You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

通过浏览器前端访问Google Cloud实例终端失败:无法连接SSH 22端口

Troubleshooting "Could not access SSH on port 22" for Google Cloud Instance Browser SSH

Hey there, let’s work through this SSH port 22 issue you’re hitting with your Google Cloud instance—this is a super common pain point, but we can troubleshoot it step by step to get you connected.

1. Verify the Instance is Running & Has a Valid External IP

  • Head over to the GCP Console’s VM Instances page and double-check your instance status: it needs to be marked Running. If it’s stopped or terminated, start it up first.
  • Confirm the instance has an external IP (either static or ephemeral). Ephemeral IPs can change if you stop/restart the instance, so refresh your browser SSH tab to pick up the latest IP if needed.

2. Check Firewall Rules Allow SSH Traffic (Port 22)

Firewall blocks are the #1 culprit here:

  • Go to VPC Network > Firewall Rules and look for the default default-allow-ssh rule. Make sure it’s:
    • Enabled (not disabled)
    • Targeted to all instances in network (or tagged with a label your instance has)
    • Set to allow ingress traffic on tcp:22
    • Source IP range includes your current public IP (or 0.0.0.0/0 for broad access, though not ideal for production)
  • If the default rule is missing or broken, create a new one:
    • Direction: Ingress
    • Action on match: Allow
    • Targets: Select "Specified target tags" and add a tag like allow-ssh (then add this tag to your instance under "Tags" in its details page)
    • Source IP ranges: Enter your public IP (find it via curl ifconfig.me locally) or 0.0.0.0/0
    • Protocols and ports: Select "tcp" and enter 22

3. Ensure the SSH Service (sshd) is Running on the Instance

If the firewall is open but SSH still fails, the sshd service might be down:

  • Use the Serial Console (found in your instance’s details page under "Connect > Serial console") to access the instance without SSH:
    • Once logged in, check the service status with:
      sudo systemctl status sshd
      
    • If it shows "inactive (dead)", start it up and enable it to run on boot:
      sudo systemctl start sshd
      sudo systemctl enable sshd
      
  • Double-check the sshd config file to make sure port 22 isn’t disabled:
    sudo nano /etc/ssh/sshd_config
    
    Look for the line Port 22—if it’s commented out (starts with #), remove the # and save the file, then restart the service with sudo systemctl restart sshd.

4. Validate SSH Key Configuration

Browser SSH relies on keys stored in GCP metadata—let’s make sure those are set up correctly:

  • Go to your instance’s details page > Metadata > SSH Keys tab. Check if your public key is listed here (format should be ssh-rsa AAAAB3NzaC1yc2E... your-username@domain).
    • If it’s missing, click "Add item" and paste your local public key (or let the browser generate a new one when you try to connect again).
  • From the Serial Console, verify the key is present in your user’s authorized_keys file:
    cat ~/.ssh/authorized_keys
    
    If it’s not there, manually add it, then fix file permissions (critical for SSH to trust the keys):
    chmod 700 ~/.ssh
    chmod 600 ~/.ssh/authorized_keys
    sudo systemctl restart sshd
    

5. Rule Out Network or Resource Issues

  • Try connecting from your local terminal instead of the browser to get more detailed error messages:
    ssh your-username@instance-external-ip
    
    This might tell you if it’s a key issue, timeout, or permission problem.
  • Check instance resource usage (CPU, memory) in the GCP Console’s Monitoring tab. If CPU is spiking to 100%, the instance might be too overloaded to respond to SSH—restart the instance to free up resources.
  • If the instance was just created, wait 2-3 minutes for full initialization. Sometimes sshd takes a moment to start up during the first boot.

If none of these steps resolve the issue, you might need to create a new instance (copying over disk data if needed) or check for more advanced VPC configuration issues (like routing tables or NAT gateways), but 9 times out of 10, one of the above fixes will get you connected.

内容的提问来源于stack exchange,提问作者Sanjay Kumar

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.27 03:47:03