Skip to main content
Support
0
Contact us
Nederlands
Deutsch
Español
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareers
Cloud Compute

With Cloud Compute, you have access anytime and anywhere to a portal through which you can configure your entire IT environment from wherever you are in the world.

Cloud Storage

Reliable access to your files, infrastructure, and applications at all times – with no interruptions or delays. At Worldstream, we offer a variety of storage solutions.

Flexible cloud icon
Flexible cloud
Private cloud icon
Private cloud
Bare metal icon
Bare Metal Compute
Hollow cube icon
Object storage
Hollow cube icon
File storage
Block storage icon
Block storage
Backup storage icon
Backup storage
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

All Servers

Choose your Dedicated Server now. Custom or Instant Delivery. Powerhouse servers built for your use case.

Use Cases

Whatever your use case, we’re here to help you find the ideal solution.

Deal servers icon
Deals
AMD servers icon
AMD Processors
AI servers icon
Intel Processors
Hollow cube icon
Virtualisation, Containerisation and Orchestration
Hollow cube icon
Websites and Applications
Hollow cube icon
Gaming and Streaming Infrastructure

24/7/365 support with an average response time of just 7 minutes. Thanks to our own data centers, our engineers can go directly to your server for fast, hands-on assistance. Email or call us anytime.

Smart outsourcing

Some IT creates added value, while other types are supportive. Use that as a starting point for outsourcing.

Cost Efficiency

Complete IT packages may seem like the safe option, but when you consider the costs, other choices often make more sense.

IT flexibility & control

Outsourcing doesn’t mean losing control; it actually provides more flexibility and control.

Cloud repatriation

The cloud is not a final destination: You should continuously evaluate and adjust your cloud environment as needs evolve.

Financial services
Logistics & Transportation
Retail & E-commerce
Media & Entertainment
Tech & Software Development
Security
Managed Service Providers
Need support?

With experienced engineers and an average response time track record on 7 minutes, you can expect a solid technical support solution in next to no time.

Chat with usContact us
About WorldstreamAbout the technologyCasesKnowledge base
About usMeet the teamJobsBecome a resellerCertificationsOur data centersOur networkDDoS ProtectionAMD EPYC serversTechnology PartnersOperating SystemsAll casesEasyTerraDutch Drone CompanyPerfGridArticlesFAQNews and BlogsProducts and Services
Contact us

Call +31 (0) 174 – 712 117

Industriestraat 53, Naaldwijk

Nederlands
Deutsch
Español
0
Dedicated serversFlexible VPSCloud TechnologyColocationChallenges in ITSectorsCareersAbout WorldstreamAbout the technologyCasesKnowledge baseMy Worldstream
Contact
Support
NederlandsDeutschEspañol
  1. HomeHome
  2. Knowledge Base
  3. Security
  4. How to change the SSH port

How to change the SSH port

Applies to Dedicated servers, Flexible VPS (Linux)Audience Server administratorsLast reviewed September 2026

Quick answer

Edit /etc/ssh/sshd_config, change the Port line to your chosen port, open that port in your firewall, then restart the SSH service. Two extra steps catch people out: recent Ubuntu releases set the port on ssh.socket instead, and RHEL-family distributions need the new port labelled in SELinux first.

Moving SSH off port 22 doesn't make your server unbreakable, but it does cut down sharply on the automated scanning traffic that hits every server on the default port. Use it alongside key-based authentication and the other steps in How to improve your SSH security, not instead of them.

Change the port

1

Choose a port

Pick an unused port above 1024 to avoid the reserved system port range. Check it isn't already used by another service on the server.

2

Edit sshd_config

Open /etc/ssh/sshd_config in a text editor and find the Port line. Uncomment it if needed, and set it to your chosen port number.

Port 2222

On recent Ubuntu releases, check for socket activation first. From Ubuntu 22.10 onwards, sshd is started by a systemd socket unit. When that unit is active, the Port directive in sshd_config is ignored and the listening port comes from the socket instead, so the change appears to work but nothing moves. Check it:

systemctl is-enabled ssh.socket

If that returns enabled, set the port on the socket as well:

sudo systemctl edit ssh.socket

Add the following, clearing the inherited value first:

[Socket]
ListenStream=
ListenStream=2222

Then reload and restart the socket:

sudo systemctl daemon-reload
sudo systemctl restart ssh.socket
3

Allow the new port through the firewall

Open the new port in whatever firewall the server runs, for example UFW, firewalld, or iptables, before you restart SSH. Leave the old port open until you've confirmed the new one works.

# UFW example
sudo ufw allow 2222/tcp
4

Restart the SSH service

On RHEL-family distributions, tell SELinux about the port first. On AlmaLinux, Rocky Linux, CentOS Stream and Oracle Linux, SELinux is enforcing by default and will not let sshd bind to a port outside its own policy, so the restart fails with a permission or bind error. Label the new port before restarting:

sudo dnf install policycoreutils-python-utils
sudo semanage port -a -t ssh_port_t -p tcp 2222

Check the configuration for syntax errors, then restart:

sudo sshd -t
sudo systemctl restart sshd

On Debian and Ubuntu the service is called ssh rather than sshd. If you changed ssh.socket in step 2, restarting the socket is what puts the new port into effect.

5

Test before you disconnect

Open a new terminal window and connect on the new port without closing your existing session:

ssh -p 2222 user@your-server-ip

Only close your original session once the new connection works. If it fails, your existing session lets you fix the configuration without being locked out.

6

Remove the old port from the firewall

Once you've confirmed the new port works, remove the rule allowing the old port (22) so it's no longer reachable.

Related articles

  • How to improve your SSH security
  • Two-factor authentication
Was this article helpful?

Solid IT. No Surprises

Sparring partner for IT maturity
Eliminating barriers so you can run
Predictable and transparant costs

Contact

  • Industriestraat 53, Naaldwijk
  • Payment Methods
  • Abuse
  • Developers Resources
  • Network Operations Center
  • About us
  • Meet the team
  • Jobs
  • Become a reseller
  • Certifications
  • Our data centers
  • Our network
  • DDoS Protection
  • AMD EPYC servers
  • Technology Partners
  • Operating Systems
  • Overview
  • FAQ
  • Cases
  • News & Blogs
  • Use Cases
Nederlands
Deutsch
Español
Nederlands
Deutsch
Español
  • Legal
  • Disclosure