← Harden & defendmoving ssh off port 22 is not real security

moving ssh off port 22 is not real security

$nmap -p- --open localhost | grep ssh

nmap · official source ↗

moving ssh off port 22 is not real security

somewhere along the way, "just change the ssh port" became the internet's favorite security tip. it's in every homelab guide, every reddit thread, every "harden your linux box" checklist. and look, it's not useless. but calling it security is like putting a "beware of dog" sign on your door when you don't own a dog. it might scare off the laziest guy on the block. it will not stop anyone who's actually looking.

let's prove it on your own machine, because that's the whole point of this blog. you should know exactly what an attacker sees when they look at you.

the command

nmap -p- --open localhost | grep ssh

break this down piece by piece:

nmap is a port scanner. it checks which doors on a machine are open and what's answering behind them.

-p- tells nmap to scan every single port, all 65,535 of them, instead of just the common ones. this is the part that matters. most quick scans only check the usual suspects, port 22, 80, 443, and so on. a full scan checks everything.

--open filters the results down to ports that are actually open. no point cluttering your output with closed doors.

localhost means you're scanning your own machine. this is not you scanning someone else's server, this is you auditing your own exposure, which is exactly what you should be doing regularly.

| grep ssh pipes the results into grep, searching for anything nmap identifies as ssh, no matter what port number it's sitting on.

run this against a box where you moved ssh to port 2222, or 22022, or whatever clever number felt safe, and nmap will still find it. it fingerprints the service by the banner it presents, not by the port number. the door has a different address, but it still says "hello, i'm ssh" the second something knocks.

why the port number never mattered

changing the port doesn't hide the service, it just relocates it. anyone running a full scan, which takes minutes on a single host and is trivial at scale across the internet, will find it exactly the same way you just did. tools like shodan and censys have already scanned the entire ipv4 internet on every port and indexed what's running where. if your ssh is reachable from the internet, someone already knows it's there, port number included.

what changing the port actually does is cut down on noise. automated bots that only check port 22 will scroll right past you. that's a real, if modest, benefit. it reduces log spam and the occasional low-effort credential stuffing attempt. it does nothing against a targeted scan.

what actually protects ssh

if you want real hardening, focus on things that change what happens after ssh is found, not where it's found.

disable password authentication. require key-based auth only. this alone kills the majority of automated attacks, since there's no password to guess.

PasswordAuthentication no
PubkeyAuthentication yes

disable root login over ssh. nobody should be logging in directly as root anyway.

PermitRootLogin no

use fail2ban or a similar tool to automatically block ips that fail authentication repeatedly. this cuts down brute force noise regardless of what port you're on.

restrict access with a firewall. if you know the ip ranges that should be connecting, like your home network or a vpn, lock ssh down to just those.

ufw allow from 203.0.113.0/24 to any port 22

put ssh behind a vpn or a bastion host if it doesn't need to face the public internet at all. the best way to protect a service from internet scanners is to make sure it's not something they can reach in the first place.

the takeaway

changing your ssh port is not a security control, it's a noise filter. it won't stop anyone who runs a real scan, and now you've watched your own machine get found in one line of nmap. use that knowledge to check your own exposure regularly, lock down auth methods, and control who can even reach the port in the first place. real security is about what happens when someone finds the door, not how well you think you've hidden it.

watch the reel ↗
the weekly drop

one command a week that makes you harder to hack.

a single tool, explained in plain english, every week. straight to your inbox.

no spam. one email a week. unsubscribe anytime.