无法通过SSH连接EC2实例,会话超时问题排查求助
Troubleshooting EC2 SSH Timeout Issues
Let’s walk through the most likely fixes for your SSH connection problem—this is a super common snag with EC2 instances, so we’ll get you connected in no time.
1. Fix Your Security Group Rules (This is Critical!)
SSH timeouts almost always boil down to blocked network traffic, and your empty security group rules are the main culprit here:
- Inbound Rules: You need to add a rule allowing SSH (port 22) traffic to your instance.
- Set the type to
SSH, protocol toTCP, port range to22, and source to your local machine’s public IP (you can find this via a quick "what's my IP" search) for security. If you need temporary access from anywhere, you can use0.0.0.0/0—but remember to lock this down later.
- Set the type to
- Outbound Rules: EC2 instances need to send outbound traffic to establish an SSH session (like sending back connection responses). Set a rule allowing all outbound traffic (type
All traffic, protocolAll, port rangeAll, destination0.0.0.0/0). This is the default setting for new security groups, so yours being empty is a problem.
2. Double-Check Your PuTTY Private Key Configuration
Even if you converted your key to .ppk format, let’s confirm a few details:
- Make sure you’re using the correct .ppk file in PuTTY’s
Connection > SSH > Auth > Private key file for authenticationfield—double-check the file path to avoid typos. - Verify the username you’re using to connect: Different AMIs use different default usernames:
- Amazon Linux 2/2023:
ec2-user - Ubuntu:
ubuntu - CentOS/RHEL:
centosorec2-user - Debian:
admin
- Amazon Linux 2/2023:
- In PuTTY’s main Session tab, confirm the port is set to
22and you’ve entered the correct public DNS (no extra spaces or typos).
3. Verify EC2 Instance & Network Setup
- Check that your instance is in the
runningstate (you can confirm this in the EC2 Console). - Ensure your instance has a public IP address assigned—if it doesn’t, you can associate an Elastic IP with it via the EC2 Console.
- If your instance is in a private subnet, make sure you have a NAT Gateway set up to allow outbound traffic, and that your security group/network ACL rules permit SSH traffic through the gateway.
4. Test Basic Connectivity from Your Local Machine
To narrow down the issue, run these commands on your local machine (if you have access to a terminal):
- Test if the public DNS resolves (you said you already did this, but just to confirm):
nslookup <your-ec2-public-dns> - Test if port 22 is reachable:
telnet <your-ec2-public-dns> 22- If this times out, it confirms the problem is still with your security group or network ACL rules blocking traffic.
Start with the security group fixes first—9 times out of 10, that’s the root cause here. Once those are set up correctly, your PuTTY connection should work as expected.
内容的提问来源于stack exchange,提问作者lordoku
相关产品推荐
相关产品推荐

