SSH Port 22: Connecting to Servers on the Default or a Custom Port
When an SSH connection fails, it’s easy to jump straight to authentication. But first, check the port: SSH normally uses TCP port 22 , and a server configured for another port won’t respond to a client trying the default. The client and server need to agree on the port. Here’s how to connect, save a custom port, and check whether the network path is open. The default: TCP port 22 If the server…
When attempting to establish an SSH connection and encountering difficulties, it is advisable to begin by inspecting the port settings. By default, SSH operates on TCP port 22, and if a server is configured to use a different port, the client will not be able to establish a connection if it is set to connect on the default port. Both client and server must agree on the port number. Here are some steps to verify and adjust the port settings for SSH connections:
1. Default Port Usage: If the SSH server is using its default configuration, you can connect without explicitly specifying the port. Simply use the following command: `ssh user@example.com`. Remember, SSH utilizes TCP, not UDP, and port 22 is merely a convention, not a mandatory requirement. A server can be configured to listen on any TCP port, such as 2222, without compromising the security of the connection.
2. Specifying a Custom Port: If the SSH server is listening on a different port, you must specify it when establishing the connection. For example, to connect to a server listening on port 2222, use the following command: `ssh -p 2222 user@example.com`. Note that this applies to SSH, SFTP, and SCP commands. However, for SCP, the correct command is `scp -P 2222 report.txt user@example.com:/tmp/`.
3. Using SSH Configuration Files: If you frequently connect to the same server with a custom port, you can simplify the process by adding the server details to your SSH configuration file located at `~/.ssh/config`. Here is an example entry for a server named "myserver" listening on port 2222:
```
Host myserver
HostName example.com
User deploy
Port 2222
```
With this configuration in place, you can connect to the server using the alias `ssh myserver`, which will automatically apply the specified port settings.
4. Verifying Port Reachability: To ensure that the SSH port is reachable from your machine, you can use a network testing tool like `nc` (netcat) on Linux or macOS, or PowerShell on Windows. For example, on Linux or macOS, use the following command: `nc -zv example.com 22`. Replace `22` with the actual port number if it has been changed.
Similarly, on Windows systems, you can use the PowerShell command `Test-NetConnection -ComputerName example.com -Port 22`. Remember to use the correct port number specified by the server administrator.
5. Checking Firewall and Network Rules: A connection refusal indicates that the destination actively rejected the connection, likely because no service is listening on that port. A timeout, on the other hand, suggests that there was no response, which could be due to various reasons such as a firewall blocking the traffic, routing issues, incorrect network address, or cloud network rules. It is essential to check the server's listening port and any firewall or network rules that may be affecting the connection.
6. Changing SSH Port: If you decide to change the SSH port on the server, keep in mind that this is a server-side configuration change. Even though using a non-default port may reduce the volume of routine scanning attempts in authentication logs, it does not enhance the overall security of the SSH connection. For the changes to take effect, the server's SSH daemon configuration must be updated to listen on the new port, and the firewall or network rules must allow traffic on that port.
Additionally, clients must be updated to use the new port when connecting to the server. If not done correctly, you may find yourself locked out of the server due to the port change.
7. Security Best Practices: While changing the SSH port can make routine scanning less conspicuous, it is not a substitute for other security measures. Always ensure that strong authentication mechanisms are in place, keep OpenSSH up to date, and implement other security best practices such as restricting network access and implementing proper firewall rules.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.