How to Change the SSH Port and Root Password on a Linux VPS Safely

15 min read 1 views 0
On this page

Moving SSH off port 22 will not stop a determined attacker, but it removes most of the automated scanning noise from your logs, and a fresh root password is the first thing you should set on any new server. This guide shows how to change the SSH port and root password on a Linux VPS without losing access: editing sshd_config, labelling the port for SELinux on Rocky Linux and AlmaLinux, opening the firewall, handling the ssh.socket unit on Ubuntu 22.10 and 24.04, and rolling back through the VNC console if anything goes wrong. It applies to Debian, Ubuntu, CentOS 7 and Rocky/AlmaLinux 8 and 9 on JUSTG cloud and dedicated servers.

Step 1: Change the Root Password

Do this first, while you are still connected the normal way. The root password is also what you will type in the VNC console if you ever need to recover, so store it in a password manager. Use at least 16 random characters.

# Generate a random 24-character password (optional)
openssl rand -base64 18
# Set the new root password (type it twice)
passwd root

To change the password of another account, run passwd username instead.

Step 2: Choose a New SSH Port

Pick an unused port between 1024 and 49151, for example 2222 or 22022, and make sure no other service already uses it. The examples below use 2222.

# Nothing should be listening on the new port yet
ss -tlnp | grep ':2222' || echo "port 2222 is free"

Step 3: Add the New Port in sshd_config

Make a backup, then configure sshd to listen on both the old and the new port. Keeping port 22 during the change means a mistake in a later step cannot lock you out.

cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak.$(date +%F)
nano /etc/ssh/sshd_config
# Replace the "#Port 22" line with BOTH ports during the change:
Port 22
Port 2222

Step 4: Allow the SSH Port in SELinux (Rocky Linux / AlmaLinux / CentOS)

On Red Hat based systems SELinux only allows sshd to bind to ports labelled ssh_port_t. Without this step sshd fails to start on the new port with a "Permission denied" bind error. Debian and Ubuntu do not use SELinux by default and can skip it.

# Rocky Linux / AlmaLinux 8, 9
dnf install -y policycoreutils-python-utils
# CentOS 7
yum install -y policycoreutils-python

semanage port -a -t ssh_port_t -p tcp 2222
semanage port -l | grep ssh_port_t

Step 5: Open the New SSH Port in the Firewall

# Debian / Ubuntu with UFW
ufw allow 2222/tcp
ufw status

# CentOS / Rocky / AlmaLinux with firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
firewall-cmd --list-ports
If you run a custom iptables or nftables script instead of UFW or firewalld, add an accept rule for TCP 2222 there. Remember that every JUSTG cloud server has free IPv6 as well, and UFW and firewalld apply these rules to IPv6 automatically.

Step 6: Restart SSH (and Handle ssh.socket on Ubuntu 22.10+ and 24.04)

Check the syntax, then restart the service. Your current session stays connected.

sshd -t                         # syntax check, no output = OK

# Debian, Ubuntu 22.04 and older
systemctl restart ssh
# CentOS / Rocky / AlmaLinux
systemctl restart sshd

# Confirm sshd is listening on both ports
ss -tlnp | grep sshd

Ubuntu 22.10 and later start SSH through systemd socket activation: ssh.socket owns the listening port, so restarting ssh alone does not change it. Use the method that matches your release:

# Is socket activation in use?
systemctl is-active ssh.socket

# Ubuntu 24.04 (and 23.10+): the Port lines in sshd_config are read
# by a systemd generator, so reload and restart the socket
systemctl daemon-reload
systemctl restart ssh.socket

# Ubuntu 22.10 / 23.04: add the ports to a socket override instead
mkdir -p /etc/systemd/system/ssh.socket.d
cat > /etc/systemd/system/ssh.socket.d/listen.conf <<'EOF'
[Socket]
ListenStream=
ListenStream=22
ListenStream=2222
EOF
systemctl daemon-reload
systemctl restart ssh.socket
# Alternative on any of these Ubuntu releases: go back to the classic service
systemctl disable --now ssh.socket
systemctl enable --now ssh.service

Step 7: Test the New SSH Port in a Second Session

Keep your existing session open. Connect from a new terminal on the new port and only continue once the login succeeds.
# From a SECOND terminal on your computer
ssh -p 2222 [email protected]

# Optional ~/.ssh/config entry so you can just type "ssh myvps"
Host myvps
    HostName 203.0.113.40
    Port 2222
    User root

A "Connection timed out" usually means the firewall is still blocking the port. "Connection refused" means sshd is not listening on it: check SELinux, ssh.socket and ss -tlnp.

Step 8: Close Port 22

When the new port works, remove the old one from the SSH configuration and the firewall, restart once more and test again from a new terminal.

# Remove "Port 22" from sshd_config (and from listen.conf on Ubuntu 22.10/23.04)
sed -i '/^Port 22$/d' /etc/ssh/sshd_config
sshd -t && systemctl restart sshd      # use "ssh" on Debian/Ubuntu
# Ubuntu 22.10+ with ssh.socket: systemctl daemon-reload && systemctl restart ssh.socket

# UFW
ufw delete allow 22/tcp
ufw delete allow OpenSSH
# firewalld
firewall-cmd --permanent --remove-service=ssh
firewall-cmd --reload

Step 9: Roll Back Through the VNC Console

If you are locked out, the VNC console still works because it does not use the network or SSH. Log in to the JUSTG client area, open My Products & Services, choose the VPS and open its management panel to launch the console. If you cannot find the console option, submit a ticket. Log in as root with the password from Step 1 and revert:

# In the VNC console, logged in as root
cp /etc/ssh/sshd_config.bak.* /etc/ssh/sshd_config   # or re-add "Port 22"
ufw allow 22/tcp                       # Debian / Ubuntu
firewall-cmd --add-service=ssh         # CentOS / Rocky / AlmaLinux (runtime)
systemctl restart ssh || systemctl restart sshd

FAQ

Does changing the SSH port make my server secure?

It reduces log noise from bots, but it is not real protection on its own. Combine it with SSH key login, a disabled password login and a firewall for proper hardening.

Why does Ubuntu 24.04 still listen on port 22 after I changed sshd_config?

Because ssh.socket holds the port. Run systemctl daemon-reload followed by systemctl restart ssh.socket, or disable the socket and use ssh.service as shown in Step 6.

sshd will not start on Rocky Linux after the port change. What is wrong?

Almost always SELinux. Run journalctl -u sshd -n 20; if you see a bind error, add the port with semanage port -a -t ssh_port_t -p tcp 2222 and restart.

If you still cannot connect after changing the SSH port, please submit a ticket at https://www.justg.com/submitticket.php and JUSTG technical support will assist you.

Was this answer helpful?