Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

To change SSH’s listening port in Ubuntu, set a Port value in the OpenSSH server configuration, validate it, apply it using the correct systemd workflow, and allow the port through applicable firewalls. Ubuntu 24.04 uses socket activation by default, so restarting only ssh.service may leave SSH listening on port 22. Keep your current remote session open until a separate connection to the new port succeeds.

Before changing the SSH port

Choose an unused TCP port that fits your host’s network and security policy. Changing the port can reduce noise from scans aimed at the default port, but it is not a substitute for secure authentication and firewall rules.

  • Make sure you can reach a console or other recovery method if SSH access is interrupted.
  • Keep your existing SSH connection open while making and testing the change.
  • Allow the new port through the host firewall and, if applicable, the cloud provider or network firewall. Retain access to port 22 during the transition if you need a rollback path.

Set the SSH server port

Ubuntu’s OpenSSH server reads /etc/ssh/sshd_config and includes configuration snippets from /etc/ssh/sshd_config.d/. Ubuntu recommends using a snippet for local settings. OpenSSH uses the first value set for most directives, so an earlier Port in an included file can take precedence over a later entry. Inspect the main file and snippets for existing Port directives before adding one. See Ubuntu’s OpenSSH server documentation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Check for existing port settings:

    grep -R "^[[:space:]]*Port[[:space:]]" /etc/ssh/sshd_config /etc/ssh/sshd_config.d/
  2. Edit the conflicting setting or create a snippet, for example:

    sudo nano /etc/ssh/sshd_config.d/60-custom-port.conf

    Add the desired port on its own line. This example uses TCP port 2222:

    Port 2222

If you prefer, make the change in /etc/ssh/sshd_config instead. Ensure there is no earlier conflicting Port value in an included file.

Allow the port through the firewall

If UFW is enabled, allow the chosen TCP port and check the resulting rules. Ubuntu documents these UFW commands in its firewall guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo ufw allow 2222/tcp
sudo ufw status

For a cloud-hosted server or a host behind a network firewall, allow the same inbound TCP port in that separate firewall as well; provider steps and labels vary. Keep the existing port 22 rule during a rollback window if needed. Remove it only after the new connection works and clients, monitoring, and automation have been updated.

Validate and apply the change

First test the OpenSSH server configuration. Do not restart the service or socket if validation reports an error; correct the configuration and test again.

sudo sshd -t

The apply procedure depends on whether the host uses systemd socket activation or a service-managed listener. Ubuntu 24.04 uses socket activation by default. Ubuntu 22.04 installations can differ, so check the installed configuration comments and unit status rather than assuming one workflow applies to every host. Ubuntu documents the service restart procedure and the socket-activation requirement in its OpenSSH guide and 2024 bug-fix record.

systemctl status ssh.socket ssh.service

Socket-activated SSH

When socket activation is in use, changing Port, AddressFamily, or ListenAddress requires systemd to regenerate the socket configuration. After sshd -t succeeds, run:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo systemctl daemon-reload
sudo systemctl restart ssh.socket

On Ubuntu 24.04’s default socket-activated setup, restarting only ssh.service may leave the listener on port 22.

Service-managed SSH

If the host is managed through the service rather than socket activation, apply a valid configuration with:

sudo systemctl restart ssh.service

Ubuntu 22.04 may be configured either way depending on its package and activation state; use the status output and the installed /etc/ssh/sshd_config comments to identify the applicable procedure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Confirm the new listener and connect

After applying the change, inspect the local listening sockets and confirm the new port is listening. For example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo ss -ltnp

Then, from a separate terminal on your client, try a new login while leaving the original session open:

ssh -p 2222 user@server

Replace user, server, and 2222 with the account, hostname or IP address, and port you actually use. Close the original session only after the new login succeeds.

Troubleshoot a port change that does not work

  • SSH still listens on port 22: Check for an earlier Port directive in sshd_config.d. On Ubuntu 24.04 with socket activation, run sudo systemctl daemon-reload and restart ssh.socket, not just ssh.service.
  • The configuration test fails: Run sudo sshd -t and resolve the reported syntax or configuration issue before applying changes.
  • The service or socket will not start: Recheck the configuration and inspect the relevant unit status with systemctl status ssh.socket ssh.service. If you have lost remote access, use your available console or recovery access to restore a working configuration.
  • The port listens locally but a remote login times out: Check UFW with sudo ufw status, then confirm inbound access is allowed by any provider-level or upstream firewall.
  • The connection is refused: Confirm the server is listening on the expected port and that the client command specifies it with -p.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.