SSH Connection Refused Ubuntu: Causes and Solutions: Practical Guide
Fix SSH connection refused errors on Ubuntu with this step-by-step guide. Covers firewall rules, service status, port conflicts, and authentication issues.

On this page
TL;DR — Key takeaways
- SSH connection refused on Ubuntu typically results from the SSH service not running, firewall blocking port 22, or incorrect SSH daemon configuration.
- Check SSH service status with 'sudo systemctl status ssh' and restart it with 'sudo systemctl restart ssh' if the service is inactive or failed.
- Verify firewall rules allow SSH traffic using 'sudo ufw status' and enable SSH access with 'sudo ufw allow 22/tcp' if needed.
- Test SSH connectivity locally first with 'ssh localhost' to isolate whether the issue is server-side configuration or network-related.
- Always create a backup SSH session before modifying SSH configuration to prevent being locked out of your server.
SSH connection refused errors on Ubuntu prevent remote access to your server, disrupting workflows and blocking critical maintenance tasks. This error appears when your SSH client cannot establish a connection to the SSH daemon on the target Ubuntu system.
This guide walks through the most common causes of SSH connection refused errors on Ubuntu and provides practical, tested solutions. You'll learn how to diagnose the issue systematically, apply fixes safely, and verify that SSH access is restored.
Understanding SSH Connection Refused Errors
When you attempt to connect via SSH and receive a 'connection refused' message, the error indicates that your connection request reached the target server, but the server actively rejected it. This differs from timeout errors, which suggest network connectivity problems or firewall blocking at the network level.
The connection refused error specifically means the SSH daemon (sshd) is either not running, not listening on the expected port, or the port is blocked by a local firewall. Understanding this distinction helps you target the right troubleshooting steps.
- Connection refused: Server reachable but SSH service unavailable or port blocked locally
- Connection timeout: Network unreachable or firewall blocking at network perimeter
- Permission denied: SSH service running but authentication failed
Checking SSH Service Status
The first step in diagnosing SSH connection refused errors is verifying that the SSH service is running. Ubuntu uses the OpenSSH server package, which runs as a systemd service named 'ssh' or 'sshd' depending on the Ubuntu version.
If you have console access to the server (physical access, VPS console, or existing SSH session), check the service status with this command:
- Run: sudo systemctl status ssh
- Look for 'active (running)' in green text indicating the service is operational
- If status shows 'inactive (dead)', start the service: sudo systemctl start ssh
- If status shows 'failed', review error logs: sudo journalctl -u ssh -n 50
- Enable SSH to start automatically on boot: sudo systemctl enable ssh
Verifying SSH Installation and Configuration
If the SSH service is not installed or has configuration errors, the connection will be refused. Verify that OpenSSH server is installed and properly configured before proceeding with other troubleshooting steps.
Check if OpenSSH server is installed with 'dpkg -l | grep openssh-server'. If not present, install it with 'sudo apt update && sudo apt install openssh-server'. After installation, the service should start automatically.
- Verify installation: dpkg -l | grep openssh-server
- Install if missing: sudo apt update && sudo apt install openssh-server
- Check configuration file syntax: sudo sshd -t
- Review main configuration: sudo cat /etc/ssh/sshd_config | grep -v '^#' | grep -v '^$'
- Verify SSH is listening on port 22: sudo ss -tlnp | grep :22
- After configuration changes, restart SSH: sudo systemctl restart ssh
Diagnosing Firewall and Port Issues
Ubuntu's Uncomplicated Firewall (UFW) or iptables rules may block incoming SSH connections even when the SSH service is running. This is a common cause of connection refused errors, especially on newly configured servers or after security hardening.
Before modifying firewall rules, ensure you have alternative access to the server (console access or existing SSH session). Never test firewall changes without a backup access method, as incorrect rules can lock you out completely.
- Check UFW status: sudo ufw status verbose
- If UFW is active and SSH is not listed, allow SSH: sudo ufw allow 22/tcp
- For SSH on custom port (example 2222): sudo ufw allow 2222/tcp
- Verify listening ports: sudo netstat -tlnp | grep ssh
- Check for port conflicts: sudo lsof -i :22
- Review iptables rules if UFW is not used: sudo iptables -L -n -v
Testing SSH Connectivity Locally and Remotely
Isolating whether the issue is server-side or network-side helps focus troubleshooting efforts. Test SSH connectivity from the server itself first, then from the network.
Local testing verifies that SSH is properly configured and accepting connections. If local connections work but remote connections fail, the issue is network-related (external firewall, security group, or network routing).
- Test from server itself: ssh localhost (or ssh 127.0.0.1)
- Test with verbose output: ssh -v username@server_ip
- Test specific port: ssh -p 2222 username@server_ip
- Check network path with: telnet server_ip 22 (from remote machine)
- If telnet connects but SSH fails, the issue is SSH authentication or configuration
- If telnet times out or is refused, check network firewalls and security groups
Resolving Common SSH Configuration Issues
SSH daemon configuration errors can prevent the service from starting or cause it to reject connections. The configuration file at /etc/ssh/sshd_config controls SSH behavior, and syntax errors or restrictive settings may block access.
Always create a backup before editing SSH configuration. Use 'sudo cp /etc/ssh/sshd_config /etc/ssh/sshd_config.backup' to preserve the original. Test configuration syntax with 'sudo sshd -t' before restarting the service to catch errors without disrupting active connections.
- Backup configuration: sudo cp /etc/ssh/sshd_config /etc/ssh/sshd_config.backup
- Common issue - SSH disabled: Check 'PermitRootLogin' and user access settings
- Verify port setting: Look for 'Port 22' or custom port in sshd_config
- Check ListenAddress directive: Ensure it's not restricting to wrong IP
- Test configuration syntax: sudo sshd -t (reports errors without restarting service)
- Apply changes safely: sudo systemctl restart ssh (only after syntax test passes)
- Rollback if needed: sudo cp /etc/ssh/sshd_config.backup /etc/ssh/sshd_config && sudo systemctl restart ssh
Preventing Future SSH Access Issues
After resolving SSH connection refused errors, implement preventive measures to avoid similar issues. Regular monitoring, proper change management, and backup access methods reduce the risk of being locked out.
Configure monitoring for the SSH service to alert when it stops. Set up fail2ban to protect against brute force attacks without blocking legitimate access. Document custom SSH configurations and maintain alternative access methods like console access for emergency recovery.
- Enable SSH service monitoring with systemd alerts or external monitoring
- Keep a documented backup of sshd_config in version control
- Configure fail2ban for SSH protection: sudo apt install fail2ban
- Set up SSH key authentication instead of password-only access
- Maintain console or out-of-band access for emergency recovery
- Test SSH access after any system updates or firewall changes
- Document custom SSH ports or configurations in your runbook
Quick troubleshooting checklist
- Verify SSH service is running with 'sudo systemctl status ssh'
- Check if OpenSSH server is installed with 'dpkg -l | grep openssh-server'
- Test SSH configuration syntax with 'sudo sshd -t' before restarting service
- Confirm SSH is listening on expected port with 'sudo ss -tlnp | grep :22'
- Check UFW firewall rules with 'sudo ufw status' and allow SSH if needed
- Test local SSH connectivity with 'ssh localhost' to isolate server vs network issues
- Review SSH logs with 'sudo journalctl -u ssh -n 50' for specific error messages
- Create backup SSH configuration before making changes
- Maintain alternative access method (console) before modifying SSH or firewall
- Enable SSH service to start on boot with 'sudo systemctl enable ssh'
FAQ
What does SSH connection refused mean on Ubuntu?
SSH connection refused on Ubuntu means your connection request reached the server, but the server actively rejected it. This typically occurs when the SSH service (sshd) is not running, not installed, or when a local firewall is blocking the SSH port (usually port 22). It differs from connection timeout errors, which indicate network-level blocking or unreachability.
How do I start SSH service on Ubuntu?
Start the SSH service on Ubuntu with the command 'sudo systemctl start ssh'. To ensure it starts automatically on boot, run 'sudo systemctl enable ssh'. You can verify the service is running with 'sudo systemctl status ssh', which should show 'active (running)' in green. If the service fails to start, check error logs with 'sudo journalctl -u ssh -n 50'.
How do I check if SSH port 22 is blocked on Ubuntu?
Check if SSH port 22 is blocked on Ubuntu by first verifying the SSH service is listening with 'sudo ss -tlnp | grep :22'. Then check UFW firewall status with 'sudo ufw status verbose' to see if port 22 is allowed. If UFW is active and SSH is not listed, allow it with 'sudo ufw allow 22/tcp'. You can also test from another machine using 'telnet server_ip 22' to determine if the port is accessible remotely.
Why is my SSH connection refused after Ubuntu update?
SSH connection refused after Ubuntu update typically occurs when the update requires a service restart that did not happen automatically, when configuration file changes conflict with custom settings, or when firewall rules were reset. Check if SSH service is running with 'sudo systemctl status ssh' and restart it with 'sudo systemctl restart ssh'. Review your configuration with 'sudo sshd -t' to catch syntax errors, and verify firewall rules with 'sudo ufw status'.
How do I fix SSH connection refused without console access?
Fixing SSH connection refused without console access is extremely difficult and depends on having alternative access methods. If you have a web-based control panel, cloud provider console, or IPMI/iLO access, use those to diagnose and restart the SSH service. Without any alternative access, you may need to contact your hosting provider or use rescue mode boot options. This is why maintaining a backup SSH session when making configuration changes is critical.
Related articles
- Hosting OperationsSelf-Hosted App Deployment Fails? Check DNS, SSL, Reverse Proxy, and Logs FirstTroubleshoot failed self-hosted app deployments by checking DNS, SSL, reverse proxy routing, container status, logs, and ports.
- Hosting OperationsSelf-Hosted PaaS on a VPS: What to Check Before Installing Coolify, Dokploy, or CapRoverA hosting support checklist for preparing a VPS before installing self-hosted PaaS tools like Coolify, Dokploy, or CapRover.
- Hosting OperationsLinux Server Security Lessons from the Arch Linux Malware Package IncidentPractical Linux server security checklist for VPS admins after package malware concerns, with safe checks, rollback steps, and support guidance.
- Hosting OperationsAWS Lightsail Hong Kong VPS Latency: Practical Hosting Guide for IndonesiaLearn how to test AWS Lightsail Hong Kong VPS latency, compare regions, migrate safely, and troubleshoot hosting performance.
- Hosting OperationsCloudflare Tomorrow Watchlist: A Practical Hosting Operations GuidePractical Cloudflare troubleshooting checklist for DNS, SSL, caching, WAF, origin health, safe testing, and rollback planning.
- Hosting OperationsNetwork Safety Checklist for AI Agent Skills in Hosting OperationsAudit AI agent skills safely with network checks, secret protection, sandbox testing, rollback steps, and hosting support troubleshooting guidance.