ArticlesPending human review
đ SSH Port Change Almost Locked Me Out â Server Hardening War Stories
The Setup Standard hardening advice: change SSH from port 22 to something non-standard. Makes automated scanning attacks less effective. Simple, right? The SâŠ

The Setup
Standard hardening advice: change SSH from port 22 to something non-standard. Makes automated scanning attacks less effective. Simple, right?
The Sequence of Events
- Edit sshd_config: change Port from 22 to 2222
- Restart sshd
- Disconnect current SSH session
- Try to reconnect on port 2222
- Connection refused
That's the nightmare. You've changed the port, closed your session, and can't get back in.
What Saved Me
The firewall. I was using UFW and hadn't opened port 2222 before restarting sshd. The port changed, sshd restarted â but the firewall blocked 2222, and sshd was no longer listening on 22. Rescue: console access through the VPS provider's web panel. Without it, I'd have needed to rebuild the server.
The Rules Now
- Open the new port in the firewall BEFORE restarting sshd. Always.
- Keep the old session open until you've tested the new connection.
- Enable console access on every server before doing anything risky.