Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Change the SSH Port on Your Server

This guide shows you how to move SSH from port 22 to another port. It needs root access, so it fits a VPS or dedicated server.

How-To Guides2 min read10 steps3 screenshots

What are SSH and ports?

SSH is a safe way to type commands on a server from your own computer. A port is like a numbered door on your server. Each service uses one door. SSH normally uses door 22. Attackers know this, so they keep knocking on it. Moving SSH to a different door cuts down on this noise. It is not full protection, so you should still use strong passwords or SSH keys.

Warning: A mistake can lock you out. Keep your current SSH window open until you test the new port in a second window. Also ask Hostvento support if your plan has an outside firewall that needs the new port opened.

Steps

  1. Pick a new port number between 1024 and 65535. For example, 2222. Do not pick a port another service uses.
  2. Log in to your server with SSH.
  3. Open the SSH settings file.
    sudo nano /etc/ssh/sshd_config
  4. Find the line #Port 22. Remove the # and change the number.
    Port 2222
    terminal-nano-port-highlighted
  5. Save the file. In nano, press Ctrl+O, Enter, then Ctrl+X.
  6. Open the new port in your firewall. A firewall is a guard that decides which doors stay open. Use the command for your system.
    sudo ufw allow 2222/tcp
    That one is for Ubuntu with UFW. On CentOS with firewalld, use sudo firewall-cmd --permanent --add-port=2222/tcp and then sudo firewall-cmd --reload.
  7. On CentOS with SELinux on, tell it about the new port.
    sudo semanage port -a -t ssh_port_t -p tcp 2222
  8. Restart SSH.
    sudo systemctl restart sshd
    On Ubuntu the service may be named ssh.
  9. Do not close your first window. Open a new window and test.
    ssh -p 2222 username@your-server-ip
  10. If it works, you may close the old window. You can later close port 22 in the firewall.

If it fails

  • Use your still-open window to undo the change.
  • Check that the firewall allows the new port.
  • Contact Hostvento support if you are locked out.

Quick recap

  • Edit /etc/ssh/sshd_config and set a new Port.
    terminal-ss
  • Open the port in the firewall first.
    terminal-netstat
  • Restart SSH and test in a new window.
  • Connect with ssh -p from now on.