To enable incoming SSH connections on Ubuntu, install openssh-server on the Ubuntu machine you want to reach. Then verify that its service or socket is listening and connect from a second machine using a normal Ubuntu user account.
ssh -V checks the SSH client. It does not prove that the server is installed or accepting connections. This guide keeps those checks separate.
Install and check the server package
Run these commands on the destination Ubuntu machine, where you have administrator access:
sudo apt update
sudo apt install openssh-serverIf the package is already installed, check its installation state directly:
dpkg-query -W -f='${Status}\n' openssh-serverinstall ok installed confirms the package state. It does not confirm that the service is listening, that a firewall permits access or that your account can authenticate. The package installation may start the server, depending on the environment.
Inspect the service and listening socket
On a normal Ubuntu installation using systemd:
systemctl status ssh.service ssh.socket --no-pager
sudo ss -ltnpLook for a listener on the configured SSH port, normally TCP 22. Some Ubuntu installations use socket activation: ssh.socket holds the listening socket and activates the service when needed. A missing socket unit on a service-based installation is not by itself a failure.
If SSH is inactive and the installation provides ssh.socket, start and enable that unit:
sudo systemctl enable --now ssh.socketIf it instead uses the traditional service without a socket unit, use:
sudo systemctl enable --now ssh.serviceChoose the branch matching the installed configuration rather than blindly enabling both. Recheck the status and listener afterward. If systemctl itself fails, use our environment diagnostic guide before changing packages.
Allow the intended connection
Check the Ubuntu firewall if UFW is in use:
sudo ufw status verboseFor an active UFW firewall and default SSH port, you can allow a specific client address. This documentation address is an example; replace it with the real trusted client's address as seen by the server:
sudo ufw allow from 192.0.2.10 to any port 22 proto tcpIf you use a different port, match that port. Cloud firewalls, network policies and router/NAT rules are separate from UFW. Use the appropriate private address or VPN route where available. Merely knowing a machine's public address does not make a private machine behind it reachable.
Do not enable a previously inactive firewall over your only remote connection without first reviewing all required access and having a recovery path. No firewall or port change is needed if the intended connection already works.
Connect from another machine
Replace the example account and address below with those of your Ubuntu machine:
ssh youruser@192.0.2.20For a nondefault port, use ssh -p 2222 youruser@192.0.2.20, replacing 2222 with the configured port. On the first connection, compare the presented host-key fingerprint with the server's fingerprint obtained through a trusted console or administrator. Do not accept an unexpected host-key change blindly.
On the server, an administrator can display the Ed25519 host-key fingerprint, when that key exists, with:
sudo ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pubAuthenticate using the account's configured method. Cloud images often expect a key rather than a password. Keep your private key on the client. After connecting, run whoami and hostname to confirm the account and destination before making changes.
Read the error before changing authentication
| Message or symptom | What it suggests |
|---|---|
| Connection refused | The destination rejected the connection. Check address, port, listener and rejection rules. |
| Connection timed out | Investigate routing, filtering, reachability and the destination address. |
| Permission denied (publickey) | The SSH connection reached authentication. Check account name, selected key and server authorization rules. |
| Remote host identification has changed | Verify the server's identity through a trusted channel before changing your known-host record. |
For additional client diagnostics, use ssh -v youruser@192.0.2.20. Its output can contain usernames, paths and network details; redact those before sharing it.
Keep configuration changes small
You do not need to enable root password login to enable SSH. The setting PermitRootLogin prohibit-password disables password and keyboard-interactive authentication for root; it does not mean all root authentication is forbidden. Use a normal account with the privileges required for the task.
If you edit server configuration, include files under /etc/ssh/sshd_config.d/ may affect the result. Validate syntax before applying changes:
sudo /usr/sbin/sshd -tA successful syntax check normally prints nothing. Keep the current working session open, apply changes using the service/socket procedure appropriate to your release, and confirm a second connection before closing the first. Socket-activated installations can require additional handling for changes to listening addresses or ports; consult the Ubuntu documentation.
Once connected, you can check Linux disk space or run your scripts. For a script that fails after login, distinguish command lookup errors from file permission errors.
Sources and verification
Revised September 11, 2026. The OpenSSH package installation, package-state check, server syntax check, listening-port check and a non-root key-authenticated SSH connection were tested in an isolated Ubuntu 24.04 container. Test SSH listened only on container loopback with no published host port. Systemd socket activation, UFW changes and remote network access were checked against documentation, not executed as part of that container test. This revision replaces two overlapping legacy setup guides.
- Ubuntu: OpenSSH server
- Ubuntu 24.04 release notes: SSH socket activation
- Ubuntu: firewall rules
- OpenSSH: server configuration on Ubuntu
If the server name is the problem
If SSH cannot resolve the destination name, follow the Ubuntu name-resolution checklist. When intentionally renaming a server, check the hostname and DNS update steps before changing client aliases.
