Servers & VPS

VPS Security: Practical Guide to Harden Your Server

Learn the essential steps to lock down your VPS server against unauthorized access, malware, and the most common Linux attacks.

Detailed view of Ethernet and VGA ports on a server highlighting connectivity features.

VPS security comes down to two principles: reduce your attack surface and detect intrusion attempts before they cause damage. Whether you just provisioned a fresh server or want to audit an existing one, this guide gives you concrete, prioritized steps to harden your Linux VPS.

1. First Login: Change All Default Settings

The biggest risk with a brand-new VPS is leaving it with factory defaults. Attackers scan the internet specifically looking for those.

Change the SSH Port

Port 22 receives tens of thousands of brute-force attempts daily. Moving to a non-standard port (e.g., 2222 or a high random port) dramatically cuts the noise. Edit /etc/ssh/sshd_config:

Port 2222

Open the new port in your firewall before restarting SSH, or you will lock yourself out.

Create a Non-Root User and Disable Root Login

Never manage your server directly as root. Create a sudo-enabled user:

adduser adminuser
usermod -aG sudo adminuser

Then in /etc/ssh/sshd_config:

PermitRootLogin no

Use SSH Key Authentication

Passwords are vulnerable to dictionary attacks. Generate a key pair on your local machine and upload the public key to the server:

ssh-keygen -t ed25519 -C "my-vps"
ssh-copy-id -p 2222 adminuser@YOUR_VPS_IP

Once you confirm key-based access works, disable password authentication:

PasswordAuthentication no

2. Configure a Firewall on Day One

A VPS without a firewall exposes every open port to the internet. UFW (Uncomplicated Firewall) is the easiest option on Ubuntu/Debian; firewalld is the standard on CentOS/RHEL.

Basic UFW Setup

ufw default deny incoming
ufw default allow outgoing
ufw allow 2222/tcp    # your custom SSH port
ufw allow 80/tcp      # HTTP
ufw allow 443/tcp     # HTTPS
ufw enable

Golden rule: block everything and open only what you need. If you install a control panel on port 8443 tomorrow, open that port then — not before.

Add fail2ban to Block Attacking IPs

fail2ban watches system logs and automatically bans IPs that exceed a set number of failed login attempts. Install it, enable the SSH jail with default settings, and you are covered against the vast majority of automated brute-force bots.

3. Keep the Operating System Updated

Known vulnerabilities are the most exploited because attackers have automated tools targeting them. Keeping your OS updated is the single highest-return security action you can take.

  • On Ubuntu/Debian: enable unattended-upgrades for automatic security patches.
  • On CentOS/RHEL: use dnf-automatic with apply_updates = yes in security-only mode.
  • Also update manually installed software — Nginx, MySQL, PHP — with the same frequency.

For a broader look at VPS management best practices, check out our VPS servers resource hub.

4. Monitoring and Intrusion Detection

Preventive measures are not enough if nobody notices when something fails. Monitoring closes the loop.

Review Logs Regularly

Key files: /var/log/auth.log (SSH attempts on Debian/Ubuntu) and /var/log/secure (on RHEL/CentOS). A quick command to spot failed attempts:

grep "Failed password" /var/log/auth.log | tail -20

Recommended Monitoring Tools

Tool Main function Difficulty
fail2ban Automatic IP banning Low
Lynis System security audit Low
rkhunter Rootkit detection Medium
Netdata / Prometheus Resource monitoring & alerts Medium
OSSEC / Wazuh Intrusion detection system (IDS) High

For most SMB or agency VPS deployments, fail2ban + Lynis + weekly log reviews is a solid starting point.

5. Backups and Recovery Plan

Security is not only about prevention — it is also about recovery. A compromised VPS that you have to clean by hand can cost you hours; one with a snapshot from yesterday restores in minutes.

  • Enable automatic snapshots through your provider's control panel.
  • Supplement with offsite backups of critical data: databases, config files, certificates.
  • Test restores periodically. A backup you have never restored is an unverified backup.

Need expert help hardening your infrastructure? The team at elenlace.com provides managed VPS administration services for agencies and businesses across Mexico.

Key Takeaways

  • Change the SSH port and disable root login on day one.
  • Use SSH key authentication and disable password-based SSH login.
  • Set up a firewall (UFW or firewalld) with a default-deny policy.
  • Install fail2ban to automatically block brute-force attacks.
  • Keep the OS and all installed software updated with security patches.
  • Review logs regularly and run security audits with Lynis.
  • Maintain automatic snapshots or backups and verify you can restore from them.

Want your VPS security handled by experts? Visit elenlace.com and explore our managed VPS plans with continuous monitoring included.

FAQ

What is the very first thing I should do on a new VPS?

Change the SSH port, create a non-root sudo user, enable SSH key authentication, and configure the firewall. These four steps, in that order, eliminate the majority of immediate attack vectors.

Do I need a managed security service, or can I handle it myself?

If you have basic Linux knowledge, the steps in this guide are executable in under an hour. For critical production environments or teams without in-house technical capacity, a managed VPS service ensures continuous monitoring and incident response.

How often should I update my VPS operating system?

Security patches should be applied as soon as they are available — ideally automatically for OS packages. Major version upgrades (e.g., Ubuntu 22 → 24) require more careful planning to avoid compatibility issues.

Does fail2ban protect against all brute-force attacks?

Fail2ban is very effective against traditional single-IP brute-force attacks. It does not stop distributed credential stuffing or zero-day vulnerabilities. Use it as part of a layered strategy, not as your only defense.

Further reading

Other providers and guides worth comparing:

← All