> ## Content Index
> Fetch the complete content index at: https://techbookshelf.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# How to Change the SSH Port on Linux for Better Security
- URL: https://techbookshelf.com/change-ssh-port-linux/
- Published: 2026-09-29T18:00:00.000Z
- Updated: 2026-09-29T18:11:12.000Z
- Description: This guide explains how to change the SSH port on Linux to improve security and reduce automated attack attempts.
- Author: Md Astafar Hossain
- Tags: Linux, Security, SSH, Server Administration

Changing the SSH port on Linux is a common security practice to reduce automated attack attempts and improve server security. This guide covers the rationale, port selection considerations, detailed implementation steps, and how to update monitoring tools accordingly.

## Why Change the Default SSH Port?

SSH servers listen on port 22 by default, making it a frequent target for automated brute-force attacks. Attackers use scripts that scan port 22 continuously, increasing noise and risk.

Changing the SSH port reduces exposure to these automated scans because many tools only check default or commonly used alternate ports. However, this is not a standalone security measure.

This change is one layer in a defense-in-depth approach, lowering the attack surface visible to opportunistic attackers and bots, and complementing strong authentication and monitoring.

## Choosing the Right Port Number: Best Practices and Pitfalls

Selecting an SSH port requires balancing obscurity with operational needs.

- Avoid well-known ports and common alternates attackers often scan (e.g., 2222, 2200, 22222). These can attract more attention than truly obscure ports.
- Do not select ports below 1024, as these are reserved for system services and require root privileges to bind. Ports between 1024 and 65535 are preferred.
- Check firewall and corporate policies to ensure the chosen port is allowed and does not conflict with other services.

| Port Number | Comments                   | Pros                    | Cons                                        |
| ----------- | -------------------------- | ----------------------- | ------------------------------------------- |
| 22          | Default SSH port           | Universal compatibility | High attack volume                          |
| 2222        | Common alternate port      | Easy to remember        | Frequently scanned by attackers             |
| 22000       | High number, less common   | Less likely scanned     | May require firewall updates                |
| 49152       | Dynamic/private port range | Obscure and flexible    | Potential conflicts with ephemeral services |

Example firewall rules:

```
# Allow SSH on port 22000 (iptables)
iptables -A INPUT -p tcp --dport 22000 -j ACCEPT

# Allow SSH on port 22000 (ufw)
ufw allow 22000/tcp

# Allow SSH on port 22000 (firewalld)
firewall-cmd --permanent --add-port=22000/tcp
firewall-cmd --reload

```

## Step-by-Step: How to Change the SSH Port on Popular Linux Distributions

![Step-by-Step: How to Change the SSH Port on Popular Linux Distributions – how to change SSH port on Linux](https://techbookshelf.com/content/images/2026/09/change-ssh-port-linux-2.webp)

1. **Adjust firewall rules:** Open the new port and close the old one.
2. For Ubuntu 22.04 using `ufw`:
3. For CentOS 8 using `firewalld`:
4. **Restart the SSH daemon safely:** Before closing existing sessions, restart SSH and test connectivity on the new port to avoid lockout.

```
sudo systemctl restart sshd
```

```
sudo firewall-cmd --permanent --add-port=22000/tcp
sudo firewall-cmd --permanent --remove-port=22/tcp
sudo firewall-cmd --reload
```

```
sudo ufw allow 22000/tcp
sudo ufw delete allow 22/tcp
```

**Test SSH connectivity on the new port:**

```
ssh -p 22000 user@your-server-ip
```

Confirm successful login before ending existing sessions on port 22.

**Edit the SSH configuration file:**

```
sudo nano /etc/ssh/sshd_config
```

Find the `Port` directive. It is often commented out as `#Port 22`. Uncomment it and set your desired port, for example:

```
Port 22000
```

Note: Changing the port here is necessary but not sufficient; firewall and monitoring configurations must also be updated.

**Back up the SSH configuration:**

```
sudo cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak
```

## Integrating Port Changes with Monitoring and Security Tools

After changing the SSH port, update security tools to maintain effective protection.

- **Fail2ban:** Edit `/etc/fail2ban/jail.local` to specify the new port under the `[sshd]` section:

```
[sshd]
enabled = true
port = 22000
filter = sshd
logpath = /var/log/auth.log
maxretry = 5

```

- **Monitoring dashboards and alert rules:** Update any port references to avoid missing SSH-related events.
- **Logging:** SSH logs remain unchanged by port, but verify logs are generated for connections on the new port.

Fail2ban and similar tools rely on correct port configuration; otherwise, they may miss repeated unauthorized attempts.

## When Changing SSH Port Is Not Enough: Complementary Security Measures

Changing the SSH port mainly deters automated scans and opportunistic attacks. It does not prevent targeted attacks or exploitation of SSH vulnerabilities.

![When Changing SSH Port Is Not Enough: Complementary Security Measures – how to change SSH port on Linux](https://techbookshelf.com/content/images/2026/09/change-ssh-port-linux-3.webp)

- Use strong authentication methods such as public key authentication combined with multi-factor authentication.
- [Disable root login](https://techbookshelf.com/p/ccf249b6-1154-4679-bf13-59f418cbffd2/) and password authentication over SSH to reduce attack vectors.
- Consider advanced protections like SSH certificates and restricting SSH access through VPNs for sensitive systems.

Systems relying solely on port changes remain more vulnerable than those implementing layered security, including key-based authentication and intrusion prevention.

## Limitations of Changing the SSH Port

This measure primarily reduces exposure to automated scans and opportunistic attackers. It does not block targeted attacks or vulnerabilities in SSH itself.

Changing the port should be part of a comprehensive security strategy combining strong authentication, monitoring, and network controls.

## Frequently asked questions

### Will changing the SSH port stop all unauthorized access attempts?

No. Changing the port reduces automated attacks on the default port but does not prevent targeted or credential-based intrusions.

### How do I choose a secure but accessible port number for SSH?

Choose a port above 1024 that is not commonly used by other services or frequently scanned by attackers. Verify firewall and policy compatibility.

### What should I do if I lose SSH access after changing the port?

Access the server via console or out-of-band management to revert changes or check firewall and SSH daemon settings.

### Can changing the SSH port interfere with automated deployment or backup scripts?

Yes. Update scripts and configurations to specify the new port explicitly to avoid connection failures.

## Related reading

- [How to Check Your iPhone’s App Privacy Report](https://techbookshelf.com/p/3ca27457-e026-45fe-8138-48a3fab07e55/)
- [How to Set Up Private DNS on Android for Better Privacy](https://techbookshelf.com/p/7b32089b-a11f-4af7-ba83-cf545cac9542/)
- [How to Install Fail2Ban on Linux](https://techbookshelf.com/p/b9ebbe5f-62f5-48a9-8a90-178149af7f06/)