ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Linux Server

How to Change the SSH Port and Root Password on Linux (Firewall and SELinux Included)

7 steps 11 min read 1 views 0
On this page

Port 22 is hammered by automated brute-force bots every day, so moving SSH to a non-standard port and setting a strong root password are the first hardening steps for any new server. This guide explains how to change the SSH port and root password on Linux: editing sshd_config, allowing the new port in the firewall and SELinux, restarting sshd safely and changing the password with passwd. It applies to Debian/Ubuntu and CentOS/Rocky/AlmaLinux.

Keep your current SSH session open and leave port 22 enabled while you switch. Close the old port only after you have confirmed you can log in on the new one. If you get locked out, use the VNC console in the client area to recover.

Step 1: Back Up and Inspect the SSH Configuration

Back up /etc/ssh/sshd_config and check the current Port setting. Newer systems may also have drop-in files in /etc/ssh/sshd_config.d/; check those too so your change is not overridden.

cp /etc/ssh/sshd_config /etc/ssh/sshd_config.bak
grep -nE '^#?Port' /etc/ssh/sshd_config
grep -rn '^Port' /etc/ssh/sshd_config.d/ 2>/dev/null

Step 2: Change the SSH Port in sshd_config

Edit sshd_config with vi or nano, uncomment Port and add a line for the new port. Pick an unused port between 1024 and 65535; the examples use 2222. During the transition, listen on both 22 and the new port.

# /etc/ssh/sshd_config - keep 22 temporarily and add the new port
Port 22
Port 2222

Step 3: Open the New SSH Port in the Firewall

CentOS, Rocky and AlmaLinux use firewalld by default; Ubuntu commonly uses ufw. If a firewall is active and the new port is not allowed, you will be unable to connect after restarting sshd. Skip this step if no firewall is enabled.

# CentOS / Rocky / AlmaLinux with firewalld
firewall-cmd --permanent --add-port=2222/tcp
firewall-cmd --reload

# Debian / Ubuntu with ufw
ufw allow 2222/tcp
ufw status

Step 4: Allow the New SSH Port in SELinux

On RHEL-family systems with SELinux in Enforcing mode, sshd may only bind to approved ports. Register the new port as ssh_port_t with semanage, or sshd will fail to start. Debian and Ubuntu do not enable SELinux by default, so you can skip this.

# Only on systems with SELinux enforcing (CentOS / Rocky / AlmaLinux)
getenforce
dnf install -y policycoreutils-python-utils
semanage port -a -t ssh_port_t -p tcp 2222
semanage port -l | grep ssh_port_t

Step 5: Validate the Config and Restart sshd

Run sshd -t to check the syntax (no output means OK), then restart the service. On Ubuntu the service is called ssh, and from Ubuntu 22.10 onwards it uses socket activation, so you also need to reload systemd and restart ssh.socket. Finally confirm with ss that the new port is listening.

# Check syntax first - no output means OK
sshd -t

# CentOS / Rocky / AlmaLinux / Debian
systemctl restart sshd

# Ubuntu (service is named "ssh"); on Ubuntu 22.10+ with socket activation also run:
systemctl restart ssh
systemctl daemon-reload && systemctl restart ssh.socket

ss -tlnp | grep -E ':22 |:2222 '

Step 6: Test the New Port and Close Port 22

Open a new terminal on your computer and log in on the new port. Once that works, remove the Port 22 line from sshd_config, restart sshd and remove the firewall rule for port 22.

# From your own computer, in a NEW window
ssh -p 2222 [email protected]

# After it works: remove "Port 22" from sshd_config, restart sshd, then close 22
firewall-cmd --permanent --remove-service=ssh && firewall-cmd --reload   # firewalld
ufw delete allow 22/tcp                                                  # ufw (if a rule exists)

Step 7: Change the Linux Root Password with passwd

Run passwd and enter the new password twice; nothing is shown as you type. Use a random password of at least 12 characters with mixed-case letters, numbers and symbols, and keep it in a password manager. For scripts, chpasswd sets passwords non-interactively.

# Change the root password interactively
passwd root

# Or non-interactively (avoid leaving it in shell history on shared systems)
echo 'root:N3w-Str0ng-P@ssw0rd' | chpasswd

FAQ

The connection times out after changing the port.

Usually the firewall or SELinux is blocking it. Log in via the VNC console, run ss -tlnp | grep sshd to confirm sshd listens on the new port, then check firewall-cmd --list-all or ufw status.

Will the client area show my new root password?

No. Passwords changed inside the OS are not synced to the client area, so store it safely. If you forget it, reset it from single-user mode via the VNC console or open a ticket.

Is changing the port enough for security?

It greatly reduces scanner noise, but you should also switch to SSH key authentication, disable password login and use fail2ban to throttle brute-force attempts.

Still stuck after following these steps? Open a support ticket and the IMIDC 24/7 technical team will help. Please include the server IP, operating system, the commands you ran and a screenshot of the error so we can pinpoint the issue faster.

Was this answer helpful?

Related Tutorials