All Products
Search
Document Center

Bastionhost:Troubleshoot client connection issues

Last Updated:Jun 21, 2026

This topic provides answers to some frequently asked questions about connections between client tools and bastion hosts.

I cannot use my client to access my bastion host by using the public endpoint of the bastion host. How do I troubleshoot the issue?

You can perform the following operations to troubleshoot this issue:

  • Check whether the configurations of your bastion host are correct.

    • On your client, run the ping command to test connectivity to Bastionhost. If the connection fails, log on to the Bastionhost console. On the instance details page, in the Network section, ensure that the Public Access switch is enabled (green) and take note of the public endpoint.

    • On your client, run the telnet command to test connectivity on the Bastionhost ports: 60022, 63389, and 443. If the connection fails, verify that the ports are configured correctly. For more information, see Configure a Bastionhost.

    • If you configured a whitelist, access to the Bastionhost public endpoint is restricted. Ensure that the public IP address of your local machine is on the whitelist. For more information, see Configure a Bastionhost.

  • Check whether Cloud Firewall is used. Check whether Cloud Firewall is used to protect your bastion host and whether access control policies are configured to block the access of your bastion host. For more information, see Configure access control policies in scenarios in which Cloud Firewall is deployed together with Bastionhost.

  • Check whether a firewall is enabled for your client. You can use another client to access your bastion host. If the client can access the bastion host, a firewall is enabled for your client.

  • Check whether your bastion host resides outside China. If your bastion host resides outside China, the access traffic that is destined for your bastion host may be blocked. We recommend that you connect your client and the bastion host by using a VPN or a leased line.

    To test if your Bastionhost instance is working correctly, purchase an ECS instance in the same region and try to access Bastionhost from the new instance. For more information about ECS, see What is ECS?.

I cannot use my client to access my bastion host by using the private endpoint of the bastion host. How do I troubleshoot the issue?

Check whether the virtual private cloud (VPC) in which your client resides and the VPC in which your bastion host resides are connected by using a VPN or a leased line.

  • If the VPCs are connected by using a VPN or a leased line, use your client to access another server that resides in the same VPC as the bastion host. If the server can be accessed, exceptions may occur on your bastion host.

  • If the VPCs are connected by using a VPN or a leased line, Internet access is normal, but access over VPCs is slow, the value of the maximum transmission unit (MTU) for the VPN may be excessively large. Specify a smaller value and try again. If the access is slow, the hosts on which you can use your bastion host to perform O&M operations may not be displayed.

What is the maximum validity period of an O&M token?

  • The maximum validity period that you can configure for an O&M token is 8 hours. You can also allow O&M engineers to renew O&M tokens and the number of times to renew an O&M token. The maximum number of times to renew an O&M token is 20. Each renewal increases 1 hour of validity period. For more information about how to configure the validity period of O&M tokens and renew O&M tokens, see Configure O&M settings.

  • If you enable O&M review for databases, the validity period of an O&M token that is approved by a Bastionhost administrator takes effect. For more information about O&M approvals, see Review an O&M application.