Updated: 28 September 2026 · Applies to: OpenSSH 8.7 to 10.2 on Ubuntu 24.04 and 26.04, Debian 13, AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10
SSH (Secure Shell) is the encrypted protocol used to log in to Linux servers and copy files with scp and sftp. The default SSH port is TCP 22, registered with IANA for SSH. Clients use port 22 unless you tell them otherwise:
ssh root@203.0.113.10 # port 22 ssh -p 2222 root@203.0.113.10 # another port
To avoid typing the port every time, add the server to ~/.ssh/config on your computer:
Host myserver
HostName 203.0.113.10
Port 2222
User root
Then connect with ssh myserver.
Should you change it?
A different port cuts down the automated login attempts that fill your logs, but it is not real protection: port scanners find SSH on any port. Key-based login, disabling password login, and a tool such as fail2ban matter more. If you do change the port, follow the steps below so you do not lock yourself out.
Change the SSH port safely
- Stay logged in during the whole change, and test in a second terminal. Your open session keeps working even if the new port fails.
- Pick a port that nothing else uses, for example 2222 (check with
ss -ltn 'sport = :2222', which should list nothing). - Create a small settings file that keeps port 22 for now and adds the new one:
printf 'Port 22\nPort 2222\n' > /etc/ssh/sshd_config.d/10-port.conf
Current distributions read files in/etc/ssh/sshd_config.d/, and a separate file survives package updates. If yoursshd_configalready has an uncommentedPortline, remove it. - Check the settings:
sshd -tprints nothing when they are valid. - Open the new port in the firewall:
firewall-cmd --permanent --add-port=2222/tcp && firewall-cmd --reload # firewalld ufw allow 2222/tcp # UFW
With CSF (common on cPanel servers), add the port toTCP_INin/etc/csf/csf.confand runcsf -r. - On AlmaLinux, Rocky Linux and RHEL, allow the port in SELinux (from the
policycoreutils-python-utilspackage):semanage port -a -t ssh_port_t -p tcp 2222
- Apply the change. The command depends on the system:
systemctl restart sshd # AlmaLinux, Rocky Linux, RHEL systemctl restart ssh # Debian 13 systemctl daemon-reload && systemctl restart ssh.socket # Ubuntu 24.04 and 26.04
Ubuntu starts SSH through a systemd socket, so restartingssh.servicealone does not change the port there. - Check that both ports listen:
ss -ltnp | grep -E ':(22|2222) '. On Ubuntu the process shown issystemd, which is normal with socket activation. - From a second terminal, log in on the new port:
ssh -p 2222 root@SERVER-IP - When that works, delete the
Port 22line from10-port.conf, repeat steps 4 and 7, and close port 22 in the firewall.
Common problems
- "Connection refused" on the new port: the service was not restarted the right way (on Ubuntu, restart
ssh.socket), or SELinux blocked the port. Checkjournalctl -u sshdorjournalctl -u ssh. - "Connection timed out": a firewall blocks the port, either on the server or in front of it.
- Locked out: log in through the server's console (IPMI on a dedicated server, or the console in your VPS panel) and undo the change. Ucartz customers can also open a support ticket.
If our engineers look after your server, tell support the new port so their access keeps working.
Official documentation: sshd_config manual (OpenSSH).
Ucartz services for this topic
- KVM VPS hosting: NVMe SSD and full root access, with Free Basic Managed Support.
- Unmanaged dedicated servers: full root access and free IPMI KVM, with Free Basic Managed Support.
- Linux server management: hardening, patching, monitoring and automation for Ubuntu, Debian, RHEL and AlmaLinux.
