A hang then 'Connection timed out' means packets are being silently dropped — firewall, wrong IP, or nothing listening. It never got to your keys.
DROP gives timeouts (REJECT would give 'connection refused' fast). Cloud security groups, host firewalls, or corporate egress filters.
Private IP from outside the VPC, stale DNS, or the router's forward rule was removed.
sshd stopped or server powered off — looks identical from outside when a firewall drops packets.
nc -zv -w 5 host 22
traceroute -T -p 22 host
sudo ss -tlnp | grep :22 && sudo ufw status # or nft list ruleset
# provider console: inbound 22 from your IP — not 0.0.0.0/0
Timeout vs refused is your first diagnostic: refused means the network is fine and sshd is the problem; timeout means the network is the problem and sshd is unknown. Always keep one out-of-band console path to every server you care about.
Refused = something answered with 'no' (nothing listening, or actively rejected). Timeout = no answer at all: firewall DROP, wrong IP, or the host down. The distinction eliminates half the search space before you start.
Most commonly: the host IP changed (DHCP/cloud), a firewall rule or security group tightened, or fail2ban banned your address after failed attempts. Check from another network first — if it works there, the block is on the path from YOUR address.
Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.
Browse the template store →One-time. Yours to modify. Instant download from the NinjaOps template store.