拥有公网 IP 的新 VPS 上线几分钟内就会开始收到自动化的登录尝试。本文提供一份清单,教您约 10 分钟完成新 Linux VPS 的安全设置:更新软件包、创建 sudo 用户、改用 SSH 密钥登录、禁用 root 密码登录、防火墙只开放必要端口、以 fail2ban 拦截暴力破解,以及启用自动安全更新。命令分别提供 Debian/Ubuntu 与 CentOS/Rocky Linux/AlmaLinux 版本,适用于东京、首尔或莫斯科的任何 JUSTG 云服务器。
步骤 1:更新所有软件包
以 root 登录(可参考我们的 SSH 登录教程),在做任何事之前先安装最新的安全补丁:
# Debian / Ubuntu
apt update && apt upgrade -y
# CentOS / Rocky / AlmaLinux
dnf upgrade -y
# reboot if a new kernel was installed
reboot
步骤 2:创建新的 sudo 用户
整天用 root 操作,任何打错字都可能酿成大祸,而且 root 是攻击者第一个尝试的账号。请创建具有 sudo 权限的普通用户(此处为 deploy)。Debian/Ubuntu 的管理组是 sudo,RHEL 系列则是 wheel。
# Debian / Ubuntu
adduser deploy
usermod -aG sudo deploy
# CentOS / Rocky / AlmaLinux
useradd -m deploy
passwd deploy
usermod -aG wheel deploy
步骤 3:设置 SSH 密钥验证
SSH 密钥比密码安全得多,也无法被猜中。请在 您自己的电脑 上生成密钥对(不是在服务器上),再把公钥复制到新用户。生成时建议为私钥设置密码短语。
# on your own computer (Windows PowerShell, macOS, Linux)
ssh-keygen -t ed25519 -C "my-laptop"
# macOS / Linux: copy the public key to the server
ssh-copy-id [email protected]
# Windows PowerShell (no ssh-copy-id)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
打开一个 新的 终端,确认可以用密钥登录并使用 sudo:
ssh [email protected]
sudo whoami
步骤 4:禁用 root 登录与 SSH 密码验证
较新的版本(Debian 12、Ubuntu 22.04 以上、Rocky/AlmaLinux 9)会读取 /etc/ssh/sshd_config.d/ 中的配置文件,且以最先读到的值为准。因此请使用排序靠前的文件名,例如 01-hardening.conf,才能覆盖云镜像在 50-cloud-init.conf 中打开的密码登录。旧系统请直接在 /etc/ssh/sshd_config 修改相同配置。
sudo nano /etc/ssh/sshd_config.d/01-hardening.conf
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
检查语法并重启 SSH:
sudo sshd -t
# Debian / Ubuntu
sudo systemctl restart ssh
# CentOS / Rocky / AlmaLinux
sudo systemctl restart sshd
再从新的终端测试:ssh [email protected] 应该会被拒绝,而 ssh [email protected] 仍可登录。
步骤 5:设置防火墙,只开放必要端口
默认拒绝所有入站连接,再只开放 SSH 与实际运行的服务(建站则开放 80 与 443)。启用防火墙 之前 一定要先允许 SSH;若已修改 SSH 端口,请改为允许新端口。
# Debian / Ubuntu (ufw)
sudo apt install ufw
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
# CentOS / Rocky / AlmaLinux (firewalld)
sudo dnf install firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --permanent --remove-service=cockpit
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
ufw 与 firewalld 都会把规则同时应用到 IPv4 与 JUSTG VPS 的免费 IPv6 地址。
步骤 6:安装 fail2ban 拦截暴力破解
即使已禁用密码登录,fail2ban 仍可让日志保持干净并封禁扫描器。它会监控验证失败记录,并暂时封禁来源 IP。systemd 后端直接读取 journal,两大发行版系列都适用。
# Debian / Ubuntu
sudo apt install fail2ban python3-systemd
# CentOS / Rocky / AlmaLinux
sudo dnf install epel-release
sudo dnf install fail2ban python3-systemd
sudo nano /etc/fail2ban/jail.local
[sshd]
enabled = true
backend = systemd
maxretry = 5
findtime = 10m
bantime = 1h
sudo systemctl enable --now fail2ban
sudo systemctl restart fail2ban
sudo fail2ban-client status sshd
步骤 7:启用自动安全更新
大多数入侵利用的都是早已有补丁的漏洞。让服务器自动安装安全更新:Debian/Ubuntu 使用 unattended-upgrades,CentOS/Rocky/AlmaLinux 使用 dnf-automatic。
# Debian / Ubuntu
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
sudo unattended-upgrade --dry-run --debug
# CentOS / Rocky / AlmaLinux
sudo dnf install dnf-automatic
sudo nano /etc/dnf/automatic.conf
# upgrade_type = security
# apply_updates = yes
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers dnf-automatic.timer
内核更新仍需重启才会生效。请定期安排短暂的维护重启,或在 Debian/Ubuntu 检查 /var/run/reboot-required 是否存在。
常见问题
禁用密码登录后把自己锁在外面了,怎么办?
从 JUSTG 客户中心 打开 VNC 控制台登录,修正 /etc/ssh/sshd_config.d/ 中的配置文件或防火墙规则。控制台不依赖 SSH 与防火墙。
需要同时修改 SSH 端口吗?
把 SSH 移出 22 端口可以减少日志噪音,但本身并非真正的安全措施。若要修改,请先更新防火墙;在启用 SELinux 的 Rocky/AlmaLinux 上还要运行 semanage port -a -t ssh_port_t -p tcp 2222。
Windows VPS 也适用吗?
思路相同:保持 Windows Update 打开、使用高强度的 Administrator 密码,并在 Windows Defender 防火墙中只允许您自己的 IP 使用 RDP。
如需协助加固服务器安全,请提交工单联系 JUSTG 技术支持。