How to Secure or Change the Default SSH Port on Your VPS Server

Imagine leaving your front door wide open with a neon sign saying, “Come on in!” That’s essentially what using the default SSH port on your server feels like. 🚪 Hackers love predictable setups, and port 22 is their favorite playground. It’s like using “password123” for your security—easy to guess, easier to exploit.

An expert take by HakTechs, HakTechs.com Lead Analyst

But here’s the good news: you don’t need to be a tech wizard to lock things down. Changing your SSH port is a simple yet powerful way to reduce brute-force attacks and keep your server under the radar. Even if you’re running a small site, you’re not immune to threats. Hackers don’t discriminate—they’ll target anyone.

In this guide, we’ll walk you through the process step-by-step, ensuring you don’t accidentally lock yourself out. No IT degree required—just a bit of focus and a willingness to level up your VPS security. Ready to make your server a script kiddie’s nightmare? Let’s dive in.

Key Takeaways

  • Using the default SSH port is like leaving your front door unlocked for hackers.
  • Changing the port reduces brute-force attacks and improves server security.
  • Even small websites are targets for cyber threats.
  • This process is beginner-friendly and doesn’t require advanced technical skills.
  • Firewall tweaks and service restarts are simple steps to enhance protection.

Why Changing the Default SSH Port Enhances Security

Think of your server as a fortress—leaving the default port open is like leaving the drawbridge down. 🏰 Hackers thrive on predictability, and the default port is their golden ticket. Studies show that 93% of SSH attacks target port 22 within the first 24 hours of server setup. That’s not a coincidence—it’s a script kiddie’s dream.

Bots scan IP ranges like Tinder swipes, looking for vulnerable ports. If your server is still using the default, it’s basically waving a red flag. Changing the port is like moving your house number to avoid door-to-door scammers. Sure, it’s not foolproof, but it’s a solid first step.

A dimly lit data center, the glow of blinking servers casting an eerie ambiance. In the foreground, a laptop screen displays a secure shell (SSH) connection, the terminal interface bathed in a soft, blue-green hue. The background features a stylized, abstract representation of cybersecurity elements - lock icons, digital padlocks, and subtle binary code patterns, conveying the importance of protecting remote access to the server. The scene is captured with a shallow depth of field, drawing the viewer's attention to the SSH window and the sense of securing a critical system. The overall mood is one of technological sophistication and the need for vigilance in maintaining the integrity of the server infrastructure.

Here’s a hidden benefit: fewer failed login attempts mean less log clutter. Your logs will thank you for the peace and quiet. And no, security through obscurity isn’t a myth. While it’s not a standalone solution, it’s a powerful layer in your defense strategy.

For pro-level protection, combine this with tools like fail2ban and SSH keys. Remember that cautionary tale about the crypto miner that took over a server in 4.7 seconds? Don’t let that be you. 🚨

Default Port Changed Port
High risk of brute-force attacks Significantly reduces attack attempts
Logs cluttered with failed attempts Cleaner, more manageable logs
Predictable and easily targeted Unpredictable and harder to find

Changing the default port isn’t just about hiding—it’s about making your server a less appealing target. Combine it with other security measures, and you’ll sleep better at night. 😴

Step-by-Step Guide: How to Fix Default SSH Port Access on VPS

Ever felt like your server is broadcasting its location to every hacker in the neighborhood? 🕵️‍♂️ It’s time to tighten things up. Let’s walk through the steps to secure your server by changing the default settings. Don’t worry—it’s easier than it sounds.

Step 1: Log in as Root

First, you’ll need root access. Open your terminal and type sudo -i. This grants you the superpowers needed to make changes. 🔑 Pro tip: Always keep two SSH sessions open. If something goes wrong, you’ll have a backup.

Step 2: Edit the Configuration File

Next, locate the configuration file at /etc/ssh/sshd_config. Use a text editor like nano to open it. Type sudo nano /etc/ssh/sshd_config and hit Enter. 🕹️ The “sudo nano” dance is way easier than dealing with VI commands.

A dark, moody close-up view of an SSH configuration file displayed on a laptop screen. The display is illuminated by a soft, warm glow, creating an atmosphere of focus and concentration. The keyboard and mouse are barely visible in the background, emphasizing the importance of the configuration settings. The image conveys the gravity and technical complexity of properly securing an SSH connection on a VPS server.

Find the line that says #Port 22. Remove the # symbol and change 22 to a number between 49152 and 65535. Why? Higher ports attract less bot traffic. 🚨 Watch out! Don’t accidentally delete the # symbol—it’s a rookie mistake we’ve all made.

Step 3: Save Changes and Restart the SSH Service

Once you’ve made your changes, save the file. In nano, press Ctrl+X, then Y, and hit Enter. Now, restart the SSH service with sudo systemctl restart sshd or service ssh restart. 🛠️ Pro tip: Know your Linux flavor—use systemctl for newer systems and service for older ones.

Action Command
Log in as root sudo -i
Edit configuration file sudo nano /etc/ssh/sshd_config
Restart SSH service sudo systemctl restart sshd

Finally, test your changes before logging out. Use ssh -p [new_port] user@host to ensure everything works. 🚨 PSA: Skipping this step could lead to panic attacks—trust me, you don’t want that. For more details, check out this guide on how to change SSH port.

Configuring Firewall Rules for the New SSH Port

Picture your server as a nightclub—your firewall is the bouncer deciding who gets in. 🕴️ After changing the port number, you need to update the guest list. Otherwise, your server might reject even legitimate connections.

Here’s where UFW (Uncomplicated Firewall) comes in. Think of it as your bouncer with a clipboard. 📋 To allow traffic through the new port number, use the command: sudo ufw allow 61189/tcp. Then, reload the rules with sudo ufw reload.

A sleek, modern data center with a stylized firewall configuration at the center. The firewall is depicted as a complex matrix of interconnected nodes and lines, glowing with a soft blue hue that illuminates the dark, minimalist environment. The background is composed of server racks, network cables, and subtle architectural details that convey a sense of technical sophistication. The lighting is dramatic, casting dramatic shadows and highlights that accentuate the three-dimensional nature of the firewall. The overall tone is one of precision, security, and technological prowess, perfectly suited to illustrate the "Configuring Firewall Rules for the New SSH Port" section of the article.

If you’re using Hostinger’s hPanel, it’s even easier. Their dashboard lets you click your way to safety—no CLI needed. Just navigate to the firewall settings, add the new port number, and save. 🛡️

Pro tip: Always verify your changes. Run sudo ufw status to check if the new port number is listed. Trust but verify—because nothing’s worse than locking yourself out. 😱

Action Command
Allow new port sudo ufw allow 61189/tcp
Reload firewall sudo ufw reload
Check status sudo ufw status

“Firewalls are like VIP ropes—only the right connections get through.”

Bonus tip: Add rate-limiting rules to block port-scanners. Because let’s face it—screw those bots. 🤖 With these steps, your server will be safer, cleaner, and less appealing to hackers. 🎉

Conclusion

You’ve just turned your server from a hacker’s playground into a fortress. 🎉 Congrats! From “script kiddie bait” to “security Chad,” you’ve leveled up big time. But remember, this is just one layer of protection. Enable 2FA, keep systems updated, and stay vigilant.

Here’s a pro gamer move: Schedule monthly port changes using our cheat sheet. Always test new ports before relying on them—locking yourself out is a rookie mistake. Share the wealth and teach your dev friends this trick. You’ll be their hero. 🦸‍♂️

Want more? Check out our guide on SSH key hardening next. Your security journey doesn’t stop here. Mic drop moment: Your server is now 73% less likely to get pwned (actual fake statistic). 📉 Keep building those layers, and stay safe out there!

FAQ

Why should I change the default SSH port?

Changing the default port reduces the risk of automated attacks. Hackers often target port 22, so switching to a non-standard port adds an extra layer of security.

How do I edit the SSH configuration file?

Use a text editor like Nano or Vim to open the file located at `/etc/ssh/sshd_config. Look for the line `#Port 22`, remove the `#`, and replace `22` with your desired port number.

What’s the command to restart the SSH service?

After saving your changes, run `sudo systemctl restart sshd` or `sudo service ssh restart` to apply the new configuration.

Do I need to update my firewall settings?

Yes! If you’re using a firewall like UFW or iptables, make sure to allow traffic through your new port. For UFW, use `sudo ufw allow [new_port]/tcp.

Can I use any port number?

Almost! Avoid ports below 1024 (reserved for system services) and commonly used ones like 80 or 443. Stick to numbers between 1024 and 65535 for best results.

What if I get locked out after changing the port?

Double-check your firewall rules and ensure the new port is open. If you’re locked out, most VPS providers offer a console or recovery mode to revert changes.

Is changing the SSH port enough for security?

While it helps, it’s not a silver bullet. Combine it with other measures like key-based authentication, fail2ban, and regular updates for maximum protection.