Moving SSH off its default port reduces noise from automated attacks. Learn how and when this simple change makes sense for your server.
Why the Default Port Attracts Attention
SSH runs on port 22 by default, and this is common knowledge exploited by automated scanning bots that continuously probe the internet for open port 22 connections to attempt brute-force logins. Changing the port doesn’t make your server invulnerable, but it does dramatically cut down on the volume of automated, opportunistic attack attempts.
Security Through Obscurity — With Caveats
Changing the SSH port is not a substitute for strong authentication; it’s a supplementary measure. Sophisticated, targeted attackers can still discover a non-standard port through a full port scan, but the vast majority of automated bots that only check the default port will simply move on.
How to Change the SSH Port
- Connect to your server and open
/etc/ssh/sshd_config. - Locate the line
#Port 22and change it to an unused port number of your choice, such asPort 2222. - Ensure your firewall rules (and any cloud provider security groups) allow traffic on the new port before restarting SSH.
- Restart the SSH service:
systemctl restart sshd. - Test the new connection using
ssh -p [new-port] user@serverin a separate session before closing your current one.
Coordinating With WHM and Firewalls
- Update WHM’s firewall configuration (such as CSF) to reflect the new SSH port.
- Inform your team of the port change and update any saved connection profiles in FTP/SSH clients.
A Layer, Not a Silver Bullet
Changing the SSH port works best combined with SSH key authentication, IP restriction, and brute-force protection — together they form a much harder target than any single measure alone.