Hi,
I have this same issue on 2 X 3650C switches.
The config for the VTY lines is identical across all my devices, very basic, using local login and a username / password with privilege 15 access.
I can ping the management address and run SNMP commands to the devices. But since upgrading the IOS 99% of the time I can't get a SSH connections going. I know there are no ACL configured on the switches, and it only happens on two that are running 15.1(1). PAcket capture shows that the switch never replies to the first SYN packet of the TCP stream.
Strange this is that if I reboot the switch SSH will work once. but after that it stops and I can't connect again. I have looked using SNMP and all the VTY lines are free. The real issue is that these switches are in a high bio security building so getting to them is a nightmare. And tonight they jsut wont let me in

all I want to do is log in and reboot them back to IOS 12 which was working fine.
Just strange the intermittent nature of it, definitely not duplicate IP's.