↑ ↓ select, Enter open, Esc close

#ssh

17 one-liners with this tag.

All one-liners tagged ssh

Allow a port only from a specific IP with ufw

#ufw allow from 198.51.100.0/24 to any port 22 proto tcp
cautionFirewall

Connect to an internal server through a jump host

$ssh -J admin@bastion.example.com webuser@10.0.0.12
harmlessSSH

Copy a directory to another server with tar over SSH

$tar czf - -C /var/www/vhosts/example.com/httpdocs . | ssh webuser@neuserver.example.com "tar xzf - -C /var/www/vhosts/example.com/httpdocs"
cautionSSH

Debug SSH connection problems with verbose output

$ssh -vvv -p 22 webuser@server.example.com
harmlessSSH

Enable ufw without locking yourself out

#ufw allow 22/tcp && ufw enable
destructiveFirewall

Expose a local service on a server with a reverse SSH tunnel

$ssh -N -R 8080:127.0.0.1:3000 webuser@server.example.com
harmlessSSH

IP addresses with the most failed SSH logins

#journalctl -u ssh --since "24 hours ago" --no-pager | grep -oE 'Failed password for .* from [0-9a-f.:]+' | awk '{print $NF}' | sort | uniq -c | sort -rn | head -20
harmlessSecurity

List all SSH keys authorized on the server

#find / -xdev -path '*/.ssh/authorized_keys' -type f -exec awk 'NF && !/^#/ {print FILENAME ": " $NF}' {} + 2>/dev/null
harmlessSecurity

Make a remote port available locally with an SSH tunnel

$ssh -N -L 3307:127.0.0.1:3306 webuser@server.example.com
harmlessSSH

Resume an interrupted transfer of large files

$rsync -avP /var/backups/example.com-2026-10-09.tar.gz webuser@backup.example.com:/home/webuser/backup/
cautionrsync and backup

Reuse SSH connections with ControlMaster

$ssh -o ControlMaster=auto -o ControlPath=~/.ssh/cm-%C -o ControlPersist=10m webuser@server.example.com
harmlessSSH

Run a command on multiple servers one after another

$for h in web1.example.com web2.example.com web3.example.com; do echo "== $h"; ssh -o BatchMode=yes -o ConnectTimeout=5 "$h" 'uptime; df -h /'; done
harmlessSSH

Run a local script on a remote server

$ssh webuser@server.example.com 'bash -s' < ./check.sh
cautionSSH

Run rsync with limited bandwidth

$rsync -avz --bwlimit=5000 /var/www/vhosts/example.com/httpdocs/ webuser@backup.example.com:/home/webuser/backup/httpdocs/
cautionrsync and backup

Set up a SOCKS proxy over an SSH connection

$ssh -N -D 1080 webuser@server.example.com
harmlessSSH

Stream a tar backup directly to another server over SSH

$tar -czf - -C /var/www/vhosts/example.com/httpdocs . | ssh webuser@backup.example.com 'cat > /home/webuser/backup/example.com-httpdocs.tar.gz'
cautionrsync and backup

Transfer files to another server with rsync over SSH

$rsync -avz -e 'ssh -p 22' /var/www/vhosts/example.com/httpdocs/ webuser@backup.example.com:/home/webuser/backup/httpdocs/
cautionrsync and backup

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.