Short answer: SSH uses TCP port 22 by default. SFTP and scp travel inside the SSH connection, so they use port 22 as well. A server can be set to listen on any other port; then you connect with ssh -p PORT user@host. Below: how to see which port a server really uses, how to test that it is reachable, and how to pass a different port to ssh, scp, rsync and your SSH config.
| Protocol | Default port | Transport | Note |
|---|---|---|---|
| SSH | 22 | TCP | Shell access, tunnels, port forwarding |
| SFTP / scp | 22 | TCP | Runs inside SSH, no separate port |
| FTP | 21 (+ data ports) | TCP | Unencrypted unless FTPS is used |
| Telnet | 23 | TCP | Unencrypted, do not expose |
| RDP | 3389 | TCP + UDP | Windows Remote Desktop |
| 2222 | — | TCP | A popular alternative SSH port, not a standard |
How to check which port sshd listens on
The configuration file says what should happen; the socket table says what is happening. Check the socket table first:
# Which TCP ports is sshd listening on right now?
sudo ss -tlnp | grep -E '"sshd"|"systemd",pid=1,'
# Example output — port 22 on all IPv4 and IPv6 addresses:
# LISTEN 0 128 0.0.0.0:22 0.0.0.0:* users:(("sshd",pid=812,fd=3))
# LISTEN 0 128 [::]:22 [::]:* users:(("sshd",pid=812,fd=4))
# The effective configuration, after all include files are merged:
sudo sshd -T | grep -iE '^(port|listenaddress)'sshd -T matters because a Port line can live in /etc/ssh/sshd_config or in any file under /etc/ssh/sshd_config.d/, andPort lines add up: sshd listens on every port named in any of them. Grepping only the main file misses a second one.
Locked out and cannot run anything? Use your provider's browser console (on VMHeaven: the VNC console in the panel), log in there and run the same two commands.
How to test whether the SSH port is open
Test from your own computer, not from the server, because the question is whether the port is reachable from outside:
# Linux, macOS
nc -zv -w 5 203.0.113.10 22
# Windows PowerShell
Test-NetConnection 203.0.113.10 -Port 22
# The SSH banner proves it is really sshd answering
# (a line starting with SSH-2.0-OpenSSH):
nc -w 3 203.0.113.10 22 </dev/null- Succeeded / TcpTestSucceeded: True — the port is open. A failing login is then an SSH problem such as Permission denied (publickey).
- Connection refused — the server answered, but nothing listens on that port or a firewall rejects it. See SSH connection refused.
- Timed out — nothing answered at all: wrong IP, server down, or a firewall drops the packets.
How to connect when SSH runs on another port
Each tool spells the port option differently, which is the most common source of confusion:
ssh -p 2222 root@203.0.113.10
scp -P 2222 backup.tar.gz root@203.0.113.10:/root/ # capital P
sftp -P 2222 root@203.0.113.10 # capital P
rsync -av -e "ssh -p 2222" ./site/ root@203.0.113.10:/var/www/site/If you connect often, put the port into ~/.ssh/config once. Every tool that uses OpenSSH — ssh, scp, sftp, rsync, git — then picks it up automatically:
Host myvps
HostName 203.0.113.10
User root
Port 2222
IdentityFile ~/.ssh/id_ed25519
# Now simply:
# ssh myvps
# scp file.txt myvps:/root/In PuTTY, the port goes into the Port field next to the host name on the Session page. WinSCP and FileZilla have the same field; in FileZilla choose the sftp:// protocol so it talks SSH, not FTP.
Should you change the SSH port?
Moving SSH off port 22 cuts the volume of automated login attempts in your logs. It does not make the server meaningfully safer: a port scan finds the new port quickly. What protects SSH is key-only authentication, disabled password login and a firewall, covered step by step in How to secure SSH access.
If you still want a different port, do it in an order that cannot lock you out: open the new port in the firewall first, add the new Port line while keeping 22, restart, test a second session on the new port, and only then remove 22.
Allowing the SSH port in the firewall
sudo ufw allow 22/tcp # or: sudo ufw allow OpenSSH
sudo ufw limit 22/tcp # optional: rate-limit repeated connection attempts
sudo ufw status verbosesudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --reloadAlways allow SSH before enabling a firewall on a server you reach over SSH. More on rules and defaults in UFW firewall setup.
SSH port on Windows Server
Windows Server 2019 and later ship OpenSSH Server as an optional feature. It also listens on TCP 22, its configuration lives in C:\ProgramData\ssh\sshd_config, and installing it creates the inbound firewall rule OpenSSH-Server-In-TCP:
Get-Service sshd
Get-NetTCPConnection -LocalPort 22 -State Listen
Get-NetFirewallRule -Name OpenSSH-Server-In-TCP | Select-Object Name, EnabledRemote Desktop is a different protocol on a different port, 3389; see RDP port 3389. If you want a server where you control both, a KVM VPS gives you full root access with SSH on port 22 from the first boot, and the Windows RDP plans come with Remote Desktop ready to use.
Frequently asked
What port does SSH use?
SSH uses TCP port 22 by default. SFTP and scp run inside SSH, so they use the same port. A server can be configured to listen on any other port, which you then pass to the client with 'ssh -p PORT'.
Is SSH TCP or UDP?
TCP. OpenSSH listens on TCP only, so a firewall rule for SSH needs to allow TCP 22 (or your custom port). Opening UDP 22 does nothing for SSH.
How do I find out which port my server's SSH runs on?
On the server, sudo ss -tlnp | grep -E '"sshd"|"systemd",pid=1,' shows the port sshd actually listens on (from Ubuntu 22.10, systemd may hold the socket for it), and sudo sshd -T | grep -i ^port shows the effective configuration. If you cannot log in, open the provider's browser console and run the same commands there.