SSH normally uses port 22. Connecting to a Linux server, port 22’s the standard doorway your computer tries first. Simple enough.

Important bit though, port 22 belongs to the SSH service, not to SSH as some permanent rule. An admin can configure SSH to listen on something else entirely, like 2222. Connection still uses SSH, just a different doorway.

Why Does SSH Use Port 22?

Port numbers help computers figure out which service should get incoming traffic. IP address is the building, port’s the specific door.

SSH got assigned port 22 decades ago as its standard. So running something like ssh user@server.com, your client normally tries port 22 unless told otherwise. Since it’s the default, you usually don’t even need to type it, one of those small conveniences you stop noticing after a while.

What Happens at Port 22?

Your SSH client opens a connection to the server’s IP on port 22. Something’s listening there, the SSH process starts, server identifies itself, negotiates the secure session, then authentication happens. Logged in, you’re working through the encrypted connection.

Nothing listening on port 22 though, you get an error instead. Exact message depends on what went wrong, a timeout feels different from a connection refusal even if both leave you staring at the same terminal.

Can SSH Use Another Port?

Absolutely, common on servers where admins don’t want SSH sitting on the default. They just configure the SSH daemon to listen elsewhere.

Port 22’s the default, most SSH commands work without extra settings. Port 2222’s a common alternative, nothing special about that number specifically. Your client needs to know the custom port though, otherwise it keeps knocking on 22. A firewall still has to allow the chosen port through too, which trips up a lot of first-time server setups.

To connect on another port, add the -p option: ssh -p 2222 user@server.com. Client connects to 2222 instead, protocol itself hasn’t changed, you’ve just told it where to find the service.

Is Port 22 Secure?

Using port 22 isn’t automatically unsafe. SSH’s designed for an encrypted connection, security depends heavily on how the server and authentication are set up.

Moving SSH to another port cuts down random automated scans hitting the standard port. Useful for noise, not really a security wall though, anyone actually scanning the server can find the new port anyway.

I’d rather see proper authentication and a sensible firewall than someone treating port 22 as the whole security problem. Changing the number’s easy, actually securing the service takes more thought.