Skip to content
abdallahmekky

CHEAT SHEET

SSH cheat sheet

Connect, authenticate with keys, copy files, tunnel ports and harden the server.

All cheat sheets

Connecting

ssh user@host                          # log inssh -p 2222 user@host                  # another portssh -i ~/.ssh/id_ed25519 user@host     # a specific keyssh user@host 'uptime'                 # run one command and exitssh -v user@host                       # verbose output for debugging

Keys

ssh-keygen -t ed25519 -C "comment"     # create a key pairssh-copy-id user@host                  # install your public key on the servereval "$(ssh-agent -s)"                 # start the agentssh-add ~/.ssh/id_ed25519              # load your key into the agentchmod 700 ~/.ssh                       # required permissionschmod 600 ~/.ssh/authorized_keys

Copying files

scp file user@host:/tmp/               # uploadscp user@host:/etc/hosts .             # downloadscp -r dir user@host:/tmp/             # a whole folderrsync -avz src/ user@host:/dst/        # sync a folder (only changes are sent)sftp user@host                         # interactive transfer

Tunnels

ssh -L 8080:localhost:80 user@host     # local port 8080 reaches port 80 on the serverssh -R 9000:localhost:3000 user@host   # server port 9000 reaches your port 3000ssh -D 1080 user@host                  # SOCKS proxy on local port 1080ssh -N -f -L 8080:localhost:80 user@host    # tunnel only, in the background

~/.ssh/config

Host lab  HostName 192.168.1.10  User alice  Port 22  IdentityFile ~/.ssh/id_ed25519

Then ssh lab replaces the whole command.

Server settings

# /etc/ssh/sshd_configPermitRootLogin noPasswordAuthentication noPort 2222
sshd -t                                               # test the configsemanage port -a -t ssh_port_t -p tcp 2222            # SELinux: allow the new portfirewall-cmd --permanent --add-port=2222/tcp          # firewall: open itfirewall-cmd --reloadsystemctl reload sshd                                 # apply the change

More cheat sheets

Questions

How do I log in over SSH without a password?

Create a key with ssh-keygen -t ed25519, install it with ssh-copy-id user@host, then connect normally.

How do I copy a file to a server?

Use scp file user@host:/path/. For whole folders use scp -r or rsync -avz.

How do I forward a remote port to a local machine?

Use ssh -L 8080:localhost:80 user@host. Then open http://localhost:8080 locally to reach port 80 on the server.

How do I change the SSH port on RHEL?

Set Port in /etc/ssh/sshd_config, allow it with semanage port -a -t ssh_port_t -p tcp PORT, open it in firewalld, test with sshd -t, then reload sshd.