Technologytech

How To SSH Into Virtual Machine

how-to-ssh-into-virtual-machine

To SSH into a virtual machine, you open a secure shell connection from your local computer to the VM's command line using the SSH protocol, typically with an SSH key pair for authentication. The core command is `ssh -i /path/to/private/key.pem username@external_ip_address`, and once you have the VM's IP address and the right credentials, the connection takes seconds to establish.

What you need to ssh into a virtual machine

Three essential prerequisites must be in place before you can establish an SSH connection to a virtual machine. First, your local machine needs an SSH client, OpenSSH is built into macOS, Linux, and recent Windows 10+ versions, while PuTTY is a common alternative for older Windows systems. Second, the virtual machine itself must be running an SSH server (such as OpenSSH server) that accepts incoming connections; most Linux distributions have this installed by default. Third, the VM must have network connectivity and its firewall or Network Security Group must allow inbound TCP traffic on port 22, the default SSH port, from your connecting IP address or a specified range.

SSH is the most common and recommended method for accessing Linux-based virtual machines because it encrypts all data transmitted between your local machine and the VM, protecting against eavesdropping on unsecured networks. While password authentication is technically possible, it is generally disabled for security reasons and strongly discouraged due to its vulnerability to brute-force attacks. The recommended and most secure approach is using public-private SSH key pairs, where the public key resides on the VM and the private key stays on your local machine.

How to find your virtual machine's IP address

You need the VM's external IP address to establish an SSH connection, and the method to find it varies by platform. On AWS EC2, the public IP address is displayed in the EC2 console under the instance details after you launch the instance. For Azure VMs, the public IP address appears in the VM overview page in the Azure portal. On Google Cloud Compute Engine, the external IP is listed next to the instance name in the VM instances list. If you are using a local hypervisor like VirtualBox or VMware, check the network settings of the virtual machine in the graphical interface, the IP address is typically shown there, or you can run `IP addr` or `ifconfig` inside the VM's terminal to display its network interface information.

Whichever platform you use, write down the external IP address before proceeding. This address is what you will type into the SSH command, and getting it correct is essential for a successful connection. If the VM obtains its IP via DHCP, the address may change on reboot, so always verify the current IP before connecting.

The ssh command to connect to your VM

Once you have the IP address, open a terminal or command prompt on your local machine and run the SSH command with the full syntax. The basic command format is:

  1. Open a terminal on your local machine (on Windows, you can use PowerShell or the built-in OpenSSH client).
  2. Type `ssh -i /path/to/private/key.pem username@external_ip_address`, replacing the path with the location of your private key file and the username with the appropriate account for your VM's operating system.
  3. Press Enter. If this is the first time connecting to this VM, you may see a host key verification prompt, type "yes" to accept it.

The username depends on the operating system image you used to create the VM. The table below lists the default usernames for common Linux distributions:

Operating system Default username
Amazon Linux ec2-user
Ubuntu Ubuntu
Debian debian
CentOS centos
Azure Linux VMs azureuser

If you created the VM with a custom username, use that instead. After the connection is established, you will see the VM's command prompt, indicating that you now have remote access to its shell.

Setting up SSH key authentication securely

SSH key authentication is the most secure way to connect to your virtual machine, and setting it up involves three main steps: generating a key pair, copying the public key to the VM, and securing the private key on your local machine. To generate an SSH key pair, run `ssh-keygen` on your local machine; this creates a public key (usually `id_rsa.pub`) and a private key (usually `id_rsa`) in your `~/.ssh` directory. You can optionally add a passphrase to encrypt the private key for extra security.

Next, copy the public key to the virtual machine. The easiest method is using `ssh-copy-id username@external_ip_address`, which automatically appends your public key to the `~/.ssh/authorized_keys` file on the VM. If `ssh-copy-id` is not available, you can manually append the contents of your public key to the `authorized_keys` file using a one-time password-based SSH connection. On the VM, ensure the `~/.ssh` directory has 700 permissions and the `authorized_keys` file has 600 permissions, so only the owner can read or modify them.

On your local machine, set restrictive permissions on the private key file with `chmod 400 my-key.pem` (on Linux/macOS). This ensures only you can read the key, preventing unauthorized access. If the private key permissions are too open, SSH will refuse to use it and display a security warning. Once the public key is on the VM and the private key is secured locally, you can connect without entering a password, the SSH client will use your private key to authenticate automatically.

Troubleshooting common SSH connection errors

When you attempt to SSH into a virtual machine, you may encounter several common errors. "Connection refused" typically indicates that the SSH service is not running on the VM, a firewall is blocking port 22, or there is a network connectivity issue. Check that the SSH server is started on the VM (using `systemctl status sshd` on most Linux systems) and verify that the VM's firewall or Network Security Group allows inbound TCP traffic on port 22 from your IP address.

"Permission denied (publickey)" usually means incorrect SSH key permissions on your local machine, the wrong private key is being used, or the VM has OS Login enabled but you are using metadata keys. Ensure your private key file has `chmod 400` permissions, verify that you are specifying the correct key path with the `-i` flag, and confirm that the public key is properly installed in the VM's `authorized_keys` file. If the VM uses OS Login (common on Google Cloud), you may need to use the `gcloud compute ssh` command instead of a manual key.

"Host key verification failed" occurs when the server's public key has changed or you are connecting to a different server than before. This can happen if the VM was recreated or its SSH host key was regenerated. To resolve this, remove the old host key from your local `~/.ssh/known_hosts` file (find the line with the VM's IP address and delete it), then attempt the connection again and accept the new host key when prompted.

Cloud-specific shortcuts for SSH access

Major cloud providers offer convenient alternatives to manual SSH commands that simplify the connection process. Azure provides browser-based SSH via the Azure portal or Azure Cloud Shell, which requires no local SSH client, you can open a terminal directly in your web browser. Similarly, Google Cloud offers SSH-in-browser from the Google Cloud console by clicking the "SSH" button next to the instance, which launches a terminal session without any local setup.

For Google Cloud VMs, the `gcloud compute ssh VM_NAME` command automatically handles SSH key generation and management, so you do not need to create or upload keys manually. This command works from any machine with the Google Cloud SDK installed and authenticates using your Google account credentials. Azure also offers Azure Bastion, which provides secure browser-based SSH access without exposing the VM to the public internet. These cloud-native shortcuts are especially useful when you need quick access to a VM without configuring SSH keys locally, though the standard `ssh -i` command remains the universal method that works across all platforms, including local hypervisors where you might first install an operating system on a vmware virtual machine before connecting to it via SSH.

About the author

Doria English is not just a contributor at Robots.net; she is a visionary exploring the vast landscapes of virtual reality (VR).

View all 99 articles by Doria English  ·  Our editorial policy

Leave a Reply

Your email address will not be published. Required fields are marked *