How to Change the SSH Port in Ubuntu

The Protocol Obfuscation Vector

Every Ubuntu server on the internet listens for incoming Secure Shell (SSH) connections on Port 22 by default. Malicious automated botnets are programmed to relentlessly bombard this specific port, executing thousands of brute-force password attacks every hour in an attempt to breach the kernel. While strong passwords and SSH keys provide the primary defense, you can drastically reduce the volume of these automated attacks by executing a protocol obfuscation—instructing the SSH daemon to abandon Port 22 and listen on a highly obscure, randomized port number (e.g., 49201).

How to Change the SSH Port

This protocol requires extreme precision. You must modify the master `sshd_config` file and simultaneously update the Ubuntu firewall (UFW) to allow traffic on the new port. Failure to execute both steps in sequence will permanently lock you out of the server.

1. Open your terminal application and connect to the server via SSH using the default Port 22.
2. Phase 1: The Firewall Reconfiguration (Crucial First Step):
* Before you change the SSH port, you must tell the firewall to accept incoming connections on your chosen new port (e.g., 49201).
* Type: sudo ufw allow 49201/tcp
* Press Enter. The firewall matrix is now prepared to accept the rerouted traffic.
3. Phase 2: Editing the Master Configuration File:
* You must now edit the core SSH daemon configuration file using the `nano` text editor.
* Type: sudo nano /etc/ssh/sshd_config
* Press Enter.
4. Phase 3: The Cryptographic Alteration:
* Use the arrow keys to scroll down until you locate the specific line that reads: #Port 22
* First, delete the `#` symbol (this “uncomments” the line, making it active).
* Second, delete the number `22` and type your new obscure port number. The line must look exactly like this: Port 49201
* Press Ctrl + O, then press Enter to save the file.
* Press Ctrl + X to exit the nano editor.
5. Phase 4: The Daemon Reboot (The Risky Execution):
* The configuration file is updated, but the daemon is still running in RAM on Port 22. You must restart the service to apply the change.
* Type: sudo systemctl restart sshd
* Press Enter.
* Critical Verification: Do not close your current terminal window. Open a brand new terminal window on your local machine and attempt to connect using the new port syntax: `ssh username@server_ip -p 49201`. If it connects successfully, you may close the original session. If it fails, you can still use the original, open session to revert the `sshd_config` file back to Port 22.

Get the best tech tips delivered straight to your inbox.

Join thousands of readers mastering Apple, Google, Microsoft, and Linux.