How to Set Up a Secure Remote SSH Connection to an IoT Device

The best way to set up a remote SSH connection to an IoT device, like a Raspberry Pi, is to turn on SSH on the device, connect with an SSH key instead of a password, and reach it from outside your home through a private VPN rather than opening a port on your router. On your local network, you can connect from Windows, macOS, or Linux by opening a terminal and typing ssh username@device-ip, for example ssh pi@192.168.1.50.

Here’s a secure setup, step by step, using a Raspberry Pi as the example. The same ideas apply to most Linux-based IoT devices.

What you need

  • An IoT device running Linux with an SSH server (Raspberry Pi OS includes one).
  • A computer with an SSH client. Windows 10 and 11, macOS, and Linux all include one in the terminal.
  • The device and computer on the same network for the first setup.

Step 1: Turn on SSH on the device

  • New Raspberry Pi setup: In Raspberry Pi Imager, open the OS customization settings, enable SSH, and set a username. You can paste your public key there too.
  • Existing Raspberry Pi: Run sudo raspi-config, choose Interface Options > SSH > Yes.
  • Other devices: Check the maker’s documentation. Some have an SSH switch in their web settings.

Step 2: Find the device’s IP address

Run hostname -I on the device, or check your router’s list of connected devices. Give the device a reserved IP address (DHCP reservation) in your router so it doesn’t change.

Step 3: Connect with SSH

  1. Open Terminal or PowerShell on your computer.
  2. Type ssh username@device-ip and press Enter.
  3. The first time, check the fingerprint and type yes.
  4. Enter your password or key passphrase.
Terminal window showing an ssh command to an IoT device and the remote device prompt after connecting
(1) Run ssh with the device’s username and IP, then (2) you’re working on the device. (Illustration)

Step 4: Use SSH keys instead of passwords

  1. On your computer, run ssh-keygen -t ed25519 and set a passphrase.
  2. Copy your public key to the device. On macOS or Linux, run ssh-copy-id username@device-ip. On Windows, copy the contents of %USERPROFILE%\.ssh\id_ed25519.pub into ~/.ssh/authorized_keys on the device.
  3. Test the key login, then turn off password logins on the device: edit /etc/ssh/sshd_config, set PasswordAuthentication no, and run sudo systemctl restart ssh.

Keep your current session open while testing, so you don’t lock yourself out.

Step 5: Connect securely from anywhere

Method Security Notes
Mesh VPN (like Tailscale or ZeroTier) High Easiest. No router changes, devices get private addresses.
Your own VPN (WireGuard or OpenVPN on your router) High More setup, full control.
Port forwarding SSH on your router Lower Exposes SSH to the internet. Only with keys, no passwords, and brute-force protection.

Keep the device secure

  • Update regularly with sudo apt update && sudo apt full-upgrade.
  • Change default usernames and passwords.
  • Install fail2ban if SSH is reachable from the internet.
  • Only run the services you need.

Frequently asked questions

What’s the default SSH port?

Port 22. Changing it reduces automated scans a little, but keys and a VPN matter much more.

Why does SSH say “connection refused”?

SSH isn’t enabled on the device, the IP address is wrong, or a firewall is blocking port 22.

Can I use SSH from my phone?

Yes. Apps like Termius work on iPhone and Android, and they support SSH keys.

Is SSH encrypted?

Yes. All traffic between your computer and the device is encrypted.