
moving ssh off port 22 is not real security
nmap -p- --open localhost | grep sshmoving ssh off port 22 is not real security
somewhere along the way, "just change the ssh port" became the internet's favorite security tip. it's in every homelab guide, every reddit thread, every "harden your linux box" checklist. and look, it's not useless. but calling it security is like putting a "beware of dog" sign on your door when you don't own a dog. it might scare off the laziest guy on the block. it will not stop anyone who's actually looking.
let's prove it on your own machine, because that's the whole point of this blog. you should know exactly what an attacker sees when they look at you.
the command
nmap -p- --open localhost | grep ssh
break this down piece by piece:
nmap is a port scanner. it checks which doors on a machine are open and what's answering behind them.
-p- tells nmap to scan every single port, all 65,535 of them, instead of just the common ones. this is the part that matters. most quick scans only check the usual suspects, port 22, 80, 443, and so on. a full scan checks everything.
--open filters the results down to ports that are actually open. no point cluttering your output with closed doors.
localhost means you're scanning your own machine. this is not you scanning someone else's server, this is you auditing your own exposure, which is exactly what you should be doing regularly.
| grep ssh pipes the results into grep, searching for anything nmap identifies as ssh, no matter what port number it's sitting on.
run this against a box where you moved ssh to port 2222, or 22022, or whatever clever number felt safe, and nmap will still find it. it fingerprints the service by the banner it presents, not by the port number. the door has a different address, but it still says "hello, i'm ssh" the second something knocks.
why the port number never mattered
changing the port doesn't hide the service, it just relocates it. anyone running a full scan, which takes minutes on a single host and is trivial at scale across the internet, will find it exactly the same way you just did. tools like shodan and censys have already scanned the entire ipv4 internet on every port and indexed what's running where. if your ssh is reachable from the internet, someone already knows it's there, port number included.
what changing the port actually does is cut down on noise. automated bots that only check port 22 will scroll right past you. that's a real, if modest, benefit. it reduces log spam and the occasional low-effort credential stuffing attempt. it does nothing against a targeted scan.
what actually protects ssh
if you want real hardening, focus on things that change what happens after ssh is found, not where it's found.
disable password authentication. require key-based auth only. this alone kills the majority of automated attacks, since there's no password to guess.
PasswordAuthentication no
PubkeyAuthentication yes
disable root login over ssh. nobody should be logging in directly as root anyway.
PermitRootLogin no
use fail2ban or a similar tool to automatically block ips that fail authentication repeatedly. this cuts down brute force noise regardless of what port you're on.
restrict access with a firewall. if you know the ip ranges that should be connecting, like your home network or a vpn, lock ssh down to just those.
ufw allow from 203.0.113.0/24 to any port 22
put ssh behind a vpn or a bastion host if it doesn't need to face the public internet at all. the best way to protect a service from internet scanners is to make sure it's not something they can reach in the first place.
the takeaway
changing your ssh port is not a security control, it's a noise filter. it won't stop anyone who runs a real scan, and now you've watched your own machine get found in one line of nmap. use that knowledge to check your own exposure regularly, lock down auth methods, and control who can even reach the port in the first place. real security is about what happens when someone finds the door, not how well you think you've hidden it.