InfraKit 39+ Programmatic Tools
Security • 6 min read • Published September 27, 2026

Hardening Linux SSH Servers: Port Selection, ED25519 Keys, and UFW Configuration

Step-by-step security blueprint for locking down OpenSSH listeners, eliminating brute-force attacks, and enforcing strict packet filtering with UFW and iptables.

IK
InfraKit Engineering Infrastructure Research & Systems Architecture

The Threat Landscape Targeting Port 22

Any server with an IP address routed to the public internet will experience automated dictionary and brute-force authentication attacks on TCP port 22 within minutes of provisioning. Botnets continuously scan the entire IPv4 address space searching for default credentials and known OpenSSH vulnerabilities.

Core Hardening Checklist

  • Disable Root Login: In /etc/ssh/sshd_config, configure PermitRootLogin no.
  • Disable Password Authentication: Enforce public key authentication via PasswordAuthentication no.
  • Use Modern Cryptography: Deprecate RSA 1024/2048 keys and generate modern elliptic curve keys with ssh-keygen -t ed25519.
  • Deploy Rate-Limiting: Install Fail2ban or CrowdSec to dynamically block offending IP blocks after 3 failed attempts.

For complete technical specifications and firewall rules for Port 22, view our dedicated Port 22 (SSH) Security Guide.

Interactive Utilities for this Guide

Put the concepts from this guide into practice with zero latency using our client-side calculators and generators.