SSH Cheatsheet - SSH Connection & Configuration Command Reference
For developers and ops who want passwordless login, hop through bastion hosts into the internal network, or map a remote port to localhost for debugging. The value of SSH lies in reusing keys and config: pin frequently used Hosts, jump hosts, and port forwards into ~/.ssh/config instead of retyping long argument sets each time. By the end you can generate and correctly permission a key pair for passwordless login, hop through bastions with ProxyJump, and expose a remote service on localhost with -L for debugging.
Typical Use Case
Remote login and file transfer, passwordless key-based login, port forwarding (tunnels), and troubleshooting connection timeouts, permission-too-open rejections, and host key change alerts.
Connection & Auth 5
ssh user@hostssh -p 2222 user@hostssh -i ~/.ssh/id_ed25519 user@hostssh -vvv user@hostssh -o ConnectTimeout=5 user@hostKey Management 5
ssh-keygen -t ed25519 -C "tom@example.com"ssh-keygen -t rsa -b 4096 -C "tom@example.com"ssh-copy-id -i ~/.ssh/id_ed25519.pub user@hostssh-keygen -lf ~/.ssh/id_ed25519.pubeval $(ssh-agent) && ssh-add ~/.ssh/id_ed25519Config File ~/.ssh/config 6
Host prodHostName 1.2.3.4User deployIdentityFile ~/.ssh/id_ed25519ProxyJump bastionLocalForward 8080 127.0.0.1:80Port Forwarding & Proxy 5
ssh -L 8080:127.0.0.1:80 user@hostssh -R 9090:127.0.0.1:80 user@hostssh -D 1080 user@hostssh -N -L 8080:127.0.0.1:80 user@hostssh -J bastion user@internalParameter matrix
| 参数 | Effect | Example |
|---|---|---|
-i | 指定私钥文件 | ssh -i ~/.ssh/id_ed25519 user@host |
-p | 指定端口(默认 22) | ssh -p 2222 user@host |
-L | 本地端口转发隧道 | ssh -L 8080:127.0.0.1:80 user@host |
-R | 远程端口转发隧道 | ssh -R 9000:localhost:3000 user@host |
-N | 只建隧道不打开 shell | ssh -N -L 5432:localhost:5432 db@host |
-f | 后台运行 | ssh -fN -L 8080:localhost:80 user@host |
scp -r | 递归拷贝目录 | scp -r ./app user@host:/srv/app |
StrictHostKeyChecking | 控制主机指纹校验策略 | ssh -o StrictHostKeyChecking=no user@host |
ProxyJump | 经跳板机连接目标 | ssh -J jump@bastion user@host |
IdentitiesOnly | 只用指定密钥,避免密钥过多被拒 | ssh -o IdentitiesOnly=yes -i key user@host |
Common pitfalls
Symptom密钥登录报 Permission denied (publickey)。
Cause私钥权限过宽(如 644)、authorized_keys 权限不对,或服务端 PubkeyAuthentication 关闭。
Fixchmod 600 ~/.ssh/id_* 与 700 ~/.ssh;服务端确认 PubkeyAuthentication yes 与 AuthorizedKeysFile 路径。
Symptom连接长时间无响应后超时。
Cause网络不可达、防火墙拦截 22、或 UseDNS 反向解析慢。
Fix先 ping/ telnet host 22 验证连通;服务端设 UseDNS no 与 GSSAPIAuthentication no 加速握手。
SymptomWARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!
Cause目标主机重装/换 IP,指纹与 known_hosts 不符(可能中间人)。
Fix确属正常变更后,ssh-keygen -R host 删除旧记录再重连;异常变更须先核实再继续。
Symptomscp/ssh 因客户端有多个密钥被服务端拒绝。
Causessh 依次尝试所有密钥,触发服务端 MaxAuthTries 限制。
Fix用 -o IdentitiesOnly=yes -i 指定唯一密钥;或在 ~/.ssh/config 按主机绑定 IdentityFile。
Symptom隧道建立后端口仍连不上。
Cause转发目标地址在远端不是 localhost,或 BindAddress 受限。
Fix确认 -L 本地:远端host:远端port 的远端地址在服务器本地可达;检查 GatewayPorts 设置。
Symptomroot 直接登录被拒。
CausePermitRootLogin 设为 no(安全最佳实践)。
Fix用普通用户登录后 sudo;确需 root 时设 PermitRootLogin prohibit-password 并仅用密钥。
Troubleshooting
1详细输出连接过程
ssh -v user@host看到是认证失败、握手慢还是连接被拒,定位阶段。
2验证端口连通性
nc -zv host 22区分网络层不通与服务未监听。
3清理失效主机指纹后重连
ssh-keygen -R host仅在确认主机变更合法后执行。
4测试免密登录是否生效
ssh -o BatchMode=yes user@host echo okBatchMode 下不会弹出密码提示,可直接验证密钥登录。
Tips
- Use ssh-copy-id for passwordless login — manually editing authorized_keys is error-prone with permissions and format.
- ~/.ssh directory must be 700, private keys must be 600 — SSH refuses keys with loose permissions.
- Add -N -f to run port forwarding in the background, but remember to stop with ssh -O exit or kill to avoid lingering processes.
Official References
Each command links to its official documentation below, so you can verify the latest usage and read deeper.
Maintained by LaoHand
Publicly updated on Jul 21, 2026, continuously proofread against official docs.
Contact Us
Wrong command or description? Send us corrections, business inquiries or product feedback by email.
Contact Us