Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For ordinary SSH connections, allow TCP to the server’s SSH listening port—TCP port 22 by default. The client initiates the connection, so the usual rule is outbound TCP from the client and inbound TCP to the server, subject to your network’s firewall policies. Do not open UDP 22 for OpenSSH merely because a port registry lists SSH on UDP; that entry alone does not mean the implementation uses UDP.

Does SSH use TCP or UDP?

Conventional SSH, including OpenSSH, uses TCP. RFC 4253 describes the SSH transport as typically running on TCP/IP and says that, when used over TCP/IP, the server normally listens on port 22. Its transport layer requires a binary-transparent connection; TCP/IP is the typical transport described by the standard.

The IANA Service Name and Transport Protocol Port Number Registry lists an ssh service entry on port 22 for both TCP and UDP. A registry assignment identifies a service name and port association; by itself, it is not proof that a particular SSH implementation communicates over both transports. For ordinary OpenSSH firewall configuration, use TCP. Allow another transport only if the documentation for the specific implementation or deployment calls for it.

Which firewall rule should I allow?

For a client connecting directly to an SSH server, allow a TCP connection from the client to the server’s configured SSH port. In a typical stateful firewall setup, this means permitting the client’s outbound TCP connection and the server’s inbound TCP traffic on that port. The precise rules depend on where enforcement occurs—such as a host firewall, network firewall, or cloud security group—and how connection tracking and network policy are configured.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
VNOPN Fanless Micro Firewall Appliance Intel J3710 Quad Core, 4xIntel i226-V LAN Ports, AES NI Network Gateway Soft Router Test with pf-Sense/opn-Sense(8GB RAM 240GB SSD)
  • 【Processor & OS】Firewall Mini PC with Intel J3710 CPU up to 2.40GHz, 4Cores4threads 2MB L2 Cache, TDP 6w, supports AES-NI/Wol. It tested with pf-sense linux ubuntu and other popular open source os. ("DEL" key to enter BIOS)
  • 【Interfaces】The firewall pc has 4 * Intel I226-V lan ports(up to 2.5G), 2 * USB3.0 ports, 1 * RS232 COM port, 2 * HD port, 1 * DC port. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
  • 【RAM & Storage】The firewall router equipped with 8G DDR3 RAM, max support 8GB; 240GB mSATA SSD, can be up to 512GB. Not support HDD.
  • 【Fanless Design】The small firewall box is only small but powerful. Low power consumption, only 6W; fanless heat dissipation design, aluminum alloy shell, efficient and fast heat dissipation, support 24/7 hours working, no noise. Equipped with VESA mount, you can install the micro pc behind the monitor to save space.
  • 【12 Months Service】You will get 1*mini pc,size:5.27 * 4.98 * 1.43 in weigh:500g. If you encounter any problems during the use, please contact us through Amazon, we have a professional and efficient team dedicated to serving you.
  • Protocol: TCP for ordinary SSH.
  • Destination port: TCP 22 by default, or the server’s configured SSH port.
  • Source and destination scope: Limit access to the client addresses and server hosts required by your environment. The standards and OpenSSH manuals do not prescribe universal address ranges.
  • Direction: Consider each connection leg and the policy at each firewall; do not assume one universal rule covers every network layout.

A firewall rule permits network traffic; it does not authenticate a user or grant authorization on the server.

Is TCP port 22 always the right port?

Port 22 is the normal default, not a guarantee that every server uses it. RFC 4253 identifies 22 as the normal listening port for SSH over TCP/IP. The current OpenBSD OpenSSH client manual, ssh_config(5), documents 22 as the client’s default port, and its server manual, sshd_config(5), documents 22 as the server listen-port default.

Rank #2
Glovary Firewall Mini PC J3710 Quad Core, 4 x i225V 2.5GbE LAN Fanless OPNsense Appliance, 8GB RAM 128GB SSD, Micro Router Computer Hardware, AES-NI, HD+DP Dual Display, Console, 2USB3.0, SPK/MIC
  • Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
  • 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
  • DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
  • HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
  • Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm

Administrators can configure a different server port. Check the server’s actual sshd configuration and match the firewall rule to its listening port; changing the port does not change the transport for ordinary SSH. OpenSSH’s Port setting can be specified more than once, so account for every configured listening port when reviewing access.

What if the connection goes through a jump host?

With OpenSSH’s ProxyJump, the client connects to an intermediary SSH host, which provides a forwarded TCP connection to the final destination. Treat these as separate connection legs: the client must be able to reach the jump host’s SSH port, and the jump host must be able to reach the destination on the port used there. The required firewall rules depend on which systems and network boundaries are involved.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

OpenSSH documents ProxyJump in its ssh_config(5) manual. If the final server listens on a non-default port, account for that port on the onward path rather than assuming the jump host uses the same port.

Why not open UDP 22?

For standard OpenSSH SSH, opening UDP 22 is unnecessary: the ordinary SSH transport uses TCP. The IANA registry’s UDP entry does not override the protocol behavior documented in RFC 4253 or establish that OpenSSH uses UDP. If a different SSH-related product or specialized deployment requires UDP, follow that implementation’s documentation instead of inferring a requirement from the registry.

Rank #4
VNOPN Fanless Firewall Appliance Intel J3710 4C/4T, Firewall Mini PC, 4 x Intel i226 LAN Ports, Network Gateway, Soft Router, Support PF-Sense/OPN-Sense, AES-NI (8GB RAM 128GB SSD)
  • 【CPU】Intel Pentium J3710 4-Core/4-Thread processor, up to 2.64GHz, with 2MB L2 Cache and 6W TDP. Supports AES-NI and suitable for firewall, router, VPN and other network applications.
  • 【Ports & Expansions】Equipped with 4 x 2.5GbE Intel i226-v LAN ports. Includes 2 x USB3.0, 1 x HDMI. 1 x VGA ports.Supports optional Wi-Fi and 3G/4G module expansion, plus a VESA mounting kit.
  • 【Fanless & Low-Power Design】6W fanless design with an aluminum alloy chassis for quiet, low-maintenance operation. Design for 24/7 continuous use and suitable for home networks, small office and network labs.
  • 【RAM & Storage】Includes 8G DDR3 RAM and a 128GB mSATA SSD. Supports up to 8GB RAM and 512GB mSATA storage. HDD storage is not supported. Compact 5.27 x 4.98 x 1.43-inch design weighs only apporximately 500g.
  • 【Warranty & Support】Tested with pfSense, OPNsense, Ubuntu and other popular open-sourse OS. Supports Proxmox VE for virtualization and home lab applications. Includes a 12-month hardware warranty and lifetime technical support. (Press "DEL" to the BIOS)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to check the rule before applying it

  1. Identify the connection path. Determine which client connects to which SSH server, and whether a jump host is involved.
  2. Confirm the listening port. Check the server’s effective sshd configuration rather than assuming it uses port 22.
  3. Set the transport and destination. For ordinary SSH, configure TCP to the relevant listening port.
  4. Apply least-needed scope. Permit only the necessary source addresses, destination hosts, and connection legs under your organization’s policy.
  5. Check each enforcement point. Review relevant host firewalls, network firewalls, and cloud security rules; a permission at one layer does not guarantee that another layer permits the connection.

RFC 4253 is the standards reference for SSH’s typical TCP/IP transport and normal port 22: RFC Editor, RFC 4253 (January 2006). The IANA registry is available at Service Name and Transport Protocol Port Number Registry; its entries should be read as registry data, not a substitute for implementation documentation.

Best Value
SonicWall TZ280 2.5 Gbps Next-Gen Firewall Appliance, HW Only
  • APPLIANCE ONLY: Hardware unit sold without a service subscription — security services, firmware updates and support are NOT included and must be purchased separately to activate protection.
  • PERFORMANCE: Up to 2.5 Gbps firewall inspection, 1 Gbps threat prevention and 1.2 Gbps IPSec VPN throughput driven by SonicWall's patented Reassembly-Free Deep Packet Inspection (RFDPI) engine.
  • CONNECTIVITY: 8x1GbE + 2x1G SFP in a desktop form factor; zero-touch deploy and manage on-box or via cloud Network Security Manager (NSM).
  • THREAT PROTECTION: SonicOS 8 delivers intrusion prevention, gateway anti-malware, application control, TLS/SSL decryption, Capture ATP multi-engine sandboxing (RTDMI) and reputation-based content & DNS filtering with an active service subscription.
  • BUILT FOR SMALL BUSINESS & BRANCH: Secure SD-WAN, IPSec and SSL VPN plus Zero-Trust Network Access through Cloud Secure Edge keep distributed sites and remote workers protected.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.