How to Change the SSH Port on a Linux Server
Move SSH off port 22 the safe way — without locking yourself out and without the false sense of security that breaks the moment someone runs a port scan.
Changing the SSH port is one of the first hardening steps people read about. It's worth doing, but for the right reason: it doesn't make your server harder to attack — a port scan finds the new port in under a minute — but it silences the constant background noise of opportunistic bots hammering port 22. Your logs become readable again, fail2ban has fewer false alarms, and network bandwidth used by attack traffic drops sharply. This guide walks through the change without the classic lockout.
This is not a security control by itself
Port obscurity stops automated bots, not attackers. Always pair this change with key-based auth, fail2ban, and a firewall that only allows trusted source IPs to your admin port. The combination is solid; the port change alone is not.
Before you start
- Working SSH access right now — both as root or via
sudo. - A second terminal you can use to test the new port without losing the first session.
- A port number you'll remember. Pick something between 1024 and 65535 that isn't already used on the system. Common choices:
2222,22222, or a memorable random number like48329. - Knowledge of your firewall: UFW, firewalld, or our cloud-firewall layer.
1Pick a port and check nothing is using it
Avoid ports that already serve traffic on your server. The quickest sanity check is to look at every listening port and pick one not in the list.
# Show every TCP port currently listening, with the owning process sudo ss -tlnp # Or grep for a specific candidate port to confirm it's free sudo ss -tln | grep :2222 || echo "2222 is free"
Don't pick a registered service port
Avoid well-known ports like 3306 (MySQL), 5432 (Postgres), 6379 (Redis), 27017 (MongoDB), or anything in the 0-1023 range without a clear reason. SELinux on RHEL-family distros also restricts which ports sshd can bind to — we handle that in step 4.
2Open the new port in your firewall FIRST
This is the step people skip and regret. If you change the SSH config before opening the new port in the firewall, you reload sshd, and your next connection is refused. Always open first, change second.
# Allow the new port BEFORE making any sshd changes sudo ufw allow 2222/tcp comment "ssh (new port)" sudo ufw status numbered
sudo firewall-cmd --permanent --add-port=2222/tcp sudo firewall-cmd --reload sudo firewall-cmd --list-ports
Don't close port 22 yet
Leave the old SSH port open in the firewall until you've confirmed the new one works end-to-end. We close port 22 in step 6, after testing.
3Edit the SSH daemon configuration
The cleanest approach is a drop-in file in /etc/ssh/sshd_config.d/ — the main sshd_config stays untouched and your override survives package upgrades cleanly.
sudo nano /etc/ssh/sshd_config.d/10-port.conf
# Listen on the new port. You can list multiple Port lines to listen on # both old and new at once while you transition. Port 2222 Port 22
Listing both ports keeps your existing session safe: SSH binds to both during the transition, and you remove the old line after verifying the new one works.
4SELinux: tell it the new port is okay (RHEL family only)
AlmaLinux, Rocky, and other RHEL-family distros run SELinux in enforcing mode. Out of the box, sshd is only allowed to bind to port 22. Skip this step on a RHEL host and sshd will refuse to start on the new port with a permission-denied error.
# Install the policy tool if needed sudo dnf install -y policycoreutils-python-utils # Permit sshd to bind to TCP/2222 sudo semanage port -a -t ssh_port_t -p tcp 2222 # Verify sudo semanage port -l | grep ssh_port_t
Ubuntu and Debian users with AppArmor: no change is needed — the default sshd profile allows any port.
5Validate, reload, and TEST from a second terminal
# 1. Make sure the config has no typos sudo sshd -t # 2. Reload (NOT restart — reload keeps your existing session) sudo systemctl reload ssh # Debian / Ubuntu sudo systemctl reload sshd # AlmaLinux / Rocky # 3. Confirm sshd is listening on both ports sudo ss -tlnp | grep sshd
Test in a NEW terminal before closing this one
Open a brand-new terminal window and run ssh -p 2222 [email protected]. If the login succeeds, you're safe to continue. If it fails, you still have the original session open to undo the change. Never close that window until the new port works.
6Remove port 22 once the new port is confirmed working
After verifying you can log in on the new port, edit the drop-in file and remove the Port 22 line. Then close port 22 in the firewall.
# Edit the drop-in and remove "Port 22" sudo nano /etc/ssh/sshd_config.d/10-port.conf # Reload SSH sudo systemctl reload ssh # Close port 22 in the firewall sudo ufw delete allow OpenSSH # Debian / Ubuntu sudo ufw delete allow 22/tcp # Or, on firewalld: sudo firewall-cmd --permanent --remove-service=ssh sudo firewall-cmd --reload
7Tell your laptop the new port
Add the new port to your SSH client config so you never have to type -p 2222 again.
Host prod-web
HostName your.vps.ip
User deploy
Port 2222
IdentityFile ~/.ssh/id_ed25519
Now ssh prod-web hits the new port automatically. Update any deployment scripts, CI runners, and Ansible inventories that reference the old port.
If you do get locked out
Every VPS-SERVER HOST plan includes an out-of-band console in the client area that connects to the hypervisor, not the guest network. If a typo in your sshd_config or a missed firewall rule shuts you out, you can still log in there to fix it.
- Sign in to your client area.
- Open My Services → pick the VPS → VNC Console.
- Log in at the console prompt (using the root password from your welcome email if you didn't change it).
- Roll back the
sshd_configchange, re-open port 22 in the firewall, reload sshd.
Frequently asked questions
Does changing the port actually improve security?
fail2ban for actual security.Can I have SSH listen on multiple ports at the same time?
Port lines to the SSH config. This is actually the safest way to migrate: bind to both old and new ports, verify clients on the new one, then remove the old line.Why does sshd fail to start with "Permission denied" on RHEL?
sudo semanage port -a -t ssh_port_t -p tcp 2222. See step 4.Should I pick a really high port like 64321?
sshd were ever offline. This rarely matters on a single-admin VPS, but is worth knowing for multi-tenant systems.Can VPS-SERVER HOST set this up for me?
Want managed hardening?
Our managed VPS plans include first-day hardening: SSH keys, fail2ban, firewall, and unattended security updates — configured by our engineers before you log in.
Deploy a VPS Open a Ticket