从VSTS克隆仓库时遭遇连接拒绝问题求助
Hey there, let's dig into this connection refused error you're facing when trying to clone your VSTS repo via PowerShell. Since you've already authenticated successfully and can pull up the full list of repos, we can rule out basic authentication issues—this is almost certainly tied to how Git is communicating with the server, or network restrictions specific to Git traffic.
Here are the most likely fixes to try, in order of simplicity:
1. Double-check your Git remote URL protocol
SSH URLs for VSTS rely on port 22, which your server's network policy probably blocks (since you can only access MyVSAccount.VisualStudio.com). Make sure you're using the HTTPS URL instead, which uses port 443 (the same one you're using to fetch repo lists).
Your HTTPS URL should look like this:
https://<your-username>:<your-personal-access-token>@MyVSAccount.VisualStudio.com/_git/YourRepoName
If you already initialized a local repo and need to update the remote, run this command:
git remote set-url origin https://<your-username>:<your-PAT>@MyVSAccount.VisualStudio.com/_git/YourRepoName
2. Verify port 443 connectivity to the VSTS domain
Even though you can fetch repo lists, Git might be hitting a different network rule. Test if your server can reach port 443 on MyVSAccount.VisualStudio.com with this PowerShell command:
Test-NetConnection MyVSAccount.VisualStudio.com -Port 443
Look for the TcpTestSucceeded field—if it's False, your server's firewall or network policy is blocking outbound traffic to port 443 for this domain. You'll need to work with your ops team to open this up.
3. Check Git proxy settings
Git might be picking up a system proxy that's interfering with access to your restricted domain. Try temporarily disabling Git's global proxy settings:
git config --global http.proxy "" git config --global https.proxy ""
If you have an internal proxy that's allowed to access MyVSAccount.VisualStudio.com, you can instead configure Git to only use the proxy for other domains:
git config --global http.https://MyVSAccount.VisualStudio.com.proxy ""
4. Confirm your PAT has the right permissions
Even though you can list repos, cloning requires the Code (Read) scope on your Personal Access Token. Head to your VS Account's Security settings, find your PAT, and double-check that the Code scope is set to Read.
5. Use your Fiddler logs to spot redirects or unexpected requests
Since you're using Fiddler, keep an eye out for these red flags:
- Is Git being redirected to
dev.azure.com? Microsoft migrated VSTS to Azure DevOps, so some requests might redirect to the new domain. If your server only allows access toMyVSAccount.VisualStudio.com, this redirect will fail. Fix this by disabling redirects in Git:git config --global http.followRedirects false - Check the exact URL Git is trying to hit—does it match the
MyVSAccount.VisualStudio.comdomain? If it's calling a different subdomain or endpoint, that's likely the issue.
Start with the first couple of steps, and if those don't work, dive into the Fiddler logs to get more specifics. Let me know if you need help interpreting those logs!
内容的提问来源于stack exchange,提问作者Consuela

