VMHeaven

Guides

SSH port 22: the default port, how to check which one your server uses, and how to connect on another

SSH listens on TCP port 22 by default. How to see which port your server really uses, test that it is open, and connect with ssh, scp and rsync on another port.

Published ~7 min read

Short answer: SSH uses TCP port 22 by default. SFTP and scp travel inside the SSH connection, so they use port 22 as well. A server can be set to listen on any other port; then you connect with ssh -p PORT user@host. Below: how to see which port a server really uses, how to test that it is reachable, and how to pass a different port to ssh, scp, rsync and your SSH config.

ProtocolDefault portTransportNote
SSH22TCPShell access, tunnels, port forwarding
SFTP / scp22TCPRuns inside SSH, no separate port
FTP21 (+ data ports)TCPUnencrypted unless FTPS is used
Telnet23TCPUnencrypted, do not expose
RDP3389TCP + UDPWindows Remote Desktop
2222—TCPA popular alternative SSH port, not a standard

How to check which port sshd listens on

The configuration file says what should happen; the socket table says what is happening. Check the socket table first:

Debian · Ubuntu · Rocky
# Which TCP ports is sshd listening on right now?
sudo ss -tlnp | grep -E '"sshd"|"systemd",pid=1,'

# Example output — port 22 on all IPv4 and IPv6 addresses:
# LISTEN 0 128   0.0.0.0:22   0.0.0.0:*   users:(("sshd",pid=812,fd=3))
# LISTEN 0 128      [::]:22      [::]:*   users:(("sshd",pid=812,fd=4))

# The effective configuration, after all include files are merged:
sudo sshd -T | grep -iE '^(port|listenaddress)'

sshd -T matters because a Port line can live in /etc/ssh/sshd_config or in any file under /etc/ssh/sshd_config.d/, andPort lines add up: sshd listens on every port named in any of them. Grepping only the main file misses a second one.

Locked out and cannot run anything? Use your provider's browser console (on VMHeaven: the VNC console in the panel), log in there and run the same two commands.

How to test whether the SSH port is open

Test from your own computer, not from the server, because the question is whether the port is reachable from outside:

from your computer
# Linux, macOS
nc -zv -w 5 203.0.113.10 22

# Windows PowerShell
Test-NetConnection 203.0.113.10 -Port 22

# The SSH banner proves it is really sshd answering
# (a line starting with SSH-2.0-OpenSSH):
nc -w 3 203.0.113.10 22 </dev/null
  • Succeeded / TcpTestSucceeded: True — the port is open. A failing login is then an SSH problem such as Permission denied (publickey).
  • Connection refused — the server answered, but nothing listens on that port or a firewall rejects it. See SSH connection refused.
  • Timed out — nothing answered at all: wrong IP, server down, or a firewall drops the packets.

How to connect when SSH runs on another port

Each tool spells the port option differently, which is the most common source of confusion:

ssh, scp, sftp, rsync
ssh  -p 2222 root@203.0.113.10
scp  -P 2222 backup.tar.gz root@203.0.113.10:/root/     # capital P
sftp -P 2222 root@203.0.113.10                           # capital P
rsync -av -e "ssh -p 2222" ./site/ root@203.0.113.10:/var/www/site/

If you connect often, put the port into ~/.ssh/config once. Every tool that uses OpenSSH — ssh, scp, sftp, rsync, git — then picks it up automatically:

~/.ssh/config
Host myvps
    HostName 203.0.113.10
    User root
    Port 2222
    IdentityFile ~/.ssh/id_ed25519

# Now simply:
#   ssh myvps
#   scp file.txt myvps:/root/

In PuTTY, the port goes into the Port field next to the host name on the Session page. WinSCP and FileZilla have the same field; in FileZilla choose the sftp:// protocol so it talks SSH, not FTP.

Should you change the SSH port?

Moving SSH off port 22 cuts the volume of automated login attempts in your logs. It does not make the server meaningfully safer: a port scan finds the new port quickly. What protects SSH is key-only authentication, disabled password login and a firewall, covered step by step in How to secure SSH access.

If you still want a different port, do it in an order that cannot lock you out: open the new port in the firewall first, add the new Port line while keeping 22, restart, test a second session on the new port, and only then remove 22.

Allowing the SSH port in the firewall

UFW (Debian · Ubuntu)
sudo ufw allow 22/tcp          # or: sudo ufw allow OpenSSH
sudo ufw limit 22/tcp          # optional: rate-limit repeated connection attempts
sudo ufw status verbose
firewalld (Rocky · Alma)
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --reload

Always allow SSH before enabling a firewall on a server you reach over SSH. More on rules and defaults in UFW firewall setup.

SSH port on Windows Server

Windows Server 2019 and later ship OpenSSH Server as an optional feature. It also listens on TCP 22, its configuration lives in C:\ProgramData\ssh\sshd_config, and installing it creates the inbound firewall rule OpenSSH-Server-In-TCP:

PowerShell (Administrator)
Get-Service sshd
Get-NetTCPConnection -LocalPort 22 -State Listen
Get-NetFirewallRule -Name OpenSSH-Server-In-TCP | Select-Object Name, Enabled

Remote Desktop is a different protocol on a different port, 3389; see RDP port 3389. If you want a server where you control both, a KVM VPS gives you full root access with SSH on port 22 from the first boot, and the Windows RDP plans come with Remote Desktop ready to use.

Frequently asked

What port does SSH use?

SSH uses TCP port 22 by default. SFTP and scp run inside SSH, so they use the same port. A server can be configured to listen on any other port, which you then pass to the client with 'ssh -p PORT'.

Is SSH TCP or UDP?

TCP. OpenSSH listens on TCP only, so a firewall rule for SSH needs to allow TCP 22 (or your custom port). Opening UDP 22 does nothing for SSH.

How do I find out which port my server's SSH runs on?

On the server, sudo ss -tlnp | grep -E '"sshd"|"systemd",pid=1,' shows the port sshd actually listens on (from Ubuntu 22.10, systemd may hold the socket for it), and sudo sshd -T | grep -i ^port shows the effective configuration. If you cannot log in, open the provider's browser console and run the same commands there.

Related articles

All guides