配置UFW与HTTPS后无法SFTP连接DigitalOcean Droplet,求解决步骤
Hey there, let's troubleshoot your SFTP connection issue. The timeout errors you're seeing (Error: Connection timed out after 20 seconds of inactivity and Error: Could not connect to server) are almost definitely related to your UFW firewall configuration—here's how to fix it:
Core Reason
SFTP runs over the SSH protocol, which uses port 22 by default. When you set up UFW, it’s common to forget to explicitly allow SSH traffic (UFW defaults to denying incoming connections unless you whitelist them). HTTPS uses port 443, so that setup doesn’t interfere with SFTP directly.
Step 1: Check Current UFW Rules
First, confirm if SSH traffic is allowed by running this command on your Droplet:
sudo ufw status
Look for a line that says 22/tcp ALLOW Anywhere (and its IPv6 equivalent if you use IPv6). If you don’t see this entry, that’s the problem.
Step 2: Allow SSH Traffic in UFW
Add a rule to allow SSH (port 22) with one of these commands:
# Allow SSH by service name sudo ufw allow ssh # Or allow by specific port (more explicit) sudo ufw allow 22/tcp
UFW will apply this rule immediately, but you can reload it to be safe:
sudo ufw reload
Step 3: Verify the Rule
Run sudo ufw status again—you should now see the SSH port allowed for incoming traffic.
Additional Troubleshooting Steps (If the Above Doesn’t Work)
- Check SSH Service Status: Make sure the SSH daemon is running on your Droplet:
If it’s not running, start it withsudo systemctl status sshdsudo systemctl start sshdand enable it to launch on boot withsudo systemctl enable sshd. - DigitalOcean Cloud Firewall: Don’t forget to check the firewall settings in your DigitalOcean account dashboard. Even if UFW allows port 22, the cloud-level firewall might block it—ensure port 22 is whitelisted there too.
- Local Network Restrictions: If you’re on a work or home network, check if your local firewall or router is blocking outbound traffic on port 22. Try connecting from a different network (like a mobile hotspot) to rule this out.
Once you’ve allowed SSH traffic through UFW (and any cloud/local firewalls), your SFTP connection should work as expected.
内容的提问来源于stack exchange,提问作者corycorycory

