Start with the symptom
In this practice scenario, a QuantumSketch worker is running and its security group permits SSH from the chosen client. The connection still times out because its subnet has no internet route. Adding a second identical port-22 rule cannot repair a missing route.
A timeout and an authentication failure point at different parts of the path. Permission denied after an SSH handshake means the server was reached; investigate the username, key and host configuration. A timeout first calls for connectivity evidence. A stopped instance or a host firewall can also prevent connection.
Follow the request and the reply
An internet client must be able to address the instance. For the public IPv4 path modeled here, that requires a public IPv4 address, an internet gateway attached to the correct VPC, and the correct subnet route. A private instance normally needs a different access path, such as a bastion or Systems Manager; exposing it publicly is not automatically the right repair.
The attached security group must allow the request from the actual source address. A network ACL must permit both the request and the return traffic. The example client uses port 49152 for its reply; real ephemeral ranges depend on the client and path.
- Verify the instance is running.
- Identify the instance subnet and its associated route table.
- Confirm the route target exists and belongs to that VPC.
- Match the source, protocol and destination port in the attached security group.
- Inspect ordered NACL rules in both directions.
- After connectivity succeeds, verify the host listener and authentication.
Repair one cause at a time
Predict the first failure before changing a control below. Run the model, inspect its explanation, fix the named cause and run it again. Then disable the NACL return rule while keeping ingress allowed: the request can arrive while the connection still fails.
For administrative access, use the narrow source range appropriate to your trusted access path. Opening SSH to every address may conceal the symptom while widening access. The useful result is a justified configuration, not merely a green badge.
What this model proves
This is a local configuration model, not a real SSH client. It checks selected IPv4 routes, security-group rules, NACL rules, state and the simulated key setting. It does not test operating-system firewalls, DNS, live sockets, IPv6, peering or an actual private key.
Use the same reasoning in a real account, then confirm with real network and host evidence. Record the tested source, port and access path so another person can reproduce the result.
Predict it. Test it. Change one thing.
Local educational model. No account or cloud charges. Nothing is deployed to AWS.
sim.shahriarlabs.com · Free to explore
Sources and scope
Reviewed against these official references. The model’s supported scope appears alongside its controls.
How we review explanations