SSH config File on Linux: Host Aliases, Keys, Ports and ProxyJump

ssh config file linux - custom-sshcfg-featured.png

Tired of typing ssh -i key -p 2222 [email protected]? The SSH client config file
~/.ssh/config stores defaults per host alias. It is one of the most searched SSH topics after key generation.

Pair with SSH keys and
tunneling.

Basic Host Block

Each Host stanza matches the name you type after ssh.

ssh-config~/.ssh/config example
Host web1
    HostName web1.internal.example
    User deploy
    Port 22
~/.ssh/config
Host alias

Per-Host Private Keys

Use IdentityFile when you have multiple keys; add IdentitiesOnly yes to stop SSH offering every key.

IdentityFile
multiple keys

ProxyJump Through a Bastion

Modern syntax for jumping through a jump host in one command.

ssh-configjump host
Host db-via-bastion
    HostName 10.0.0.50
    User deploy
    ProxyJump bastion.example
    IdentityFile ~/.ssh/deploy_ed25519
ProxyJump
bastion

Custom SSH Port

Set Port in the matching Host block — global Host * defaults are possible but use carefully.

Port
non-22

Agent Forwarding Caution

ForwardAgent yes is convenient and risky on untrusted jump boxes — leave off unless you understand the tradeoff.

WarningPrefer ProxyJump and direct keys over agent forwarding when possible.
ForwardAgent
security

Test Resolved Config

ssh -G hostname prints the effective configuration after merges.

bashtest
ssh -G web1 | grep -E '^(hostname|user|port|identityfile) '
ssh -G
debug

Permissions Matter

OpenSSH ignores config if permissions are too open.

bashfix perms
chmod 700 ~/.ssh
chmod 600 ~/.ssh/config ~/.ssh/id_*
chmod
700 and 600

Quick Reference

  • Host alias + HostName + User
  • ProxyJump for bastion access
  • chmod 600 on config and keys

Related tutorials

Diagrams are original illustrations by Gnome IT Solutions. Tutorial text © Gnome IT Solutions.