If SSH listens on a nonstandard port, SCP needs to connect to that same port. The easy-to-miss detail is capitalization: use uppercase -P with scp, not lowercase -p.
SCP uses the SSH port
SCP doesn't have a separate network port. It connects through SSH, which uses TCP port 22 by default. If a server's SSH service listens on port 2222, SCP must connect to 2222 too.
For a one-time upload, specify the port like this:
scp -P 2222 report.txt deploy@example.com:/var/tmp/
To download a file, put the remote path first:
scp -P 2222 deploy@example.com:/var/tmp/report.txt .
The final . means the current local directory. The port flag applies to the SSH connection SCP makes; it doesn't change the server's configuration.
Why is the port flag uppercase?
SCP reserves lowercase -p for preserving file modification times and permissions. Use uppercase -P to select the port:
# Use TCP port 2222
scp -P 2222 report.txt deploy@example.com:/var/tmp/
# Preserve times and permissions
scp -p report.txt deploy@example.com:/var/tmp/
The flags can be combined when you need both behaviors:
scp -p -P 2222 report.txt deploy@example.com:/var/tmp/
This differs from the ssh command, which uses lowercase -p for the port:
ssh -p 2222 deploy@example.com
If you're switching between SSH and SCP commands, double-check the capitalization before troubleshooting the server.
Save the port in SSH config
For a host you use regularly, put its connection details in ~/.ssh/config:
Host staging
HostName example.com
User deploy
Port 2222
Then use the alias for either command:
ssh staging
scp report.txt staging:/var/tmp/
SCP reads the same SSH configuration as the SSH client, so the host's configured port is applied without repeating -P. You can also add other per-host settings as needed; see this SSH config example with host-specific options.
Copying between two remote hosts
A single scp -P option isn't a way to assign two different ports to two separate remote hosts. For a one-off transfer between hosts that use different ports, modern OpenSSH supports an SCP URI for each endpoint:
scp scp://alice@host1:2200/var/tmp/file.txt scp://bob@host2:2222/incoming/
Each URI carries its own host and port. By default, current OpenSSH routes a remote-to-remote copy through your local machine, making the two connections separately. The URI approach does not work for specifying a target port when -R is used to have the two remote hosts communicate directly.
If you repeat this kind of transfer, define a separate SSH config alias for each host instead:
Host remote1
HostName host1.example.com
User alice
Port 2200
Host remote2
HostName host2.example.com
User bob
Port 2222
Then the copy can use those aliases:
scp remote1:/var/tmp/file.txt remote2:/incoming/
For other transfer patterns, including copying directories and choosing between SCP and SFTP, this SCP command guide covers useful examples.
When a transfer fails
First check that you're targeting the port where the server's SSH service is listening. A port change on the server affects both SSH logins and SCP transfers.
You can test whether the port is reachable before retrying the copy:
# Linux or macOS
nc -zv example.com 2222
On Windows PowerShell:
Test-NetConnection -ComputerName example.com -Port 2222
A successful port check only tells you that the TCP port is reachable; it doesn't confirm that authentication or the file transfer will succeed. If the port is unreachable, check the server address, network path, and firewall rules. If SSH connects but SCP fails, inspect the error and the remote path permissions rather than changing the port flag.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)