Disabling SELinux Before Changing the SSH Port
While changing the SSH port, you may find that the new setting does not take effect. Restarting sshd can also fail after the change. One possible cause is that SELinux is enabled and is restricting the new SSH port configuration.
Before changing the port, check the current SELinux status with either of these commands:
[root@localhost ~] #/usr/sbin/sestatus -v
or:
[root@localhost ~] # sestatus
If the output contains:
SELinux status: enabled
SELinux is enabled on the system.
To disable it permanently, open the SELinux configuration file:
[root@localhost ~] # vi /etc/selinux/config
Locate the setting currently defined as SELINUX\=enforcing or SELINUX\=permissive, and change it to:
SELINUX=disabled
Save the file and restart the system. After rebooting, run sestatus again to verify the result. The status should now be:
SELinux status: disabled
SELinux is then disabled, allowing you to continue configuring the SSH port.