SSH is turned on through the OpenSSH server package, which you install and then start using three terminal commands

SSH (Secure Shell) lets you log into your Ubuntu machine from another computer over a network. By default, Ubuntu does not have SSH running. To turn it on, you install the OpenSSH server package, start the service, and configure your firewall to allow SSH traffic. The whole process takes about five minutes if you already have terminal access to the machine.

You will need either a terminal window open on the Ubuntu machine itself, or access through a tool like VNC or a physical console. You cannot enable SSH remotely if it is not already running.

Key Takeaways

  • Install OpenSSH server by running sudo apt update followed by sudo apt install openssh-server in the terminal.
  • Start the SSH service immediately with sudo systemctl start ssh and set it to run at startup with sudo systemctl enable ssh.
  • Allow SSH through the firewall by running sudo ufw allow 22/tcp if UFW is active on your system.
  • Verify SSH is running by checking the service status with sudo systemctl status ssh, which should show "active (running)".
  • Find your Ubuntu machine's IP address with hostname -I so you know what address to connect to from another computer.

Installing OpenSSH Server

Open a terminal on your Ubuntu machine. You can do this by pressing Ctrl + Alt + T, or by clicking the terminal icon in your application menu.

First, update your package list by typing:

sudo apt update

Press Enter and wait for the update to finish. Then install the OpenSSH server package:

sudo apt install openssh-server

The system will ask you to confirm. Type y and press Enter. The installation takes a minute or two depending on your internet speed.

Starting the SSH Service

Once installation is complete, start the SSH service immediately:

sudo systemctl start ssh

This turns on SSH right now, but it will stop if you restart the machine. To make SSH start automatically every time Ubuntu boots, run:

sudo systemctl enable ssh

You only need to run the enable command once. After that, SSH will be running whenever your machine is on.

Opening the Firewall for SSH

Ubuntu comes with a firewall tool called UFW (Uncomplicated Firewall). If it is active, it will block SSH connections by default. Check whether UFW is running:

sudo ufw status

If the output says "Status: active", you need to allow SSH traffic. Run:

sudo ufw allow 22/tcp

SSH uses port 22 by default. This command tells the firewall to accept incoming connections on that port. If UFW shows "Status: inactive", you can skip this step — the firewall is not blocking anything.

Checking That SSH Is Running

Verify the service is active and running:

sudo systemctl status ssh

The output should show a line that says "active (running)" in green. If it shows "inactive (dead)", go back and run sudo systemctl start ssh again.

You can also check whether SSH is listening on port 22:

sudo ss -tlnp | grep ssh

This command lists all services listening on network ports. If SSH is running, you will see a line with "sshd" (the SSH daemon) and port 22.

Finding Your Ubuntu Machine's IP Address

To connect to your Ubuntu machine from another computer, you need its IP address on your network. Run:

hostname -I

This prints one or more IP addresses. If you are on a home or office network, it will likely start with 192.168 or 10.0. Write down this address — you will use it when connecting from another machine.

If you see multiple addresses, use the one that matches your network. If you are unsure which one is correct, try them in order when you attempt to connect.

Connecting to Your Ubuntu Machine Over SSH

From another computer (Windows, Mac, or Linux), open a terminal or command prompt and type:

ssh username@192.168.1.100

Replace username with your Ubuntu login name and 192.168.1.100 with the IP address you found above. Press Enter.

The first time you connect, you will see a message asking whether you trust this host. Type yes and press Enter. Then enter your Ubuntu password when prompted. You are now logged in to your Ubuntu machine remotely.

Frequently Asked Questions

What if I get "Connection refused" when I try to connect?

SSH is either not running or the firewall is still blocking it. Go back to your Ubuntu terminal and run sudo systemctl status ssh to check if the service is active. If it shows "inactive", run sudo systemctl start ssh. If it shows "active" but you still cannot connect, check that you allowed port 22 through the firewall with sudo ufw allow 22/tcp.

Can I change the SSH port from 22 to something else?

Yes, but it requires editing the SSH configuration file. Open /etc/ssh/sshd_config in a text editor with sudo nano /etc/ssh/sshd_config, find the line that says #Port 22, remove the #, change the number, and save. Then run sudo systemctl restart ssh and update your firewall rule to allow the new port instead of 22.

Do I need a password every time I connect over SSH?

Yes, by default. You can set up key-based authentication instead, which uses a pair of cryptographic keys rather than a password. This is more secure and faster, but requires additional setup on both your Ubuntu machine and the computer you are connecting from.

What if I only want certain users to be able to connect over SSH?

Edit the SSH configuration file at /etc/ssh/sshd_config and add a line like AllowUsers username1 username2 at the bottom, listing only the usernames you want to allow. Save the file and run sudo systemctl restart ssh for the change to take effect.