SSH Cheatsheet - SSH Connection & Configuration Command Reference

For developers and ops who want passwordless login, hop through bastion hosts into the internal network, or map a remote port to localhost for debugging. The value of SSH lies in reusing keys and config: pin frequently used Hosts, jump hosts, and port forwards into ~/.ssh/config instead of retyping long argument sets each time. By the end you can generate and correctly permission a key pair for passwordless login, hop through bastions with ProxyJump, and expose a remote service on localhost with -L for debugging.

SysOps·21 commands·Last updated 2026-07-21
sshSecretsTunnelslinux

Typical Use Case

Remote login and file transfer, passwordless key-based login, port forwarding (tunnels), and troubleshooting connection timeouts, permission-too-open rejections, and host key change alerts.

Connection & Auth 5

ssh user@host
Login on default port 22, omits user for current username
ssh -p 2222 user@host
Specify port when server uses non-default port
ssh -i ~/.ssh/id_ed25519 user@host
Specify private key, common with multiple keys
ssh -vvv user@host
Verbose debug output for troubleshooting auth failures
ssh -o ConnectTimeout=5 user@host
Set connection timeout to prevent hanging

Key Management 5

ssh-keygen -t ed25519 -C "tom@example.com"
Generate ed25519 key, shorter and faster than RSA
ssh-keygen -t rsa -b 4096 -C "tom@example.com"
Generate RSA 4096-bit key, compatible with older servers
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@host
Copy public key to server for passwordless login
ssh-keygen -lf ~/.ssh/id_ed25519.pub
View key fingerprint and length, verify server host key
eval $(ssh-agent) && ssh-add ~/.ssh/id_ed25519
Start agent and load private key, avoid repeated passwords

Config File ~/.ssh/config 6

Host prod
Define host alias, then ssh prod connects directly
HostName 1.2.3.4
Actual IP or domain to connect to
User deploy
Default login user, saves typing user@host each time
IdentityFile ~/.ssh/id_ed25519
Specify private key for this host
ProxyJump bastion
Connect through a jump host, replaces ssh -t ssh -t multi-hop
LocalForward 8080 127.0.0.1:80
Auto-setup local port forwarding on login

Port Forwarding & Proxy 5

ssh -L 8080:127.0.0.1:80 user@host
Local port forwarding, access local:8080 = remote:80
ssh -R 9090:127.0.0.1:80 user@host
Remote port forwarding, expose local service remotely
ssh -D 1080 user@host
Dynamic SOCKS5 proxy, all traffic goes through remote
ssh -N -L 8080:127.0.0.1:80 user@host
Forward only, no command execution, for background tunnels
ssh -J bastion user@internal
Direct connection through jump host, equivalent to ProxyJump

Parameter matrix

参数EffectExample
-i指定私钥文件ssh -i ~/.ssh/id_ed25519 user@host
-p指定端口(默认 22)ssh -p 2222 user@host
-L本地端口转发隧道ssh -L 8080:127.0.0.1:80 user@host
-R远程端口转发隧道ssh -R 9000:localhost:3000 user@host
-N只建隧道不打开 shellssh -N -L 5432:localhost:5432 db@host
-f后台运行ssh -fN -L 8080:localhost:80 user@host
scp -r递归拷贝目录scp -r ./app user@host:/srv/app
StrictHostKeyChecking控制主机指纹校验策略ssh -o StrictHostKeyChecking=no user@host
ProxyJump经跳板机连接目标ssh -J jump@bastion user@host
IdentitiesOnly只用指定密钥,避免密钥过多被拒ssh -o IdentitiesOnly=yes -i key user@host

Common pitfalls

Symptom密钥登录报 Permission denied (publickey)。

Cause私钥权限过宽(如 644)、authorized_keys 权限不对,或服务端 PubkeyAuthentication 关闭。

Fixchmod 600 ~/.ssh/id_* 与 700 ~/.ssh;服务端确认 PubkeyAuthentication yes 与 AuthorizedKeysFile 路径。

Symptom连接长时间无响应后超时。

Cause网络不可达、防火墙拦截 22、或 UseDNS 反向解析慢。

Fix先 ping/ telnet host 22 验证连通;服务端设 UseDNS no 与 GSSAPIAuthentication no 加速握手。

SymptomWARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!

Cause目标主机重装/换 IP,指纹与 known_hosts 不符(可能中间人)。

Fix确属正常变更后,ssh-keygen -R host 删除旧记录再重连;异常变更须先核实再继续。

Symptomscp/ssh 因客户端有多个密钥被服务端拒绝。

Causessh 依次尝试所有密钥,触发服务端 MaxAuthTries 限制。

Fix用 -o IdentitiesOnly=yes -i 指定唯一密钥;或在 ~/.ssh/config 按主机绑定 IdentityFile。

Symptom隧道建立后端口仍连不上。

Cause转发目标地址在远端不是 localhost,或 BindAddress 受限。

Fix确认 -L 本地:远端host:远端port 的远端地址在服务器本地可达;检查 GatewayPorts 设置。

Symptomroot 直接登录被拒。

CausePermitRootLogin 设为 no(安全最佳实践)。

Fix用普通用户登录后 sudo;确需 root 时设 PermitRootLogin prohibit-password 并仅用密钥。

Troubleshooting

  1. 1详细输出连接过程

    ssh -v user@host

    看到是认证失败、握手慢还是连接被拒,定位阶段。

  2. 2验证端口连通性

    nc -zv host 22

    区分网络层不通与服务未监听。

  3. 3清理失效主机指纹后重连

    ssh-keygen -R host

    仅在确认主机变更合法后执行。

  4. 4测试免密登录是否生效

    ssh -o BatchMode=yes user@host echo ok

    BatchMode 下不会弹出密码提示,可直接验证密钥登录。

Tips

  • Use ssh-copy-id for passwordless login — manually editing authorized_keys is error-prone with permissions and format.
  • ~/.ssh directory must be 700, private keys must be 600 — SSH refuses keys with loose permissions.
  • Add -N -f to run port forwarding in the background, but remember to stop with ssh -O exit or kill to avoid lingering processes.

Official References

Each command links to its official documentation below, so you can verify the latest usage and read deeper.

Maintained by LaoHand

Publicly updated on Jul 21, 2026, continuously proofread against official docs.

Contact Us

Wrong command or description? Send us corrections, business inquiries or product feedback by email.

Contact Us