SSH Connection Times Out (Hanging Before Auth)

A hang then 'Connection timed out' means packets are being silently dropped — firewall, wrong IP, or nothing listening. It never got to your keys.

What you'll see

Root causes

Firewall DROP between you and the host

DROP gives timeouts (REJECT would give 'connection refused' fast). Cloud security groups, host firewalls, or corporate egress filters.

Wrong address or NAT/port-forward missing

Private IP from outside the VPC, stale DNS, or the router's forward rule was removed.

ssh not listening / host down

sshd stopped or server powered off — looks identical from outside when a firewall drops packets.

Fix it

  1. Is the port even open? (timeout = filtered, refused = open-but-dead)
    nc -zv -w 5 host 22
  2. See where packets die
    traceroute -T -p 22 host
  3. From another path (console, VPN, bastion), check the listener and firewall
    sudo ss -tlnp | grep :22 && sudo ufw status   # or nft list ruleset
  4. Check cloud security group allows your current IP
    # provider console: inbound 22 from your IP — not 0.0.0.0/0

Field note

Timeout vs refused is your first diagnostic: refused means the network is fine and sshd is the problem; timeout means the network is the problem and sshd is unknown. Always keep one out-of-band console path to every server you care about.

Common questions

Timeout vs connection refused — what's the difference?

Refused = something answered with 'no' (nothing listening, or actively rejected). Timeout = no answer at all: firewall DROP, wrong IP, or the host down. The distinction eliminates half the search space before you start.

SSH worked yesterday and now times out — what changed?

Most commonly: the host IP changed (DHCP/cloud), a firewall rule or security group tightened, or fail2ban banned your address after failed attempts. Check from another network first — if it works there, the block is on the path from YOUR address.

Ship it right the first time

Our most-documented failures, packaged as ready-to-ship starter kits: Docker, Kubernetes, and Terraform.

Browse the template store →

One-time. Yours to modify. Instant download from the NinjaOps template store.