1: identity file devops.pem type -1 debug1: identity file devops.pem-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_8.6
可能的原因及解决方法
- 密钥文件权限问题:SSH对密钥文件权限要求严格,权限过宽会被拒绝使用。执行
chmod 400 devops.pem修改权限,同时确保密钥文件仅当前用户可读。 - SSH服务配置异常:从日志看,连接建立后无服务器端版本回应,说明sshd服务未正常响应。可通过EC2串行控制台登录实例,执行
systemctl status sshd检查服务状态;查看/etc/ssh/sshd_config,确认PubkeyAuthentication设为yes、对应用户登录权限开启;执行systemctl restart sshd重启服务。 - 实例内部防火墙拦截:即使安全组放通22端口,实例内部防火墙可能阻断后续握手。执行
iptables -L检查规则,或临时关闭防火墙(CentOS/RHEL用systemctl stop firewalld,Ubuntu用ufw disable)测试。 - 实例资源耗尽:CPU、内存耗尽会导致sshd无法处理新连接。通过EC2控制台查看监控指标,若资源不足,可升级实例规格,或通过串行控制台清理占用资源的进程。
- 版本兼容性问题:客户端为OpenSSH 8.6,服务器端若为旧版本可能存在兼容问题。可添加兼容性参数测试:
ssh -i "devops.pem" -o KexAlgorithms=diffie-hellman-group1-sha1 -o HostKeyAlgorithms=ssh-rsa ec2-user@ec2-3-91-100-189.compute-1.amazonaws.com
内容的提问来源于stack exchange,提问作者Daniel Wu
相关产品推荐
相关产品推荐

