Linux & Terminal · Cheatsheet
SSH Commands Cheatsheet
SSH connections, key management, SCP/SFTP transfers, tunnels, and security hardening
54 commands 8 sections
No entry matches that filter.
-
ssh user@hostConnect to remote host -
ssh user@host -p 2222Connect on custom port -
ssh -i ~/.ssh/key.pem user@hostConnect with specific key file -
ssh -v user@hostVerbose mode for debugging -
ssh -o StrictHostKeyChecking=no user@hostRelaxes host-key checks and can accept changed keys; avoid this for normal connections -
ssh -J jump@bastion user@targetConnect via jump host (ProxyJump) -
ssh user@host "command"Run single command remotely -
ssh -t user@host "sudo command"Force TTY allocation for sudo
-
ssh-keygen -t ed25519 -C "email@example.com"Generate Ed25519 key pair -
ssh-keygen -t rsa -b 4096Generate 4096-bit RSA key pair -
ssh-copy-id user@hostCopy public key to remote host -
ssh-keygen -l -f ~/.ssh/id_ed25519.pubShow key fingerprint -
ssh-keygen -p -f ~/.ssh/id_ed25519Change passphrase on existing key -
ssh-keygen -R hostnameRemove host from known_hosts -
cat ~/.ssh/id_ed25519.pubDisplay public key for copying
-
eval "$(ssh-agent -s)"Start SSH agent in current shell -
ssh-add ~/.ssh/id_ed25519Add key to SSH agent -
ssh-add -lList keys loaded in agent -
ssh-add -DRemove all keys from agent -
ssh-add -t 3600 ~/.ssh/keyAdd key with 1-hour lifetime -
ssh -A user@hostForward agent to remote host
-
scp file.txt user@host:/remote/path/Copy file to remote host -
scp user@host:/remote/file.txt ./local/Copy file from remote host -
scp -r ./dir user@host:/remote/Copy directory recursively -
scp -P 2222 file.txt user@host:/path/Copy via custom port -
sftp user@hostStart interactive SFTP session -
sftp> put localfile remotepathUpload file via SFTP -
sftp> get remotefile localpathDownload file via SFTP -
rsync -avz ./src user@host:/destSync files efficiently over SSH
-
ssh -L 8080:localhost:80 user@hostLocal port forward (access remote:80 via local:8080) -
ssh -R 9090:localhost:3000 user@hostRemote port forward (expose local:3000) -
ssh -D 1080 user@hostDynamic SOCKS proxy tunnel -
ssh -L 5432:db-server:5432 user@bastionTunnel to internal database -
ssh -fN -L 8080:localhost:80 user@hostBackground tunnel (no shell) -
ssh -O exit user@hostClose a background tunnel
-
Host myserverDefine a connection alias -
HostName 192.168.1.100Server address for alias -
User deployDefault username for connection -
Port 2222Custom port for connection -
IdentityFile ~/.ssh/deploy_keySpecific key for this host -
ProxyJump bastionJump through another host -
Host *Wildcard: apply to all connections -
ServerAliveInterval 60Send keepalive every 60 seconds
-
PermitRootLogin noDisable root SSH login (sshd_config) -
PasswordAuthentication noDisable password login (key only) -
AllowUsers deploy adminAllow only specific users -
Port 2222Change default SSH port -
MaxAuthTries 3Limit authentication attempts -
sudo systemctl restart sshdRestart SSH daemon after changes -
chmod 700 ~/.sshCorrect .ssh directory permissions -
chmod 600 ~/.ssh/id_ed25519Correct private key permissions
-
https://man.openbsd.org/sshOpenSSH client: connections, forwarding, and control commands. -
https://man.openbsd.org/ssh_configOpenSSH client configuration, including host-key verification. -
https://man.openbsd.org/sshd_configOpenSSH server authentication and access settings.
Related cheatsheets
Guides that use these commands
Tools for this work
- Security Headers AnalyzerCheck HTTP security headers for web applications and get improvement recommendations.
- DNS Security ScannerScan DNS records for security configurations including SPF, DKIM, and DMARC.
- Email Security CheckerVerify email domain security with SPF, DKIM, DMARC, and MTA-STS checks.