Recommended Free Tools
On Ubuntu 22.04 LTS (Jammy), install the openssh-server package, start ssh.service, allow the selected port through any local and provider firewalls, and test from a separate computer. Then add an Ed25519 key and validate every configuration change before reloading SSH.
SSH encrypts remote administration and file transfers such as SFTP and scp. The client runs on the computer initiating a connection; the server runs on the Ubuntu machine being accessed. Installing openssh-client alone does not make Ubuntu accept incoming connections.
Before you begin
- An Ubuntu 22.04 LTS computer, virtual machine, cloud instance, or WSL-like environment.
- A local console or an existing administrative session, plus a user with
sudoprivileges. - Network connectivity and the server’s IP address or hostname.
- A separate client computer for the connection test.
Keep your current session open until a second SSH session works. Cloud providers and home routers have separate firewalls or NAT rules; Ubuntu’s firewall cannot override them. OpenSSH also does not provide a public IP address, DNS, port forwarding, or protection against compromised accounts.
Check whether the server is already installed
Cloud images and installer selections sometimes include OpenSSH already. Check before installing:
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute#1 Best Overall
- 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
- Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
- Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
- PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
- Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5
dpkg -l openssh-server
systemctl status ssh
Ubuntu’s Jammy package stream is maintained through security and update repositories, so install the package name rather than a hard-coded revision. See the Ubuntu package listing.
Install OpenSSH Server
sudo apt update
sudo apt install openssh-server
apt update refreshes package metadata; apt install openssh-server installs the daemon, service unit, and supporting files. The client package is separate. Ubuntu’s official procedure is documented in OpenSSH server documentation.
Start and verify the SSH service
Enable SSH at boot and start it immediately:
sudo systemctl enable --now ssh
sudo systemctl status ssh
Look for active (running). Non-interactive checks are useful in scripts:
systemctl is-active ssh
systemctl is-enabled ssh
sudo ss -tlnp | grep ssh
The Ubuntu service is called ssh.service, while the daemon and configuration terminology use sshd. The default listening port is TCP 22; the Jammy sshd manual documents the default and the Port directive.
To inspect the effective configuration and port:
sudo sshd -T
sudo sshd -T | grep '^port '
Allow SSH through UFW (if UFW is enabled)
Installing OpenSSH does not require enabling UFW. If UFW is already active, allow SSH before testing remotely:
Rank #2
- Cat 6 performance at a Cat5e price but with higher bandwidth
- High Performance Cat6, 30 AWG, RJ45 Ethernet Patch Cable provides universal connectivity for LAN network components such as PCs,computer servers,printers,routers,switch boxes,network media players,NAS,VoIP phones
- Jadaol cat6 standard cable support Cat8 and Cat7 network and provides performance of up to 250 MHz 10Gbps and is suitable for 10BASE-T, 100BASE-TX (Fast Ethernet), 1000BASE-T/1000BASE-TX (Gigabit Ethernet) and 10GBASE-T (10-Gigabit Ethernet)
- UTP(Unshielded Twisted Pair) patch cable with RJ45 gold-plated Connectors and are made of 100% bare copper wire, ensure minimal noise and interference
- The unique flat cable shape allows for a cleaner and safer installation. You can easily and seamlessly make the cable run along walls, follow edges & corners or even make it completely invisible by sliding it under a carpet.
sudo ufw allow OpenSSH
sudo ufw status
If the application profile is unavailable, allow the port explicitly:
sudo ufw allow 22/tcp
Never run sudo ufw enable from a remote session until an SSH rule is in place. Do not remove the existing rule while it is your only access path. A cloud security group, provider firewall, router, network ACL, or IPv6 policy may still block the connection.
Find the server address
hostname -I
ip address
On a LAN, use the server’s private address, such as 192.168.1.50. For a cloud instance, use the provider’s public IPv4 or IPv6 address or its DNS name; the private address from hostname -I may not be reachable from the internet. Public access additionally needs routing, an inbound rule, and possibly router port forwarding. IPv4 and IPv6 firewall policies can differ.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Connect from another computer
From Linux, macOS, or a Windows system with an OpenSSH client, run:
ssh username@SERVER_IP
Replace username with the Ubuntu account actually created by the installation or cloud image; direct root login is not required. For another port:
Rank #3
- Designed for Outdoor & Direct Burial Installations – Heavy-duty double-shielded Cat8 Ethernet cable minimizes EMI/RFI interference and delivers stable long-distance performance. Waterproof, anti-corrosion PVC jacket allows safe direct burial and reliable use in outdoor or indoor environments.
- 26AWG for Stable High-Load Networks – Thicker 26AWG conductors provide faster, more stable data transmission than standard 32AWG cables. Ideal for high-performance home networks, gaming setups, smart homes, and data-intensive applications.
- F/FTP Shielding & Hyper-Speed Performance: Cat8 Ethernet cable constructed with 4 shielded foiled twisted pairs and 26AWG OFC conductors; supports bandwidth up to 2000 MHz and data transmission speeds up to 40 Gbps, effectively reducing signal interference and ensuring stable connections. Ideal for low-latency gaming, 4K/8K streaming, and high-speed internet connections.
- RJ45 Connectors & Wide Compatibility: Cat8 Ethernet cable with two shielded RJ45 connectors; compatible with networking switches, IP cameras, routers, Nintendo Switch, modems, PS3, PS4, Xbox, patch panels, servers, smart TVs, and more; works with Cat7, Cat6, Cat5e, and Cat5 devices
- Weatherproof & UV Resistant: Outdoor-rated Cat8 Ethernet cable with UV-resistant PVC jacket; withstands direct sunlight, extreme cold, humidity, and hot weather; anti-aging and durable; Includes 18-month support.
ssh -p 2222 username@SERVER_IP
The first connection displays the server host-key fingerprint. Verify it through a trusted channel when security matters instead of blindly accepting it. After login, confirm the destination:
hostname
whoami
exit
Use verbose output when diagnosing a client-side failure:
ssh -v username@SERVER_IP
ssh -vvv username@SERVER_IP
A localhost test (ssh username@localhost) checks only the local daemon; it does not prove remote routing, DNS, UFW, provider firewalls, or router forwarding.
Set up SSH-key authentication
Generate a key on the client
ssh-keygen -t ed25519
Accept the default path or choose a distinct filename, and protect the private key with a passphrase. Ubuntu recommends Ed25519; a 4096-bit RSA key is an alternative. The private key remains on the client; only the public key is copied to the server.
Install and test the public key
ssh-copy-id username@SERVER_IP
ssh username@SERVER_IP
The key is appended to the target account’s ~/.ssh/authorized_keys. If ssh-copy-id is unavailable, use an existing login:
Rank #4
- High-Performance Connectivity: This Cat 6 ethernet cable is designed for superior performance, with a 24 AWG copper wire core. It provides universal connectivity as an ethernet cord for LAN network components such as PCs, servers, printers, routers, and more, ensuring reliable and fast network connections
- Advanced Cat6 Technology: Experience Cat6 performance with higher bandwidth at a Cat5e price. This network cable is future-proof, ready for 10-Gigabit Ethernet and backwards compatible with any existing Cat 5 cable network. It meets or exceeds Category 6 performance according to the TIA/EIA 568-C.2 standard
- Reliable Wired Network Solution: Known variously as a Cat6 network cable, ethernet cable Cat 6, or Cat 6 data/LAN cable, this RJ45 cable offers a more secure and reliable connection than wireless networks. It's ideal for internet connections that demand consistency and security
- Durable and Secure Design: The connectors of this ethernet cable feature gold-plated contacts and strain-relief boots for enhanced durability. Bare copper conductors not only improve cable performance but also comply with communication cable specifications
- High-Speed Data Transfer: With up to 550 MHz bandwidth, this ethernet cord is ideal for server applications, cloud computing, video surveillance, and streaming high-definition video. It also supports Power over Ethernet (PoE, PoE+, PoE++) for powering devices like IP cameras, VoIP phones, and wireless access points, ensuring fast and reliable network performance.
cat ~/.ssh/id_ed25519.pub | ssh username@SERVER_IP
'umask 077; mkdir -p ~/.ssh; cat >> ~/.ssh/authorized_keys'
For a non-default private-key filename:
ssh -i ~/.ssh/my_server_key username@SERVER_IP
Or define a client alias in ~/.ssh/config:
Host my-ubuntu-server
HostName SERVER_IP
User username
IdentityFile ~/.ssh/my_server_key
If authentication fails, check that the public key is in the correct account’s file, that ownership is correct, and that permissions are restrictive. Ubuntu’s guidance includes chmod go-w ~/.ssh/authorized_keys.
Harden authentication only after key login works
Open a new terminal and prove key login works before disabling passwords. Keep console or recovery access available.
Disable password authentication
Create a local snippet rather than overwriting package-managed defaults:
sudo nano /etc/ssh/sshd_config.d/60-hardening.conf
Add:
PasswordAuthentication no
Depending on your PAM and image configuration, keyboard-interactive authentication may be a separate pathway. If you understand the consequence, you may also set:
KbdInteractiveAuthentication no
Inspect the effective values:
sudo sshd -T | grep -E 'passwordauthentication|kbdinteractiveauthentication|pubkeyauthentication'
Do not assume a line in the main file is authoritative. Ubuntu includes /etc/ssh/sshd_config.d/*.conf, and OpenSSH generally uses the first value encountered for most directives; earlier snippets can win. The Ubuntu OpenSSH guide explains this layout.
Best Value
- 40 Gbps 2000 Mhz High Speed: The Cat 8 ethernet cable support max. 40 Gbps data transfer and 2000 MHz Brandwith, ideal for gaming and streaming, greatly improving upload and download speed, sound, image and resolution quality
- Excellent Anti-interference: The ethernet cable comes with 4 shielded foiled twisted pairs (F/FTP), pure copper core and gold-plated RJ45 connector, reducing interference, noise and crosstalk, making network speed faster and more stable
- Marvelous Durability: Internet cable wrapped with quality cotton braided cord, which makes the LAN cable stronger and more durable. The test proves that this internet cable can be bent at least 10000 times without broken, very suitable for long-term use
- PoE Supported: All lengths of ethernet cord can support the PoE power supply function except 65ft. You don't need additional power supply when installing a PoE camera, which is very convenient and safe
- Wide Compatibility: With the RJ45 Connector, network cable can be perfectly compatible with computers, laptops, modems, routers, PS5, X-Box and other networking devices. It can also be fully backward compatible with Cat7, Cat6e, Cat6, Cat5e, Cat5
Restrict permitted users (advanced)
After confirming a working key for every administrator, add a dedicated rule such as:
AllowUsers username
AllowUsers, AllowGroups, DenyUsers, and DenyGroups can exclude administrators accidentally. Refer to the Jammy sshd_config manual.
Changing the port is optional
A custom port can reduce automated scanning noise but is not a substitute for keys, patching, least privilege, or firewall restrictions. To use 2222:
sudo nano /etc/ssh/sshd_config.d/60-port.conf
Port 2222
sudo ufw allow 2222/tcp
sudo sshd -t
sudo systemctl reload ssh
ssh -p 2222 username@SERVER_IP
Only after the new connection works should you remove the old UFW rule, if appropriate:
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemssudo ufw delete allow OpenSSH
sudo ufw delete allow 22/tcp
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Safely edit and apply configuration
Always validate before reloading or restarting:
sudo sshd -t
sudo systemctl reload ssh
reload rereads settings while usually preserving existing sessions; restart is more disruptive. Use snippets under /etc/ssh/sshd_config.d/ to keep local changes auditable. The primary file is /etc/ssh/sshd_config, and user keys reside in ~/.ssh/authorized_keys.
Troubleshoot common failures
| Symptom | Likely cause | Checks and recovery |
|---|---|---|
| Connection refused | Stopped service, wrong port, or local rejection | sudo systemctl status ssh; sudo ss -tlnp; inspect UFW. |
| Connection timed out | Wrong address, provider firewall, router/NAT, or blocked route | Verify public/private address and external inbound rules. |
| No route to host | Routing or network problem | Confirm the address and test network reachability. |
| Permission denied (publickey) | Wrong user or key, missing key, or permissions | Use ssh -i key -v; inspect that user’s authorized_keys, ownership, and permissions. |
| Password prompt loops | Wrong password or password authentication disabled | Check sudo sshd -T and sudo journalctl -fu ssh.service. |
| Could not resolve hostname | DNS or hostname typo | Try the server IP address. |
| Service fails after editing | Syntax error or unsupported directive | Run sudo sshd -t; restore the last-known-good snippet. |
| Key works for one account only | Key installed in another home directory | Confirm the target username and its ~/.ssh/authorized_keys. |
| Setting appears ignored | An earlier included snippet wins | Inspect /etc/ssh/sshd_config.d/ and run sudo sshd -T. |
| Local login works but remote login does not | Network or external firewall path | Test from another machine; check provider and router rules. |
View service errors with:
sudo journalctl -u ssh --no-pager
sudo journalctl -fu ssh.service
sudo systemctl status ssh
sudo ufw status verbose
Recover from a bad configuration
If the current session still works, identify and disable the newest suspect snippet:
sudo sshd -t
ls -lt /etc/ssh/sshd_config.d/
sudo mv /etc/ssh/sshd_config.d/60-hardening.conf
/etc/ssh/60-hardening.conf.disabled
sudo sshd -t
sudo systemctl reload ssh
If you are locked out, use a local console, cloud web console, virtual-machine console, another administrator, physical access, or a rescue environment. Ubuntu warns that an invalid configuration can stop the service and prevent remote access.
Desktop, cloud, and Windows notes
- Ubuntu Desktop and Ubuntu Server use the same package command, but Desktop does not automatically run an SSH server merely because networking works.
- Cloud images may pre-create provider-specific users and configuration snippets. Check the effective value with
sudo sshd -Trather than relying on one visible file. - Current Windows installations commonly expose
ssh username@SERVER_IPin PowerShell or Command Prompt, but availability depends on the Windows installation. Enable the optional OpenSSH Client feature or use a maintained SSH client if the command is missing. - For IPv4 or IPv6 troubleshooting, force the family with
ssh -4 username@SERVER_IPorssh -6 username@SERVER_IPV6.
Optional defenses and operational choices
- Use a normal account with
sudoinstead of encouraging direct root SSH login. - Keep Ubuntu patched and restrict UFW or provider rules to trusted source addresses where practical.
- Fail2ban can supplement a public server that still permits passwords, but it is not a replacement for keys, patching, account security, or firewall policy.
- Do not uninstall SSH as a first troubleshooting step. To disable it intentionally, ensure console access exists, then run
sudo systemctl disable --now ssh; removing the package withsudo apt remove openssh-servereliminates remote administration.
Where to run Ubuntu 22.04
SSH itself is free and comes from Ubuntu repositories. A local computer needs no hosting purchase. For a VPS, compare current CPU, memory, storage, transfer, backups, IPv4, region, recovery console, and firewall controls rather than choosing on an advertised starting price alone. DigitalOcean lists Droplets at its current pricing page; Lightsail lists eligibility and conditions on AWS Lightsail pricing. Prices, availability, and free-tier conditions change.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




