SSH: Installation and Port 22 Configuration
To enable SSH, you must install the server software, ensure the service is active, and configure your firewall to allow traffic on port 22.
Linux (Ubuntu / Debian)
- Install OpenSSH Server:
sudo apt update && sudo apt install openssh-server -y - Start and Enable Service:
sudo systemctl enable --now ssh - Configure Firewall (UFW):
sudo ufw allow 22/tcp sudo ufw reload
Linux (RHEL / CentOS / Fedora)
- Install OpenSSH Server:
sudo dnf install openssh-server -y - Start and Enable Service:
sudo systemctl enable --now sshd - Configure Firewall (Firewalld):
sudo firewall-cmd --add-port=22/tcp --permanent sudo firewall-cmd --reload
Windows 10 / 11
- Install OpenSSH Server:
- Go to Settings > Apps > Optional Features.
- Click View features, search for OpenSSH Server, and install.
- Start and Automate Service:
- Open
services.msc. - Locate OpenSSH SSH Server, set Startup type to Automatic, and click Start.
- Open
- Open Firewall Port:
- Run in PowerShell (Admin):
New-NetFirewallRule -Name "Allow_SSH" -DisplayName "Allow SSH port 22" -Direction Inbound -Action Allow -Protocol TCP -LocalPort 22
- Run in PowerShell (Admin):
macOS
- Enable Remote Login:
- Go to System Settings > General > Sharing.
- Toggle Remote Login to ON. (This automatically handles firewall rules).
Verification and Connectivity
Verify Listening Port
Check if the system is actively listening on port 22:
ss -tlnp | grep :22Connect to the Server
From a remote machine, use:
ssh username@your_server_ipImportant: External Access
If you are connecting from outside your local network:
- Home Network: You must configure Port Forwarding on your router to map external port 22 to your machine’s local IP.
- Cloud Providers (AWS/Azure/GCP): You must configure the provider’s Security Groups or Network ACLs to allow inbound traffic on port 22.
Strategic Note
If you are exposing port 22 to the public internet, you are creating a high-value target for brute-force attacks. Consider using SSH keys instead of passwords, changing the default port to a non-standard one, or using a VPN (like Tailscale or WireGuard) to access your machine without exposing it to the open web.
Reference:
- Google Flash 3.5