The best way to set up a remote SSH connection to an IoT device, like a Raspberry Pi, is to turn on SSH on the device, connect with an SSH key instead of a password, and reach it from outside your home through a private VPN rather than opening a port on your router. On your local network, you can connect from Windows, macOS, or Linux by opening a terminal and typing ssh username@device-ip, for example ssh pi@192.168.1.50.
Here’s a secure setup, step by step, using a Raspberry Pi as the example. The same ideas apply to most Linux-based IoT devices.
What you need
- An IoT device running Linux with an SSH server (Raspberry Pi OS includes one).
- A computer with an SSH client. Windows 10 and 11, macOS, and Linux all include one in the terminal.
- The device and computer on the same network for the first setup.
Step 1: Turn on SSH on the device
- New Raspberry Pi setup: In Raspberry Pi Imager, open the OS customization settings, enable SSH, and set a username. You can paste your public key there too.
- Existing Raspberry Pi: Run
sudo raspi-config, choose Interface Options > SSH > Yes. - Other devices: Check the maker’s documentation. Some have an SSH switch in their web settings.
Step 2: Find the device’s IP address
Run hostname -I on the device, or check your router’s list of connected devices. Give the device a reserved IP address (DHCP reservation) in your router so it doesn’t change.
Step 3: Connect with SSH
- Open Terminal or PowerShell on your computer.
- Type
ssh username@device-ipand press Enter. - The first time, check the fingerprint and type yes.
- Enter your password or key passphrase.

Step 4: Use SSH keys instead of passwords
- On your computer, run
ssh-keygen -t ed25519and set a passphrase. - Copy your public key to the device. On macOS or Linux, run
ssh-copy-id username@device-ip. On Windows, copy the contents of %USERPROFILE%\.ssh\id_ed25519.pub into ~/.ssh/authorized_keys on the device. - Test the key login, then turn off password logins on the device: edit /etc/ssh/sshd_config, set
PasswordAuthentication no, and runsudo systemctl restart ssh.
Keep your current session open while testing, so you don’t lock yourself out.
Step 5: Connect securely from anywhere
| Method | Security | Notes |
|---|---|---|
| Mesh VPN (like Tailscale or ZeroTier) | High | Easiest. No router changes, devices get private addresses. |
| Your own VPN (WireGuard or OpenVPN on your router) | High | More setup, full control. |
| Port forwarding SSH on your router | Lower | Exposes SSH to the internet. Only with keys, no passwords, and brute-force protection. |
Keep the device secure
- Update regularly with
sudo apt update && sudo apt full-upgrade. - Change default usernames and passwords.
- Install fail2ban if SSH is reachable from the internet.
- Only run the services you need.
Frequently asked questions
What’s the default SSH port?
Port 22. Changing it reduces automated scans a little, but keys and a VPN matter much more.
Why does SSH say “connection refused”?
SSH isn’t enabled on the device, the IP address is wrong, or a firewall is blocking port 22.
Can I use SSH from my phone?
Yes. Apps like Termius work on iPhone and Android, and they support SSH keys.
Is SSH encrypted?
Yes. All traffic between your computer and the device is encrypted.

Kermit Matthews is a freelance writer based in Philadelphia, Pennsylvania with more than a decade of experience writing technology guides. He has a Bachelor’s and Master’s degree in Computer Science and has spent much of his professional career in IT management.
He specializes in writing content about iPhones, Android devices, Microsoft Office, and many other popular applications and devices.