Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

You can administer a private Amazon EC2 instance with AWS Systems Manager Session Manager while leaving inbound SSH port 22 closed. The SSM Agent on the instance initiates its connection to Systems Manager, so the instance does not need an inbound SSH rule for a Session Manager shell. It still needs outbound HTTPS access to the required AWS endpoints—through internet egress or private VPC endpoints.

How Session Manager connects to a private instance

Session Manager provides interactive access to Systems Manager managed nodes, including EC2 instances. You can start a shell from the AWS console or use the AWS CLI. On the instance, SSM Agent initiates communication with the Systems Manager service; the operator does not connect directly to the instance over SSH. AWS describes the model this way: “SSM Agent initiates all connections to the Systems Manager service in the cloud.” (AWS Systems Manager VPC endpoint guidance.)

That distinction lets you keep inbound port 22 closed for Session Manager access. It does not make the instance network-independent: SSM Agent must still reach the regional Systems Manager endpoints over HTTPS. AWS identifies outbound port 443 connectivity as a prerequisite when using service endpoints over internet egress.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What the instance and operator need

Supported operating system and running SSM Agent

The EC2 instance must use an operating system supported by Session Manager, and SSM Agent must be installed, running, and able to reach the service. AWS lists the regional ssm, ssmmessages, and ec2messages endpoints among the prerequisites. Check the current requirements for your Region and operating system before deployment: Session Manager prerequisites.

#1 Best Overall

Some features require specific minimum agent versions. AWS specifies SSM Agent 3.0.222.0 or later for port forwarding or SSH sessions, and 3.0.284.0 or later for streaming session data to CloudWatch Logs. These are feature requirements, not a universal minimum for every Session Manager shell. AWS recommends automating agent updates because newer features and changes can require a newer version.

An instance role for Systems Manager

Attach an IAM role to the EC2 instance so SSM Agent can communicate with Systems Manager. AWS’s EC2 connection guidance identifies a role with the AmazonSSMManagedInstanceCore policy as an example prerequisite. If your design sends logs to S3 or CloudWatch Logs, the role and related policies may also need permissions for those destinations. Use least privilege and validate custom policies against current AWS permissions guidance.

See Connect to your Linux instance using Session Manager and Systems Manager instance permissions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Operator permissions

The instance role and the operator’s IAM permissions serve different purposes. The role lets the node communicate with AWS; operator policies determine who can start a session and which managed nodes they can reach. Scope permissions to the intended nodes and session types. Decide separately whether operators may start general shell sessions, use specific session documents, or create SSH tunnels and port-forwarding sessions. AWS documents IAM as the centralized way to grant and revoke Session Manager access in its Session Manager overview.

Choose a network path for a private subnet

The instance needs a path to Systems Manager whether or not it has a public IP. Choose between outbound internet connectivity and private interface endpoints; the latter is the option when the instance has no internet egress.

Network design What the instance needs What to configure
Internet egress Outbound HTTPS access to the required regional Systems Manager endpoints. Allow the outbound path to the regional ssm, ssmmessages, and ec2messages endpoints. AWS lists these in its Session Manager prerequisites.
PrivateLink interface endpoints Private network reachability to the configured Systems Manager interface endpoints over HTTPS. Create the required VPC endpoints, allow inbound TCP 443 in each endpoint’s security group from the managed instance’s private subnet, and verify DNS and endpoint policies. This Systems Manager path does not require internet access, an internet gateway, or a NAT device. See Create VPC endpoints for Systems Manager and AWS PrivateLink interface endpoints.

With interface endpoints, also check how the VPC resolves endpoint names. If you use custom DNS, configure the required forwarding to Amazon DNS. Endpoint policies and security groups must permit the intended traffic; creating endpoints alone does not guarantee connectivity.

Account for optional services

Additional features can introduce additional network dependencies. If session preferences send data to S3 or CloudWatch Logs, provide the appropriate endpoint and permissions when the instance has no internet egress. KMS encryption and other optional features can also require access to additional AWS services. AWS notes these dependencies in its Session Manager troubleshooting guidance.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set access and audit expectations before enabling tunnels

Choose who can access which nodes

Use IAM policies to scope operators to the intended managed nodes and session actions. Avoid treating permission to start a session as equivalent to permission to perform every available session action. Review whether your users need ordinary interactive shells, specific session documents, SSH-over-Session-Manager, or port forwarding. AWS explains the SSH and tunnel configuration in Enable SSH connections through Session Manager.

Decide what session data you need to retain

Session Manager can send supported session data to an S3 bucket or CloudWatch Logs log group, with KMS encryption options. Configure the destination, encryption, and required permissions, and make sure a private instance can reach the logging service if it has no internet egress. The Session Manager logging guidance describes the supported options.

Do not assume every session produces a readable transcript. AWS says Session Manager cannot log session contents for SSH and port-forwarding sessions: SSH encrypts the data inside the TLS connection, and Session Manager tunnels that traffic rather than interpreting it. If command-level session records are a requirement, account for this limitation when choosing the session type.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Implementation sequence

  1. Confirm the node is ready. Verify that its operating system is supported, SSM Agent is installed and running, and the agent version meets the requirements for the features you intend to use. Check the current Session Manager prerequisites.
  2. Attach the instance role. Give the EC2 instance the required Systems Manager permissions, using an appropriate managed or custom policy. Add only the destination permissions needed if you plan to send logs to S3 or CloudWatch Logs. See Systems Manager instance permissions.
  3. Provide the network path. Either allow outbound HTTPS to the required regional endpoints or configure private interface endpoints. For endpoints, verify TCP 443 access from the instance subnet, DNS resolution, and endpoint policies. Add relevant service endpoints if logging, encryption, or another selected feature requires them. Follow AWS VPC endpoint guidance.
  4. Scope operator access. Grant session permissions only to the intended operators and managed nodes, and decide which session types they may use.
  5. Configure logging deliberately. Set up S3 or CloudWatch Logs destinations and KMS options if appropriate, then validate the needed IAM permissions and network access. Do not rely on Session Manager content logging for SSH or port-forwarding tunnels.
  6. Start a session and validate the design. Use the Systems Manager or EC2 console, or the AWS CLI, to open a session. Confirm that the node appears online and that the intended operator can reach only the authorized node and session type.

Troubleshoot an unavailable instance or failed session

Work from the node outward, then check optional features:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Node is missing or offline: Confirm it is registered as a Systems Manager managed node, its instance role has the needed permissions, and SSM Agent is running and sufficiently current. AWS’s troubleshooting guide covers common causes.
  • Agent cannot connect: Verify outbound HTTPS reachability to the required regional endpoints. For PrivateLink, inspect endpoint state, endpoint security groups, DNS resolution, and endpoint policies.
  • Session opens but logging fails: Check that the S3 bucket or CloudWatch log group exists, permissions allow the requested operation, and the private subnet has a path to the logging service.
  • A feature is unavailable: Check the agent version against that feature’s current requirements and verify any required local AWS CLI components for the connection method.

Choose the session type with its trade-offs in mind

Access pattern Inbound port 22 on the instance Content logging through Session Manager Key consideration
Interactive Session Manager shell Not required Supported session data can be sent to S3 or CloudWatch Logs, subject to configuration. Requires a managed node, suitable IAM permissions, and outbound reachability to Systems Manager.
SSH over Session Manager Not required for the tunnel to the instance Session Manager cannot log the tunneled SSH content. Requires the SSH session configuration and an agent version meeting the applicable feature requirement.
Port forwarding through Session Manager Not required for the tunnel to the instance Session Manager cannot log forwarded session content. Requires a compatible agent and the relevant port-forwarding setup.

All three patterns avoid opening inbound SSH on the managed instance for the Session Manager path. They do not remove the need to secure IAM access or provide the network connectivity required by SSM Agent.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.