DEV Community

dpm_bush
dpm_bush

Posted on Originally published at sshflow.com

Using SCP on a Custom Port (and Avoiding the -p vs -P Mix-Up)

If SSH listens on a nonstandard port, SCP needs to connect to that same port. The easy-to-miss detail is capitalization: use uppercase -P with scp, not lowercase -p.

SCP uses the SSH port

SCP doesn't have a separate network port. It connects through SSH, which uses TCP port 22 by default. If a server's SSH service listens on port 2222, SCP must connect to 2222 too.

For a one-time upload, specify the port like this:

scp -P 2222 report.txt deploy@example.com:/var/tmp/
Enter fullscreen mode Exit fullscreen mode

To download a file, put the remote path first:

scp -P 2222 deploy@example.com:/var/tmp/report.txt .
Enter fullscreen mode Exit fullscreen mode

The final . means the current local directory. The port flag applies to the SSH connection SCP makes; it doesn't change the server's configuration.

Why is the port flag uppercase?

SCP reserves lowercase -p for preserving file modification times and permissions. Use uppercase -P to select the port:

# Use TCP port 2222
scp -P 2222 report.txt deploy@example.com:/var/tmp/

# Preserve times and permissions
scp -p report.txt deploy@example.com:/var/tmp/
Enter fullscreen mode Exit fullscreen mode

The flags can be combined when you need both behaviors:

scp -p -P 2222 report.txt deploy@example.com:/var/tmp/
Enter fullscreen mode Exit fullscreen mode

This differs from the ssh command, which uses lowercase -p for the port:

ssh -p 2222 deploy@example.com
Enter fullscreen mode Exit fullscreen mode

If you're switching between SSH and SCP commands, double-check the capitalization before troubleshooting the server.

Save the port in SSH config

For a host you use regularly, put its connection details in ~/.ssh/config:

Host staging
  HostName example.com
  User deploy
  Port 2222
Enter fullscreen mode Exit fullscreen mode

Then use the alias for either command:

ssh staging
scp report.txt staging:/var/tmp/
Enter fullscreen mode Exit fullscreen mode

SCP reads the same SSH configuration as the SSH client, so the host's configured port is applied without repeating -P. You can also add other per-host settings as needed; see this SSH config example with host-specific options.

Copying between two remote hosts

A single scp -P option isn't a way to assign two different ports to two separate remote hosts. For a one-off transfer between hosts that use different ports, modern OpenSSH supports an SCP URI for each endpoint:

scp scp://alice@host1:2200/var/tmp/file.txt scp://bob@host2:2222/incoming/
Enter fullscreen mode Exit fullscreen mode

Each URI carries its own host and port. By default, current OpenSSH routes a remote-to-remote copy through your local machine, making the two connections separately. The URI approach does not work for specifying a target port when -R is used to have the two remote hosts communicate directly.

If you repeat this kind of transfer, define a separate SSH config alias for each host instead:

Host remote1
  HostName host1.example.com
  User alice
  Port 2200

Host remote2
  HostName host2.example.com
  User bob
  Port 2222
Enter fullscreen mode Exit fullscreen mode

Then the copy can use those aliases:

scp remote1:/var/tmp/file.txt remote2:/incoming/
Enter fullscreen mode Exit fullscreen mode

For other transfer patterns, including copying directories and choosing between SCP and SFTP, this SCP command guide covers useful examples.

When a transfer fails

First check that you're targeting the port where the server's SSH service is listening. A port change on the server affects both SSH logins and SCP transfers.

You can test whether the port is reachable before retrying the copy:

# Linux or macOS
nc -zv example.com 2222
Enter fullscreen mode Exit fullscreen mode

On Windows PowerShell:

Test-NetConnection -ComputerName example.com -Port 2222
Enter fullscreen mode Exit fullscreen mode

A successful port check only tells you that the TCP port is reachable; it doesn't confirm that authentication or the file transfer will succeed. If the port is unreachable, check the server address, network path, and firewall rules. If SSH connects but SCP fails, inspect the error and the remote path permissions rather than changing the port flag.

I originally published a more detailed version of this guide on the SSHFlow blog.

I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.

Top comments (0)