在 CentOS 上遇到 SSH 连接报错,排查可以按照“由近及远、由简到繁”的思路来。下面给你一套通用排查流程和常见错误对照表。
先搞清楚是哪种报错:
可用命令测试:
ssh -v user@ip
-v 能看到详细过程,二般问题看 -vvv
ping ip
telnet ip 22
# 或
nc -vz ip 22
systemctl status sshd
没跑就起:
systemctl start sshd
systemctl enable sshd
ss -lntp | grep ssh
正常应看到:
LISTEN 0 128 0.0.0.0:22
firewall-cmd --list-all
没开 22:
firewall-cmd --add-service=ssh --permanent
firewall-cmd --reload
getenforce
如果是 Enforcing,可临时验证:
setenforce 0
若这样就能连,说明 SELinux 策略问题。
vi /etc/ssh/sshd_config
重点检查:
Port 22
PermitRootLogin yes/no
PasswordAuthentication yes/no
PubkeyAuthentication yes
AllowUsers xxx
改完重启:
systemctl restart sshd
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
chown -R user:user ~/.ssh
| 报错 | 原因 |
|---|---|
| Connection refused | sshd 没起 / 端口不对 |
| Connection timeout | 防火墙 / 网络不通 |
| Permission denied | 密码错 / 禁止 root / 密钥不对 |
| Too many authentication failures | 尝试太多 |
| Host key verification failed | known_hosts 冲突 |
| Broken pipe | 网络断 / 空闲超时 |
服务端看日志:
journalctl -u sshd -f
# 或
tail -f /var/log/secure
客户端加 -v 对照看。
如果你愿意,可以把具体报错信息或 ssh -v 输出贴出来,我可以直接帮你定位是哪一步的问题。