- Moving ssh to a nonstandard port probably isn't worth the hassle. I need to do some actual statistics on this, but I think that if you disable remote password login, and set up fail2ban or equivalent for port 22, that's more than good enough, unless you're a hyperscaler, in which case you probably have a separate control-plane network interface anyway.