CHEAT SHEET
SSH cheat sheet
Connect, authenticate with keys, copy files, tunnel ports and harden the server.
Connecting
ssh user@host # log inssh -p 2222 user@host # another portssh -i ~/.ssh/id_ed25519 user@host # a specific keyssh user@host 'uptime' # run one command and exitssh -v user@host # verbose output for debugging
Keys
ssh-keygen -t ed25519 -C "comment" # create a key pairssh-copy-id user@host # install your public key on the servereval "$(ssh-agent -s)" # start the agentssh-add ~/.ssh/id_ed25519 # load your key into the agentchmod 700 ~/.ssh # required permissionschmod 600 ~/.ssh/authorized_keys
Copying files
scp file user@host:/tmp/ # uploadscp user@host:/etc/hosts . # downloadscp -r dir user@host:/tmp/ # a whole folderrsync -avz src/ user@host:/dst/ # sync a folder (only changes are sent)sftp user@host # interactive transfer
Tunnels
ssh -L 8080:localhost:80 user@host # local port 8080 reaches port 80 on the serverssh -R 9000:localhost:3000 user@host # server port 9000 reaches your port 3000ssh -D 1080 user@host # SOCKS proxy on local port 1080ssh -N -f -L 8080:localhost:80 user@host # tunnel only, in the background
~/.ssh/config
Host lab HostName 192.168.1.10 User alice Port 22 IdentityFile ~/.ssh/id_ed25519
Then ssh lab replaces the whole command.
Server settings
# /etc/ssh/sshd_configPermitRootLogin noPasswordAuthentication noPort 2222
sshd -t # test the configsemanage port -a -t ssh_port_t -p tcp 2222 # SELinux: allow the new portfirewall-cmd --permanent --add-port=2222/tcp # firewall: open itfirewall-cmd --reloadsystemctl reload sshd # apply the change
More cheat sheets
Questions
How do I log in over SSH without a password?
Create a key with ssh-keygen -t ed25519, install it with ssh-copy-id user@host, then connect normally.
How do I copy a file to a server?
Use scp file user@host:/path/. For whole folders use scp -r or rsync -avz.
How do I forward a remote port to a local machine?
Use ssh -L 8080:localhost:80 user@host. Then open http://localhost:8080 locally to reach port 80 on the server.
How do I change the SSH port on RHEL?
Set Port in /etc/ssh/sshd_config, allow it with semanage port -a -t ssh_port_t -p tcp PORT, open it in firewalld, test with sshd -t, then reload sshd.