Skip to main content

SSH Config Cheatsheet

By Dejan Panovski •Updated on • Download PDF

SSH client config directives at a glance: Host and Match patterns, keys, jump hosts, keepalives, multiplexing, port forwarding, host key checking, and tokens for ~/.ssh/config.

The SSH client config file stores per-host settings so that ssh myserver replaces a long command with flags for the user, port, key, and jump host. This cheatsheet lists the ~/.ssh/config directives you use most often, how OpenSSH matches and applies them, and the commands that show the settings ssh actually uses.

File Locations

ssh reads the command line first, then your config, then the system config.

PathDescription
~/.ssh/configPer-user client config
/etc/ssh/ssh_configSystem-wide client config for every user
/etc/ssh/ssh_config.d/*.confSystem drop-ins, loaded by Include on Ubuntu and Debian
chmod 600 ~/.ssh/configRecommended permissions; ssh rejects a file others can write
ssh -F ~/alt-config hostUse a different config file and skip the defaults
ssh -F none hostIgnore every config file

Inspect the Effective Config

Check what ssh will use before you connect.

CommandDescription
ssh -G hostPrint every option that applies to host, then exit
ssh -G host | grep -i proxyjumpCheck one option
ssh -v hostShow which config lines and keys are applied while connecting
ssh -o User=admin hostOverride a config value for one connection
ssh -T git@github.comTest a host without opening a shell

Host Patterns

A Host line starts a block that runs until the next Host or Match line.

PatternMatches
Host webThe alias web only
Host web1 web2 dbAny of the listed names
Host *.example.comEvery host under example.com
Host 192.168.1.?Single-character wildcard
Host *.example.com !legacy.example.comAll but the negated host
Host *Every host; put it at the end for defaults

The first value wins for most directives; repeated IdentityFile entries accumulate. Put specific blocks above general ones and Host * last.

Match Blocks

Match applies a block based on conditions, not just the name.

DirectiveDescription
Match host db*Hostname after HostName is applied
Match originalhost db*Name as typed on the command line
Match user rootRemote user
Match localuser aliceLocal account running ssh
Match host *.corp exec "nc -z vpn.corp 22"Apply only when a command exits 0
Match allClose a conditional block and match everything again

Connection Basics

The directives most host blocks need.

DirectiveDescription
HostName 203.0.113.10Real hostname or IP behind the alias
User adminRemote login name
Port 2222Remote port; default is 22
AddressFamily inetForce IPv4 (inet6 for IPv6)
ConnectTimeout 10Give up after 10 seconds
ConnectionAttempts 3Retry the connection before failing
Compression yesCompress traffic on slow links

Keys and Authentication

Pick the key per host and stop ssh from trying every key it has.

DirectiveDescription
IdentityFile ~/.ssh/id_ed25519_workPrivate key for this host
IdentitiesOnly yesOffer only the configured keys, not every agent key
AddKeysToAgent yesAdd the key to the running agent after first use
CertificateFile ~/.ssh/id_ed25519-cert.pubSSH certificate to present
PreferredAuthentications publickeyTry public-key authentication only
PasswordAuthentication noDisable password authentication; keyboard-interactive prompts can still occur
KbdInteractiveAuthentication noDisable keyboard-interactive authentication, including its password prompts
IgnoreUnknown UseKeychainSkip options that this ssh build does not know
UseKeychain yesmacOS only: store key passphrases in the keychain

Jump Hosts

Reach private hosts through a bastion.

DirectiveDescription
ProxyJump bastionConnect through the bastion alias
ProxyJump admin@bastion.example.com:2222Jump host with user and port
ProxyJump bastion1,bastion2Chain several jump hosts in order
ProxyJump noneDisable jumping; place this before a matching broader block
ProxyCommand ssh -W %h:%p bastionOlder equivalent of ProxyJump
ssh -J bastion internalSame jump from the command line

Keepalives

Stop idle sessions from being dropped by NAT or firewalls.

DirectiveDescription
ServerAliveInterval 60Send a keepalive after 60 seconds without server data
ServerAliveCountMax 3Disconnect after 3 unanswered keepalives
TCPKeepAlive yesTCP-level keepalives; on by default

Multiplexing

Reuse one TCP connection for later sessions to the same host.

Directive or commandDescription
ControlMaster autoOpen a master connection, or reuse an existing one
ControlPath ~/.ssh/cm-%CSocket path; %C keeps it short and unique
ControlPersist 10mKeep the master open 10 minutes after the last session
ssh -O check hostCheck whether a master connection is running
ssh -O exit hostClose the master connection

Port Forwarding

Set up tunnels every time you connect to a host.

DirectiveDescription
LocalForward 8080 localhost:80Local port 8080 to port 80 on the remote side
LocalForward 3307 db.internal:3306Reach a host that only the server can see
RemoteForward 9000 localhost:3000Remote port 9000 to local port 3000
DynamicForward 1080SOCKS proxy on local port 1080
ExitOnForwardFailure yesAbort if a forward cannot be set up
ForwardAgent yesForward your agent; set it only for trusted hosts
ForwardX11 yesForward X11 for GUI applications

Host Key Checking

Control how ssh treats new and changed server keys.

DirectiveDescription
StrictHostKeyChecking askPrompt for new hosts; the default
StrictHostKeyChecking accept-newTrust new hosts, still refuse changed keys
StrictHostKeyChecking yesRefuse any host not in known_hosts
UserKnownHostsFile ~/.ssh/known_hosts_labSeparate known_hosts file for a group of hosts
UserKnownHostsFile /dev/nullDo not record keys; for throwaway VMs only
HashKnownHosts yesHash hostnames written to known_hosts
UpdateHostKeys yesAccept additional keys the server announces

Session and Environment

Change what happens after you log in.

DirectiveDescription
RemoteCommand tmux new -A -s mainRun a command instead of a login shell
RequestTTY yesAllocate a terminal; needed with RemoteCommand for interactive tools
SetEnv APP_ENV=prodSend a variable; the server must allow it with AcceptEnv
SendEnv LANG LC_*Pass local variables by name
LogLevel ERRORHide warnings; DEBUG for troubleshooting
Include ~/.ssh/config.d/*Load more files; put it at the top of the file

Tokens

Expanded in ControlPath, IdentityFile, RemoteCommand, and similar directives. Supported tokens vary by directive.

TokenExpands To
%hRemote hostname after HostName
%nHostname as typed on the command line
%pRemote port
%rRemote user
%uLocal user
%dLocal home directory
%CHash of local host, remote host, port, remote user, and jump-host setting
%%A literal %

ProxyCommand accepts only %%, %h, %n, %p, and %r.

Troubleshooting

ProblemCheck
Bad owner or permissions on ~/.ssh/configCheck ownership with ls -l ~/.ssh/config; the owner must be you or root. Fix incorrect ownership, then run chmod 600 ~/.ssh/config
Bad configuration optionTypo, or an option this ssh version lacks; see man ssh_config
Option is ignoredAn earlier block set it first; check ssh -G host
Too many authentication failuresAdd IdentitiesOnly yes and an IdentityFile
Permission denied (publickey)ssh -v host and look for Offering public key
too long for Unix domain socketShorten ControlPath; use %C instead of %r@%h:%p

Use these articles for full SSH client workflows.

GuideDescription
Using the SSH Config FileHost blocks, patterns, precedence, and examples
SSH Command in Linuxssh options and connection examples
How to Set Up SSH TunnelingLocal, remote, and dynamic port forwarding
SSH Folder Files and PermissionsWhat lives in ~/.ssh and the correct modes
SSH Cheatsheetssh, keys, agent, scp, and sftp commands