Linux, Web Server & Database
Change SSH Port
Move SSH off the default port 22 to cut down on automated scanning and brute-force noise.
The Problem
Your server's SSH is sitting on the default port 22, which is scanned constantly by automated bots across the entire internet, filling your logs with brute-force attempts even if none of them actually succeed.
About this problem
Moving SSH to a non-standard port doesn't make a server unbreakable, but it dramatically cuts down the sheer volume of automated scanning noise, since most mass-scanning bots only check the default port rather than probing the full range — it's considered a layer of mitigation, not a replacement for proper authentication security.
This is commonly done alongside other hardening steps like disabling root login and switching to key-based authentication.
What's Included
- Choosing a sensible non-standard port that doesn't conflict with other services
- Updating the SSH daemon configuration and any relevant firewall rules together
- Testing the new port thoroughly before closing the old one
- Documentation of the new port for your own reference going forward
What's NOT Included
- Broader SSH hardening beyond the port change (see the full hardening service)
- Changing ports for other services beyond SSH
- Setting up port-knocking or more advanced obfuscation (can be scoped separately)
How It Works
- Choose a new port in a sensible, uncommonly-scanned range, avoiding other services already in use.
- Update the Port directive in sshd_config and add a firewall rule allowing the new port.
- Restart the SSH service without closing the current session.
- Test connecting on the new port from a fresh terminal before removing access on the old port.
- Remove the old port's firewall rule once the new one is confirmed working reliably.
In practice: you buy the service, send over whatever access or details the job needs, I investigate and do the work, and you confirm it's resolved before we call it done.
Frequently Asked Questions
- Does changing the SSH port make my server secure?
- It reduces automated scanning noise significantly, but it's not a substitute for proper authentication security like key-based login and disabled root access — think of it as one layer among several.
- Will changing the SSH port break anything?
- Only if something isn't updated to match — any saved connection profiles, scripts, or firewall rules referencing the old port need updating alongside the server-side change.
- Can attackers still find my new SSH port?
- A determined, targeted attacker running a full port scan can find any open port eventually, but this stops the constant, low-effort automated scanning that targets port 22 specifically.
- What port should I move SSH to?
- Any unused high port works, as long as it doesn't conflict with another service you're running — there's no single 'correct' port, just one that isn't already in use.
- Do I need to update my firewall when I change the SSH port?
- Yes — the new port needs an explicit allow rule, and forgetting this step before restarting SSH is one of the most common ways people lock themselves out.
- How do I connect after the SSH port has changed?
- Most SSH clients need the port specified explicitly, for example ssh -p 2222 user@yourserver, or configured as a default in your SSH config file for that host.