CmdKeys LogoCommand Quiz

SSH Command Practice

ssh opens an encrypted channel to a remote host and can forward ports or run commands without an interactive shell. This track drills connection flags (-p, -i, -J), tunnel flags (-L, -R, -D, -f, -N), key generation with ssh-keygen, and known_hosts management — the subset you reach for every time you provision a server or debug a connection.

Command Reference

connect

CommandDescription
ssh -i <keyfile> <user>@<host>Connect using a specific private key file (identity file).
ssh <user>@<host>Open an interactive SSH session to a remote host as a given user.
ssh <alias>Connect using a Host alias defined in ~/.ssh/config.
ssh <user>@<host> -p <port>Connect to a remote host on a non-default port.
ssh <user>@<host> '<command>'Execute a single command on the remote host and return its output locally.
ssh <user>@<host> bash < <script.sh>Pipe a local shell script to bash on the remote host without copying the file.
ssh -J <proxy_host> <remote_host>Connect to a target host by jumping through a bastion or proxy host.
ssh -J <user>@<proxy_host> <user>@<remote_host>Jump through a bastion host specifying explicit users for both the proxy and the target.
ssh -f -N <user>@<host>Send ssh to the background without executing a remote command — used to keep a tunnel open silently.
ssh <user>@<host> "tar cvzf - <dir>" > <output.tgz>Archive a remote directory on the fly and stream it to a local file.
ssh -J <user>@<proxy1>:<port1>,<user>@<proxy2>:<port2> <user>@<remote_host>Chain multiple jump hosts in a single SSH command to reach a deeply nested host.

known-hosts

CommandDescription
ssh-copy-id <user>@<server>Append the default public key to the remote host's authorized_keys file.
ssh-keygen -R <host>Remove a host entry from known_hosts — used after a server is rebuilt and its key changes.
ssh-keygen -F <host>Search known_hosts for an entry matching a hostname or IP address.
ssh-copy-id <alias>Distribute the default public key to a host referenced by a ~/.ssh/config alias.
ssh-copy-id -i <keyfile.pub> <user>@<server>Copy a specific public key file to the remote host's authorized_keys.

keygen

CommandDescription
ssh-keygen -f <keyfile>Generate an SSH key pair and save it to a specified file path instead of the default location.
ssh-keygenGenerate an SSH key pair interactively, prompting for type, file location, and passphrase.
ssh-keygen -t rsa -b 4096 -C <comment>Generate a 4096-bit RSA key pair with an email address or label as a comment.
ssh-keygen -t ed25519 -C <comment>Generate a modern ed25519 key pair — shorter, faster, and more secure than RSA.
ssh-keygen -t ecdsa -b 521 -C <comment>Generate an ECDSA key pair using the strongest 521-bit curve.
ssh-keygen -y -f <private.key>Re-derive and print the public key from an existing private key file.
ssh-keygen -c -f <keyfile>Change the comment on an existing SSH key without regenerating the key pair.
ssh-keygen -p -f <keyfile>Change, add, or remove the passphrase of an existing SSH private key.

tunnel

CommandDescription
ssh -L <local_port>:<remote_host>:<remote_port> <user>@<server>Bind a local port and forward connections to a remote host and port through the SSH server.
ssh -L <local_port>:<target_host>:<target_port> <user>@<server>Forward local port traffic to an internal host visible from the SSH server side.
ssh -D <local_port> <user>@<server>Create a SOCKS5 proxy on a local port so all proxied traffic exits at the remote server.
ssh -f -N -L <local_port>:<remote_host>:<remote_port> <user>@<server>Open a local port-forwarding tunnel in the background without an interactive shell.
ssh -R <remote_port>:<local_host>:<local_port> <user>@<server>Ask the remote server to listen on a port and forward connections back to a local host and port.
ssh -f -N -D <local_port> <user>@<server>Start a SOCKS5 proxy tunnel in the background without an interactive shell.
ssh -L <port1>:<host1>:<rport1> -L <port2>:<host2>:<rport2> <user>@<server>Forward multiple local ports to different remote services in a single SSH connection.
ssh -f -N -g -L <local_port>:<target_host>:<target_port> -i <keyfile> <user>@<server>Background tunnel that allows remote hosts to connect to the forwarded port, authenticated with a custom identity file.

Key Use Cases

  • Connect to a remote host on a non-standard port with an identity file
  • Forward a local port to a service inside a private network via -L
  • Create a SOCKS5 proxy tunnel with -D for dynamic port forwarding
  • Jump through a bastion host to a private server with -J
  • Generate an ed25519 or RSA key pair and distribute the public key
  • Remove a stale host key from known_hosts after a server rebuild

Frequently Asked Questions

What is the difference between -L and -R in SSH?

-L (local forwarding) binds a port on your local machine and forwards traffic to a remote host through the tunnel. -R (remote forwarding) does the reverse — the remote host listens and forwards back to your machine or a local host.

What does ssh -f -N do?

-f sends ssh to the background before command execution. -N tells ssh not to execute a remote command. Together they create a tunnel process that runs silently in the background without an interactive shell.

When do I use ProxyJump (-J) instead of -L?

Use -J when you need a full SSH session to a host that is only reachable through a bastion. Use -L when you only need to forward a specific port from a service on the far side.

Why does ssh-keygen -y need the private key?

The public key is derived from the private key mathematically. -y reads the private key file and prints the corresponding public key to stdout, which is useful if you have the private key but lost the .pub file.

Ready to master SSH commands?

Test your muscle memory with our spaced-repetition quiz system. Free forever.

Start Practice Now →