Connection reset by peer

What “Connection reset by peer” usually means

When PuTTY reports Connection reset, the client has already attempted a network or protocol step and failed before a normal interactive shell is available. This guide explains what the message usually means on Windows clients, which local settings to verify first, and when the problem is almost certainly on the server, firewall, or DNS path rather than inside the PuTTY GUI.

The remote side (or a middlebox pretending to be it) tore down the TCP session with a reset. This can happen during handshake or mid-session.

Independent resource: Putty.info is educational only and is not affiliated with the official PuTTY project. Compare symptoms against the official documentation for your installed version.

Symptoms you will see

Operators usually notice this failure in one of a few repeatable ways. Capture the exact dialog text, the hostname and port from the Session panel, and whether the failure happens before or after a username prompt—those details decide which checklist below applies.

  • Sudden disconnect with reset language.
  • May occur right after TCP connect when a firewall dislikes the traffic pattern.

Likely causes ranked by frequency

Several independent conditions can produce the same client-facing wording. Work from the outside in: reachability first, protocol selection second, authentication third. Changing key files will not fix a TCP refusal, and opening a wider firewall will not fix a rejected public key.

  • sshd MaxStartups or connection throttling.
  • IPS/WAF devices resetting SSH.
  • Server process crash during handshake.
  • Idle middlebox policies—though idle drops more often look like aborts/timeouts.

Step-by-step client checks

Use this ordered checklist on a workstation you control. Prefer saved sessions so Host Name, Port, and Connection type stay consistent while you isolate one variable at a time.

  1. Retry once; if immediate and consistent, capture whether a banner appeared.
  2. Try from another network path to detect IPS on one egress.
  3. Review Connection → SSH algorithm settings only if policy requires—do not randomly weaken crypto.
  4. Ask admins for sshd and firewall logs covering your source IP.
  5. Ensure you are not reconnecting in a tight loop that trips anti-abuse systems.
  6. Confirm MTU/VPN fragmentation issues if resets happen after large banner exchange.

Do not paste private keys, passphrases, or production passwords into Putty.info tools or contact forms. Diagnose locally with PuTTY, Plink, PSCP, or PSFTP from an official install.

When it is a server or network issue

Investigate crashes, forced disconnect Match rules, and network appliances. Client-side key regeneration almost never fixes resets.

If TCP connects from another network path but fails from yours, involve the network team with traceroute/path evidence rather than repeatedly regenerating keys. If authentication fails after a banner appears, collect the server sshd logs for the same timestamp and username—client-side retries alone rarely reveal AccountLocked, Match blocks, or AllowUsers denials.

Sources

  • PuTTY Documentation — Simon Tatham / PuTTY Project · verified 2026-09-03 04:12:04
  • PuTTY FAQ — Simon Tatham / PuTTY Project · verified 2026-09-03 04:12:04