Cannot Connect to Your Server
Last updated 29 September 2026
Work through these in order
Most connection problems are one of a handful of causes, and the dashboard shows you which. Open Compute, select the server, and check each of the following before opening a ticket.
1. Is the server running?
Look at the status badge at the top of the server page.
- stopped: click Start. A server that was stopped from inside the operating system (for example with
shutdown) stays stopped until you start it here. - provisioning: the server is still being built. The status changes to running when provisioning completes.
- suspended_billing: a banner explains that the server is suspended because an invoice is unpaid, and the controls are disabled until it is paid. Click Pay Now, and the server returns to service once payment is confirmed.
- error: provisioning failed. Open a support ticket and quote the server name.
2. Are you using the right address?
The IP Addresses card lists the server's IPv4 and IPv6 addresses. Copy the address from there rather than from an old note: a floating IP you have since moved, or a server you have since rebuilt, is a common cause of "connection refused" on a perfectly healthy machine.
Try the connection from your terminal with verbose output so you can see where it stops:
ssh -v root@203.0.113.10
- Connection timed out usually means a firewall is dropping the traffic, or the server has no working network configuration.
- Connection refused means the server answered but nothing is listening on that port: SSH is not running, or is listening on a different port.
- Permission denied (publickey) means you reached SSH but your key was not accepted; see section 5.
3. Check the firewalls
Traffic to your server passes through up to three firewalls, and any one of them can block you.
Edge Firewall (the card on the server page). Rules here are applied at the network edge, before traffic reaches your server, on every public address of the server, in the order listed and with the action shown. With no rules, all traffic is allowed. A Deny rule that matches your connection blocks you before the server sees it. A common pattern is an Allow rule for your own address followed by a Deny for everyone else; it locks you out the day your address changes, so check that the address you are connecting from is still the one allowed. Edge rules are not yet available at every location; the card tells you when you try to add a rule.
Firewall Rules (the guest firewall card). These rules are enforced by the platform on the server's network interface. With no rules, all traffic is allowed. A Drop or Reject rule for the SSH port, or an Accept rule with a source range that does not include you while other traffic is dropped, will lock you out. Rules are applied when you click Save. See the Firewall article for the rule options.
The operating system's own firewall (ufw, firewalld, nftables, Windows Firewall). This runs inside your server and is under your control. If you have changed it recently and can no longer connect, use the console (section 4) to review it.
4. Use the console
The Console button opens your server's screen in a new browser tab. It does not use the server's network, so it works when SSH does not. Log in with the username and password shown on the Initial Password card (see section 5), then check from inside the server:
ip addr # does the interface have the address shown on the dashboard?
ip route # is there a default route?
systemctl status ssh # is SSH running? (sshd on some distributions)
ss -tlnp | grep ssh # which port is it listening on?
If the graphical console is not enough, most servers also have a Serial console, which gives you a text terminal. If it reports that it becomes available after the next restart, restart the server once from the dashboard; if it still does not open, use the graphical console. The Using the Console article covers both.
5. SSH key or password?
How you log in depends on how the server was built.
- Built with an SSH key. Password login over SSH is switched off; only the keys on your account at the time of deployment (or of the last reinstall) are accepted. Check you are using the matching private key (
ssh -i ~/.ssh/id_ed25519 root@...). If the key you need is not on the server, use the console with a password instead, or reinstall so the account's current keys are installed. - Built without an SSH key (and all Windows servers). A password was generated at build time. It is shown on the server page under Initial Password, together with the username to use (root on Linux, Administrator on Windows): click View Initial Password. It is never sent by email. If the card says no initial password is available, the server was built with a key.
- Forgotten or unknown password. With the server running, choose More, then Reset Password. You can generate a random password or set your own. The new password is shown once in the dashboard; copy it then. On Linux servers the reset also enables password login over SSH. If the reset reports an error, choose Set Custom Password so that you know the password, and run the reset again. Password reset needs the guest agent that our images include; it is not available for router appliances.
If SSH accepts your key but the server closes the connection at once, the shell or the disk inside the server is the likely problem; the console will show you the error.
6. Is the server throttled?
If the Bandwidth Usage card shows a Throttled badge, the server has used its included traffic for the billing period. It remains reachable but at a reduced speed, which can make an SSH session feel unresponsive. The speed is restored at the start of the next period. See Monitoring Your Server and Usage.
7. Rescue and reinstall
If the operating system will not boot or the disk needs repair, mount a rescue or installer image from ISO Management on the server page, reboot, and work from the console. You can use the images we provide at your location or upload your own (.iso or .img, up to 1 GB, three images per location).
If the server cannot be recovered, reinstalling the operating system gives you a fresh system on the same addresses. It erases the disk, so copy off anything you need first.
What our support covers
Our support covers our network, our hardware and the platform itself: connectivity, routing, the hypervisor, storage and your dashboard. Your server is self-managed: the operating system, the software on it and the configuration inside it are under your control, and as a matter of policy we do not log in to customer servers.
If you have worked through the list above and the problem is on our side (the server is Running, no firewall rule applies, and the console shows the network configured correctly but traffic does not arrive), open a support ticket and include the server name, the address you are connecting from, the exact error text and what you have already checked. That lets us start on the network rather than on the questions.