When your regular SSH client, such as OpenSSH, Termius, or PuTTY, suddenly reports Connection refused、Connection timed out or reports a key authentication failure, remote network access to the VPS has usually been interrupted. The hosting provider's web console (Web Console / VNC / Interactive Shell) is then the most important entry point for troubleshooting and recovering the system.
The console connects directly to the virtual display and keyboard through the underlying virtualization host (such as KVM's VNC or serial console), without relying on the guest system's network, firewall, or SSH daemon. As long as the host and control panel are functioning, you can troubleshoot as though you were sitting in front of a physical monitor.
1. Check Basic Status Before Opening the Console#
Before logging into the console to troubleshoot, first confirm the instance's physical operating state in the provider's management panel. This avoids pointless investigation while it is already suspended or awaiting an underlying scheduled task.
Check Instance Lifecycle and Billing Status#
- DMIT: Instances that are not renewed by the due date are Suspended. Invoices are usually generated 7 days before expiration. Under DMIT's rules, there is generally only a 3-day grace period after suspension; failure to settle the invoice then triggers data destruction. If the instance status is not
Running, first check billing and service status. - BandwagonHost( BandwagonHost ): Invoices are also issued 7 days before expiration, without mandatory automatic charges by default. If the account has credit and automatic deductions are enabled, the system settles the bill automatically. If nonpayment causes suspension, instance service stops and neither networking nor the underlying virtual hardware remains active.
Identify the Type of Console Access#
不同 Providers 在面板中的控制台功能命名和底层实现有所不同:
- BandwagonHost (KiwiVM Panel):
- Interactive Console / Root shell - interactive: provides a browser-based interactive Shell and is the preferred channel for troubleshooting.
- Screenshot: captures only a static image of the virtual machine's current screen. If you only need to check quickly whether the system is stuck at GRUB, experiencing a Kernel Panic, or running a filesystem repair (fsck), view the screenshot first without opening a terminal. Interactive operations require the interactive console.
- DMIT (Client Area Management Panel):
- Provides directly on the service details page Console entry point. It bridges to the instance's virtual display through HTML5 VNC/NoVNC, fully supporting keyboard input and key interactions during boot.
The Browser Reports: the browser may block the popup the first time you click Launch or Console. Add the provider's panel domain to the popup allowlist. Do not immediately click “Reinstall” simply because the page loads blank.
2. Understand the Console Login Credential System#
After the console starts, the screen usually displays a Linux text-terminal login prompt:
Ubuntu 24.04 LTS vps-hostname tty1
vps-hostname login:Many users get stuck at this step because they confuse credentials used at different access levels.
Credential Separation and Differences#
- Provider Client Area Password: Used to log in to the provider's website and view invoices and support tickets; it cannot be used for terminal login.
- 面板专属密码: for example, BandwagonHost's separate KiwiVM management password is used only to log into the KiwiVM management interface; it is not the system root password.
- Operating System Password (root / sudo User):
- BandwagonHost: On initial provisioning or a KiwiVM OS reinstall, the system generates a random initial root password. If you changed it yourself, use the changed password.
- DMIT: Official templates disable remote root password login by default and require SSH keys. If the key is damaged and no system password was ever set, ordinary password verification in the console will not work. First use the DMIT instance panel's Access section to set a new password or inject a new public key.Note: after changing credentials in the Access panel, you must reboot the instance (Reboot) as specified by the panel before the underlying cloud-init or automated configuration scripts can write the new credentials into the system image。
控制台输入细节#
- Enter
login:then type the username (usuallyroot), then press Enter. - appears
Password:enter the password at the prompt.For Security, Linux Terminals Show No Asterisks or Placeholders While You Enter a Password, finish typing without visible feedback and simply press Enter. - Because Web consoles rely on browser keyboard mappings, pasting from the clipboard may lose characters or produce incorrect symbols. If the password is long and includes complex special characters, first test the keyboard layout on a plain-text line (for example, distinguish between
-and_), or use the panel to reset it to a short, strong character string for emergency access, then harden it again after logging in.
3. First Step in Console Troubleshooting: Collect Read-Only Information#
After logging in successfully, do not rush to edit configuration files or run destructive commands. Start with low-risk, read-only checks to quickly isolate the fault.
Check System Load, Disk, and Memory#
# 查看系统运行时长与负载
uptime
# 查看磁盘挂载与空间占用(确认根目录 / 是否写满,Inode 是否耗尽)
df -h
df -i
# 查看内存消耗情况
free -m
# 查看内核最近是否有硬件错误、OOM 杀死进程或驱动故障
dmesg -T | tail -n 50If df -h shows / usage reaches 100%, and the SSH daemon, while attempting to write /var/log, allocating a pseudo-terminal (pty), or reading authorized keys can crash outright and disconnect the remote session.
Check Network Interfaces and Routing Status#
# 查看网卡接口状态与 IP 分配
ip -br address
# 查看默认网关与路由表
ip route show
# 测试宿主机网关连通性(使用 ip route 中显示的 default 网关 IP)
ping -c 4 <网关IP>If the network interface is DOWN status, or has not obtained a public IP, the network stack is malfunctioning. Try restarting the network service (systemctl restart systemd-networkd or systemctl restart NetworkManager, depending on the system version).
Check the SSH Daemon Status#
# Debian / Ubuntu 常用服务名为 ssh;CentOS / AlmaLinux / RockyLinux 常用 sshd
systemctl status ssh --no-pager || systemctl status sshd --no-pager
# 查看 SSH 具体的启动失败日志
journalctl -u ssh -n 30 --no-pager || journalctl -u sshd -n 30 --no-pager
# 检查实际监听端口
ss -tulpn | grep -E 'ssh|sshd'4. Common Causes of Lost Connectivity and Targeted Remedies#
Scenario A: Local Firewall Misconfiguration (Blocking Your Own Ports)#
When adjusting ufw、iptables or firewalld 时,未提前放行自定义 SSH 端口或误启用了默认丢弃(DROP)规则,是导致失联的最常见诱因。
Troubleshooting and Recovery Methods:
# 检查 UFW 状态
ufw status verbose
# 若因误启 UFW 阻断,可直接在控制台临时停用
ufw disable
# 检查 iptables 规则是否包含 DROP
iptables -L -n -v --line-numbers
# 若需要临时清空防火墙规则恢复网络
iptables -F
iptables -X
iptables -t nat -F
iptables -P INPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -P OUTPUT ACCEPTAfter confirming that remote SSH access is restored, immediately rebuild and save the correct allow rules. Do not leave the server unprotected long-term.
Scenario B: SSH Configuration Syntax Errors or Overly Strict Security Restrictions#
修改 /etc/ssh/sshd_config 后重载服务,若存在语法错误,进程将直接崩溃。
Troubleshooting and Recovery Methods:
# 使用 sshd 自检命令验证配置文件语法
sshd -tIf the output reports an error, go directly to the indicated line in the file and fix it with a text editor (such as nano /etc/ssh/sshd_config)。
Key Configuration Settings to Check:
Port 22: confirm that the port matches the one specified when you connect.PermitRootLogin: If attempting to log in as root, check whether it is set tono。PasswordAuthentication:若私钥失效试图使用密码登录,需确认该项是否被关闭。
After making changes, restart the service:
systemctl restart ssh || systemctl restart sshdScenario C: Process Failures Caused by a Full Disk#
If df -h shows disk usage at 100%:
# 快速定位 /var/log 或系统大文件占用
du -ahx / | sort -rh | head -n 20
# 常见清理方案:安全收缩 systemd 日志空间
journalctl --vacuum-size=100M
# 清理 APT 或 YUM 软件包缓存
apt-get clean || dnf clean allAfter freeing disk space, restart SSH to restore responsiveness.
5. Handling Boot Failures and Kernel Crashes#
If you do not see the following in the console: login: prompt, but instead the screen remains on the GRUB menu or a boot error (such as initramfs 提示符)或大量连续的内核调用栈输出,说明系统未能完成正常启动。
Roll Back to a Working Kernel#
If the VPS fails to boot after a kernel upgrade or module compilation, such as enabling BBR or installing a specific virtualization driver:
- 在控制台发送重启指令( Passed 面板管理页面的 Reboot or Reset 按钮)。
- As soon as the GRUB boot screen flashes in the console, quickly press
Up/Down箭头键停止倒计时。 - Enter Advanced options for ... menu, and select the previous stable kernel version to boot.
- If the old kernel boots successfully, log in and remove the damaged kernel package or correct the update error.
Repair Filesystem Corruption#
If the system remains at (initramfs) prompt usually indicates inconsistent root-filesystem metadata caused by an unclean shutdown or interrupted write.
(initramfs) fsck -y /dev/sda1(请根据控制台屏幕中明确给出的根分区设备名替换 /dev/sda1, and after completing the repair, enter exit or reboot restart.)
6. 控制台完全无法连接时的应对机制#
In very rare cases, clicking Launch or Console displays Target Unreachable、WebSocket Disconnected or remains on a black screen without a cursor.
- 区分软故障与硬死锁:
- Check the CPU and memory usage graphs in the service panel. If usage remains at 100% and the console is completely unresponsive, the virtual machine's kernel has entered a Hard Hang.
- Do not rely only on a soft reboot inside the system; use the panel to perform Force Stop / Power Off, wait until the instance is completely shut down before running Start cold boot.
- 底层宿主机维护与迁移限制:
- Check the provider's official status page or announcements to determine whether the physical host or network switching equipment has failed.
- BandwagonHost-Specific Reminder: KiwiVM offers data center migration (Migrate), but if an instance's IP is blocked by an upstream network or flagged as abnormal, the system automatically disables the migration option. Focus first on diagnosing connectivity at the current data center rather than blindly attempting migration.
- Enable Temporary Rescue Mode:
- If severe system damage cannot be repaired through the console, use the panel's rescue mode to boot a lightweight Linux recovery system entirely in memory. Mount the original disk partitions, back up critical application data and configuration files over the network, then repair or reinstall the system.