VPS security comes down to two principles: reduce your attack surface and detect intrusion attempts before they cause damage. Whether you just provisioned a fresh server or want to audit an existing one, this guide gives you concrete, prioritized steps to harden your Linux VPS.
1. First Login: Change All Default Settings
The biggest risk with a brand-new VPS is leaving it with factory defaults. Attackers scan the internet specifically looking for those.
Change the SSH Port
Port 22 receives tens of thousands of brute-force attempts daily. Moving to a non-standard port (e.g., 2222 or a high random port) dramatically cuts the noise. Edit /etc/ssh/sshd_config:
Port 2222
Open the new port in your firewall before restarting SSH, or you will lock yourself out.
Create a Non-Root User and Disable Root Login
Never manage your server directly as root. Create a sudo-enabled user:
adduser adminuser
usermod -aG sudo adminuser
Then in /etc/ssh/sshd_config:
PermitRootLogin no
Use SSH Key Authentication
Passwords are vulnerable to dictionary attacks. Generate a key pair on your local machine and upload the public key to the server:
ssh-keygen -t ed25519 -C "my-vps"
ssh-copy-id -p 2222 adminuser@YOUR_VPS_IP
Once you confirm key-based access works, disable password authentication:
PasswordAuthentication no
2. Configure a Firewall on Day One
A VPS without a firewall exposes every open port to the internet. UFW (Uncomplicated Firewall) is the easiest option on Ubuntu/Debian; firewalld is the standard on CentOS/RHEL.
Basic UFW Setup
ufw default deny incoming
ufw default allow outgoing
ufw allow 2222/tcp # your custom SSH port
ufw allow 80/tcp # HTTP
ufw allow 443/tcp # HTTPS
ufw enable
Golden rule: block everything and open only what you need. If you install a control panel on port 8443 tomorrow, open that port then — not before.
Add fail2ban to Block Attacking IPs
fail2ban watches system logs and automatically bans IPs that exceed a set number of failed login attempts. Install it, enable the SSH jail with default settings, and you are covered against the vast majority of automated brute-force bots.
3. Keep the Operating System Updated
Known vulnerabilities are the most exploited because attackers have automated tools targeting them. Keeping your OS updated is the single highest-return security action you can take.
- On Ubuntu/Debian: enable unattended-upgrades for automatic security patches.
- On CentOS/RHEL: use
dnf-automaticwithapply_updates = yesin security-only mode. - Also update manually installed software — Nginx, MySQL, PHP — with the same frequency.
For a broader look at VPS management best practices, check out our VPS servers resource hub.
4. Monitoring and Intrusion Detection
Preventive measures are not enough if nobody notices when something fails. Monitoring closes the loop.
Review Logs Regularly
Key files: /var/log/auth.log (SSH attempts on Debian/Ubuntu) and /var/log/secure (on RHEL/CentOS). A quick command to spot failed attempts:
grep "Failed password" /var/log/auth.log | tail -20
Recommended Monitoring Tools
| Tool | Main function | Difficulty |
|---|---|---|
| fail2ban | Automatic IP banning | Low |
| Lynis | System security audit | Low |
| rkhunter | Rootkit detection | Medium |
| Netdata / Prometheus | Resource monitoring & alerts | Medium |
| OSSEC / Wazuh | Intrusion detection system (IDS) | High |
For most SMB or agency VPS deployments, fail2ban + Lynis + weekly log reviews is a solid starting point.
5. Backups and Recovery Plan
Security is not only about prevention — it is also about recovery. A compromised VPS that you have to clean by hand can cost you hours; one with a snapshot from yesterday restores in minutes.
- Enable automatic snapshots through your provider's control panel.
- Supplement with offsite backups of critical data: databases, config files, certificates.
- Test restores periodically. A backup you have never restored is an unverified backup.
Need expert help hardening your infrastructure? The team at elenlace.com provides managed VPS administration services for agencies and businesses across Mexico.
Key Takeaways
- Change the SSH port and disable root login on day one.
- Use SSH key authentication and disable password-based SSH login.
- Set up a firewall (UFW or firewalld) with a default-deny policy.
- Install fail2ban to automatically block brute-force attacks.
- Keep the OS and all installed software updated with security patches.
- Review logs regularly and run security audits with Lynis.
- Maintain automatic snapshots or backups and verify you can restore from them.
Want your VPS security handled by experts? Visit elenlace.com and explore our managed VPS plans with continuous monitoring included.
FAQ
What is the very first thing I should do on a new VPS?
Change the SSH port, create a non-root sudo user, enable SSH key authentication, and configure the firewall. These four steps, in that order, eliminate the majority of immediate attack vectors.
Do I need a managed security service, or can I handle it myself?
If you have basic Linux knowledge, the steps in this guide are executable in under an hour. For critical production environments or teams without in-house technical capacity, a managed VPS service ensures continuous monitoring and incident response.
How often should I update my VPS operating system?
Security patches should be applied as soon as they are available — ideally automatically for OS packages. Major version upgrades (e.g., Ubuntu 22 → 24) require more careful planning to avoid compatibility issues.
Does fail2ban protect against all brute-force attacks?
Fail2ban is very effective against traditional single-IP brute-force attacks. It does not stop distributed credential stuffing or zero-day vulnerabilities. Use it as part of a layered strategy, not as your only defense.
Further reading
Other providers and guides worth comparing: