Securing your VPS: the basics Print

  • VPS, Sicherheit, Firewall, Fail2ban
  • 0

Since VPS CORE is unmanaged, securing the server is your responsibility. Apply these basic measures right after setup.

1. Keep the system up to date

Debian/Ubuntu: apt update && apt upgrade -y, optionally automatic security updates with apt install unattended-upgrades.
AlmaLinux/Rocky Linux: dnf upgrade -y, optionally with dnf-automatic.

2. Create a user with sudo rights

Debian/Ubuntu: adduser username and usermod -aG sudo username
AlmaLinux/Rocky Linux: adduser username, passwd username and usermod -aG wheel username

3. Enable a firewall

Ubuntu/Debian with ufw: ufw allow OpenSSH, open other required ports (e.g. ufw allow 80,443/tcp), then ufw enable.
AlmaLinux/Rocky with firewalld: firewall-cmd --permanent --add-service=ssh, if needed --add-service=http and --add-service=https, then firewall-cmd --reload.

4. Install Fail2ban

Fail2ban blocks IP addresses after repeated failed logins: apt install fail2ban or dnf install epel-release fail2ban, then systemctl enable --now fail2ban.

5. Disable root password login

Set up SSH keys and in /etc/ssh/sshd_config set PermitRootLogin prohibit-password (or no if you only work with the sudo user) and PasswordAuthentication no. Then restart the SSH service.

Important: Allow the SSH port before enabling the firewall, and test every change in a second window so you do not lock yourself out. Also create your own backups regularly.


Was this answer helpful?

« Back

Powered by WHMCompleteSolution