AWS EC2端口22连接异常求助:SSH连接被IP端口22关闭
Troubleshooting "Connection closed by [IP] port 22" when SSHing to AWS EC2 from Mac
Hey there, sorry to hear you're stuck with this frustrating SSH connection issue—let's walk through some additional checks that might help get you connected, since you've already covered the basic troubleshooting steps.
Double-check your EC2 instance's core health and details
- First, hop into the AWS Console to confirm your instance is in a healthy state: it should be running, system status checks should pass, and there's no pending maintenance. Underlying hardware glitches can sometimes cause unexpected connection drops even if all configs look right.
- Also, make 100% sure you're using the correct public IP or public DNS for the instance. It's easy to mix up details if you have multiple EC2 instances running in your account.
Validate your PEM key file (again)
- Even if you set permissions with
chmod 400 your-key.pem, the key file itself might be corrupted. Try re-downloading the PEM from the AWS Console (if you still have access to the key pair) and save it again to your Mac—accidental edits or transfer issues can break the key without you noticing. - When connecting, ensure you're specifying the key correctly with the
-iflag:ssh -i /full/path/to/your-key.pem ec2-user@[instance-ip](note: replaceec2-userwith the right AMI-specific user—likeubuntufor Ubuntu AMIs,adminfor some Debian variants).
- Even if you set permissions with
Rule out local network/firewall restrictions
- AWS confirmed your IP isn't blocked, but your local network (corporate firewall, home router) might be restricting outbound port 22 traffic. Try connecting via a mobile hotspot to eliminate this variable.
- On your Mac, check if the local firewall is blocking SSH. You can run
sudo pfctl -s rulesto list active PF rules, or head to System Settings > Network > Firewall to ensure SSH is allowed outbound.
Check the EC2 instance's SSH daemon and logs (if you can)
- If you have AWS Systems Manager (SSM) access to the instance (requires the SSM agent installed and proper IAM permissions), start an SSM session to dig into the SSH service:
- Run
sudo systemctl status sshd(for systemd-based distros like Amazon Linux 2 or Ubuntu) to confirm the SSH daemon is running. - Check auth logs for connection errors:
sudo tail -f /var/log/auth.log(Ubuntu/Debian) orsudo tail -f /var/log/secure(Amazon Linux/RHEL). These logs will often tell you exactly why the connection is being closed (e.g., invalid key, user permissions).
- Run
- If you have AWS Systems Manager (SSM) access to the instance (requires the SSM agent installed and proper IAM permissions), start an SSM session to dig into the SSH service:
Verify NACL settings (not just security groups)
- You mentioned configuring inbound security group rules, but don't forget Network Access Control Lists (NACLs) for the instance's subnet. NACLs are stateless, so you need both:
- Inbound allow rule for TCP port 22 from your IP
- Outbound allow rule for ephemeral ports (usually 1024-65535) to let the SSH handshake complete
- It's common to overlook the outbound NACL rule, which can cause connection drops even if security groups are correct.
- You mentioned configuring inbound security group rules, but don't forget Network Access Control Lists (NACLs) for the instance's subnet. NACLs are stateless, so you need both:
Test with a fresh EC2 instance
- Spin up a new, minimal EC2 instance using the same key pair and security group settings. If you can connect to this new instance, the issue is specific to your original instance (likely OS-level SSH config corruption or system file issues). If you still can't connect, the problem might lie with your key pair or account-level settings.
Hopefully one of these steps helps you track down the root cause. Let me know if you spot any specific errors in the logs or have more details to share!
内容的提问来源于stack exchange,提问作者jvera
相关产品推荐
相关产品推荐

