把 SSH 从 22 端口移走虽然挡不住有心的攻击者,却能让日志里大部分自动扫描消失;而任何新服务器的第一件事,就是换一组新的 root 密码。本文说明如何在 Linux VPS 修改 SSH 端口与 root 密码且不断线:修改 sshd_config、在 Rocky Linux / AlmaLinux 为新端口设置 SELinux 标签、开放防火墙、处理 Ubuntu 22.10 与 24.04 的 ssh.socket,以及出错时通过 VNC 控制台恢复。适用于 JUSTG 云服务器与独立服务器上的 Debian、Ubuntu、CentOS 7 与 Rocky/AlmaLinux 8、9。
步骤 1:修改 root 密码
请趁现在还能正常连接时先完成。日后若需要用 VNC 控制台救援,输入的也是这组 root 密码,建议存放在密码管理工具中,长度至少 16 个随机字符。
# Generate a random 24-character password (optional)
openssl rand -base64 18
# Set the new root password (type it twice)
passwd root
若要修改其他账号的密码,改运行 passwd 用户名 即可。
步骤 2:选择新的 SSH 端口
在 1024 到 49151 之间挑一个未使用的端口,例如 2222 或 22022,并确认没有其他服务占用。以下示例使用 2222。
# Nothing should be listening on the new port yet
ss -tlnp | grep ':2222' || echo "port 2222 is free"
步骤 3:在 sshd_config 加入新的 SSH 端口
先备份,再让 sshd 同时监听旧端口与新端口。变更期间保留 22 端口,后续步骤即使出错也不会被锁在外面。
cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak.$(date +%F)
nano /etc/ssh/sshd_config
# Replace the "#Port 22" line with BOTH ports during the change:
Port 22
Port 2222
步骤 4:在 SELinux 允许新的 SSH 端口(Rocky Linux / AlmaLinux / CentOS)
Red Hat 系列系统的 SELinux 只允许 sshd 绑定标记为 ssh_port_t 的端口。少了这一步,sshd 会因“Permission denied”绑定错误而无法在新端口启动。Debian 与 Ubuntu 默认未启用 SELinux,可略过。
# Rocky Linux / AlmaLinux 8, 9
dnf install -y policycoreutils-python-utils
# CentOS 7
yum install -y policycoreutils-python
semanage port -a -t ssh_port_t -p tcp 2222
semanage port -l | grep ssh_port_t
步骤 5:在防火墙开放新的 SSH 端口
# Debian / Ubuntu with UFW
ufw allow 2222/tcp
ufw status
# CentOS / Rocky / AlmaLinux with firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload
firewall-cmd --list-ports
步骤 6:重新启动 SSH(含 Ubuntu 22.10+ / 24.04 的 ssh.socket)
先检查语法再重新启动服务,目前的连接不会中断。
sshd -t # syntax check, no output = OK
# Debian, Ubuntu 22.04 and older
systemctl restart ssh
# CentOS / Rocky / AlmaLinux
systemctl restart sshd
# Confirm sshd is listening on both ports
ss -tlnp | grep sshd
Ubuntu 22.10 之后改用 systemd socket activation 启动 SSH:监听端口由 ssh.socket 掌管,只重新启动 ssh 并不会改变端口。请依版本选择做法:
# Is socket activation in use?
systemctl is-active ssh.socket
# Ubuntu 24.04 (and 23.10+): the Port lines in sshd_config are read
# by a systemd generator, so reload and restart the socket
systemctl daemon-reload
systemctl restart ssh.socket
# Ubuntu 22.10 / 23.04: add the ports to a socket override instead
mkdir -p /etc/systemd/system/ssh.socket.d
cat > /etc/systemd/system/ssh.socket.d/listen.conf <<'EOF'
[Socket]
ListenStream=
ListenStream=22
ListenStream=2222
EOF
systemctl daemon-reload
systemctl restart ssh.socket
# Alternative on any of these Ubuntu releases: go back to the classic service
systemctl disable --now ssh.socket
systemctl enable --now ssh.service
步骤 7:用第二个连接测试新的 SSH 端口
# From a SECOND terminal on your computer
ssh -p 2222 [email protected]
# Optional ~/.ssh/config entry so you can just type "ssh myvps"
Host myvps
HostName 203.0.113.40
Port 2222
User root
出现“Connection timed out”通常是防火墙仍在阻挡;“Connection refused”代表 sshd 没有监听该端口,请检查 SELinux、ssh.socket 与 ss -tlnp。
步骤 8:关闭 22 端口
新端口可正常使用后,从 SSH 设置与防火墙移除旧端口,再重新启动一次,并从新终端再次测试。
# Remove "Port 22" from sshd_config (and from listen.conf on Ubuntu 22.10/23.04)
sed -i '/^Port 22$/d' /etc/ssh/sshd_config
sshd -t && systemctl restart sshd # use "ssh" on Debian/Ubuntu
# Ubuntu 22.10+ with ssh.socket: systemctl daemon-reload && systemctl restart ssh.socket
# UFW
ufw delete allow 22/tcp
ufw delete allow OpenSSH
# firewalld
firewall-cmd --permanent --remove-service=ssh
firewall-cmd --reload
步骤 9:通过 VNC 控制台恢复设置
万一被锁在外面,VNC 控制台不经过网络与 SSH,仍然可以使用。请登录 JUSTG 客户中心 → 我的产品与服务 → 选择 VPS → 管理/控制面板打开控制台;如找不到可提交工单。以步骤 1 设置的 root 密码登录后还原:
# In the VNC console, logged in as root
cp /etc/ssh/sshd_config.bak.* /etc/ssh/sshd_config # or re-add "Port 22"
ufw allow 22/tcp # Debian / Ubuntu
firewall-cmd --add-service=ssh # CentOS / Rocky / AlmaLinux (runtime)
systemctl restart ssh || systemctl restart sshd
常见问题
修改 SSH 端口就能让服务器安全吗?
它能减少机器人造成的日志噪声,但本身不算真正的防护。请搭配 SSH 密钥登录、停用密码登录与防火墙,才是完整的安全强化。
为什么改了 sshd_config,Ubuntu 24.04 仍在监听 22 端口?
因为端口由 ssh.socket 掌控。请运行 systemctl daemon-reload 再运行 systemctl restart ssh.socket,或依步骤 6 停用 socket 改用 ssh.service。
Rocky Linux 改了端口后 sshd 无法启动,怎么办?
几乎都是 SELinux 造成。运行 journalctl -u sshd -n 20,若看到绑定错误,用 semanage port -a -t ssh_port_t -p tcp 2222 加入端口后重新启动。
如修改 SSH 端口后仍无法连接,请至 https://www.justg.com/submitticket.php 提交工单,JUSTG 技术支持团队会协助您处理。