温馨提示×

centos ssh报错怎么排查

小樊
38
2026-09-17 21:31:18
栏目: 智能运维

在 CentOS 上遇到 SSH 连接报错,排查可以按照“由近及远、由简到繁”的思路来。下面给你一套通用排查流程和常见错误对照表。


一、先确认问题现象

先搞清楚是哪种报错:

  • 连接超时(timeout)
  • 连接被拒绝(Connection refused)
  • 密码/密钥错误
  • 能连上但马上断开

可用命令测试:

ssh -v user@ip

-v 能看到详细过程,二般问题看 -vvv


二、基础网络排查(最常见)

1. 网络是否通

ping ip
  • 不通:网络/防火墙/IP 错
  • 通但 ssh 不行:继续往下

2. 端口是否通

telnet ip 22
# 或
nc -vz ip 22
  • 不通:sshd 没起 / 防火墙拦了

三、服务端排查(CentOS 本机)

1. 看 sshd 是否运行

systemctl status sshd

没跑就起:

systemctl start sshd
systemctl enable sshd

2. 看端口监听

ss -lntp | grep ssh

正常应看到:

LISTEN 0 128 0.0.0.0:22

3. 防火墙(CentOS 7+)

firewall-cmd --list-all

没开 22:

firewall-cmd --add-service=ssh --permanent
firewall-cmd --reload

4. SELinux(常被忽略)

getenforce

如果是 Enforcing,可临时验证:

setenforce 0

若这样就能连,说明 SELinux 策略问题。


四、SSH 配置问题

1. 配置文件

vi /etc/ssh/sshd_config

重点检查:

Port 22
PermitRootLogin yes/no
PasswordAuthentication yes/no
PubkeyAuthentication yes
AllowUsers xxx

改完重启:

systemctl restart sshd

2. 权限问题(密钥登录失败常见)

chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R user:user ~/.ssh

五、常见报错对照

报错 原因
Connection refused sshd 没起 / 端口不对
Connection timeout 防火墙 / 网络不通
Permission denied 密码错 / 禁止 root / 密钥不对
Too many authentication failures 尝试太多
Host key verification failed known_hosts 冲突
Broken pipe 网络断 / 空闲超时

六、日志是终极手段

服务端看日志:

journalctl -u sshd -f
# 或
tail -f /var/log/secure

客户端加 -v 对照看。


如果你愿意,可以把具体报错信息或 ssh -v 输出贴出来,我可以直接帮你定位是哪一步的问题。

0 踩