You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Amazon Lightsail Ubuntu VPS修改SSH端口后无法登录求助

Troubleshooting Non-Standard SSH Port Timeouts on Amazon Lightsail Ubuntu

Hey there, let’s work through this SSH port issue you’re facing on your Lightsail Ubuntu instance. I’ve dealt with this exact scenario multiple times, so here’s a breakdown of the most likely fixes:

1. Don’t Forget the Lightsail Instance Firewall

Amazon Lightsail has its own cloud-level firewall that’s completely separate from UFW or iptables on your server. Even if you disabled UFW, this external firewall is probably blocking your new port. Here’s how to fix it:

  • Log into your Amazon Lightsail console
  • Navigate to your Ubuntu instance
  • Click the Networking tab
  • Under the Firewall section, click Add rule
  • Select Custom as the application, set the protocol to TCP, and enter your desired port (e.g., 2200) in the Port range field
  • Set the Source to 0.0.0.0/0 (or restrict it to your local IP for extra security)
  • Save the rule and wait 1-2 minutes for changes to take effect

2. Confirm SSHD is Properly Listening on the New Port

While sudo service ssh status might show the service is running, let’s verify with a more precise command to ensure it’s bound to the correct port:

sudo ss -tulpn | grep ssh

You should see output like this (replace 2200 with your port):

LISTEN 0      128                0.0.0.0:2200            0.0.0.0:*    users:(("sshd",pid=1234,fd=3))
LISTEN 0      128                   [::]:2200               [::]:*    users:(("sshd",pid=1234,fd=4))

If you don’t see your port here, double-check your sshd_config for typos (e.g., extra spaces, wrong port number) and restart the service again with sudo systemctl restart ssh (note: newer Ubuntu versions use systemctl instead of service for more reliable status tracking).

3. Check for Hidden iptables Rules

Even with UFW disabled, there might be leftover iptables rules blocking your port. Run this to list current rules:

sudo iptables -L

If you don’t see an ACCEPT rule for your port, add it manually:

sudo iptables -A INPUT -p tcp --dport 2200 -j ACCEPT

To save these rules so they persist after a reboot, use:

sudo netfilter-persistent save

4. Rule Out Local Network Restrictions

Some ISPs or local firewalls block non-standard SSH ports like 2200 or 2222. Test connectivity from a different network (e.g., your phone’s hotspot) or use telnet to diagnose:

telnet your-server-public-ip 2200

If this times out, try a less common port (like 2022 or 3022) — some ports are less likely to be blocked by default.

5. Double-Check sshd_config for Mistakes

It’s easy to make a small typo in the config file. Open it again to confirm:

sudo nano /etc/ssh/sshd_config

Ensure the line for the port is exactly:

Port 2200

(No extra spaces, no comments before it, and make sure you didn’t accidentally set it to a port that’s already in use by another service.)


Most of the time, the root cause is the Lightsail cloud firewall not allowing the new port — that’s the first thing I check whenever this issue pops up. Give these steps a try, and you should be able to connect on your non-standard port in no time.

内容的提问来源于stack exchange,提问作者AmrAnwar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 09:38:25