Updated: 28 September 2026 · Applies to: OpenSSH 8.7 to 10.2 on Ubuntu 24.04 and 26.04, Debian 13, AlmaLinux and Rocky Linux 9 and 10, RHEL 9 and 10

SSH (Secure Shell) is the encrypted protocol used to log in to Linux servers and copy files with scp and sftp. The default SSH port is TCP 22, registered with IANA for SSH. Clients use port 22 unless you tell them otherwise:

ssh root@203.0.113.10             # port 22
ssh -p 2222 root@203.0.113.10     # another port

To avoid typing the port every time, add the server to ~/.ssh/config on your computer:

Host myserver
    HostName 203.0.113.10
    Port 2222
    User root

Then connect with ssh myserver.

Should you change it?

A different port cuts down the automated login attempts that fill your logs, but it is not real protection: port scanners find SSH on any port. Key-based login, disabling password login, and a tool such as fail2ban matter more. If you do change the port, follow the steps below so you do not lock yourself out.

Change the SSH port safely

  1. Stay logged in during the whole change, and test in a second terminal. Your open session keeps working even if the new port fails.
  2. Pick a port that nothing else uses, for example 2222 (check with ss -ltn 'sport = :2222', which should list nothing).
  3. Create a small settings file that keeps port 22 for now and adds the new one:
    printf 'Port 22\nPort 2222\n' > /etc/ssh/sshd_config.d/10-port.conf
    Current distributions read files in /etc/ssh/sshd_config.d/, and a separate file survives package updates. If your sshd_config already has an uncommented Port line, remove it.
  4. Check the settings: sshd -t prints nothing when they are valid.
  5. Open the new port in the firewall:
    firewall-cmd --permanent --add-port=2222/tcp && firewall-cmd --reload    # firewalld
    ufw allow 2222/tcp                                                      # UFW
    With CSF (common on cPanel servers), add the port to TCP_IN in /etc/csf/csf.conf and run csf -r.
  6. On AlmaLinux, Rocky Linux and RHEL, allow the port in SELinux (from the policycoreutils-python-utils package):
    semanage port -a -t ssh_port_t -p tcp 2222
  7. Apply the change. The command depends on the system:
    systemctl restart sshd                                   # AlmaLinux, Rocky Linux, RHEL
    systemctl restart ssh                                    # Debian 13
    systemctl daemon-reload && systemctl restart ssh.socket  # Ubuntu 24.04 and 26.04
    Ubuntu starts SSH through a systemd socket, so restarting ssh.service alone does not change the port there.
  8. Check that both ports listen: ss -ltnp | grep -E ':(22|2222) '. On Ubuntu the process shown is systemd, which is normal with socket activation.
  9. From a second terminal, log in on the new port: ssh -p 2222 root@SERVER-IP
  10. When that works, delete the Port 22 line from 10-port.conf, repeat steps 4 and 7, and close port 22 in the firewall.

Common problems

  • "Connection refused" on the new port: the service was not restarted the right way (on Ubuntu, restart ssh.socket), or SELinux blocked the port. Check journalctl -u sshd or journalctl -u ssh.
  • "Connection timed out": a firewall blocks the port, either on the server or in front of it.
  • Locked out: log in through the server's console (IPMI on a dedicated server, or the console in your VPS panel) and undo the change. Ucartz customers can also open a support ticket.

If our engineers look after your server, tell support the new port so their access keeps working.

Official documentation: sshd_config manual (OpenSSH).

Ucartz services for this topic

Was this answer helpful? 0 Users Found This Useful (0 Votes)