帮助中心

服务器、网络和账户的分步教程。

新手入门

10 分钟完成 Linux VPS 安全设置:SSH 密钥、防火墙、Fail2ban 与自动更新

10 分钟完成 Linux VPS 安全设置:SSH 密钥、防火墙、Fail2ban 与自动更新

拥有公网 IP 的新 VPS 上线几分钟内就会开始收到自动化的登录尝试。本文提供一份清单,教您约 10 分钟完成新 Linux VPS 的安全设置:更新软件包、创建 sudo 用户、改用 SSH 密钥登录、禁用 root 密码登录、防火墙只开放必要端口、以 fail2ban 拦截暴力破解,以及启用自动安全更新。命令分别提供 Debian/Ubuntu 与 CentOS/Rocky Linux/AlmaLinux 版本,适用于东京、首尔或莫斯科的任何 JUSTG 云服务器。

步骤 1:更新所有软件包

以 root 登录(可参考我们的 SSH 登录教程),在做任何事之前先安装最新的安全补丁:

# Debian / Ubuntu
apt update && apt upgrade -y

# CentOS / Rocky / AlmaLinux
dnf upgrade -y

# reboot if a new kernel was installed
reboot

步骤 2:创建新的 sudo 用户

整天用 root 操作,任何打错字都可能酿成大祸,而且 root 是攻击者第一个尝试的账号。请创建具有 sudo 权限的普通用户(此处为 deploy)。Debian/Ubuntu 的管理组是 sudo,RHEL 系列则是 wheel。

# Debian / Ubuntu
adduser deploy
usermod -aG sudo deploy

# CentOS / Rocky / AlmaLinux
useradd -m deploy
passwd deploy
usermod -aG wheel deploy

步骤 3:设置 SSH 密钥验证

SSH 密钥比密码安全得多,也无法被猜中。请在 您自己的电脑 上生成密钥对(不是在服务器上),再把公钥复制到新用户。生成时建议为私钥设置密码短语。

# on your own computer (Windows PowerShell, macOS, Linux)
ssh-keygen -t ed25519 -C "my-laptop"

# macOS / Linux: copy the public key to the server
ssh-copy-id [email protected]

# Windows PowerShell (no ssh-copy-id)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

打开一个 新的 终端,确认可以用密钥登录并使用 sudo:

ssh [email protected]
sudo whoami
新用户的密钥登录确认成功前,请不要进行下一步。在测试完以下所有更改之前,保留当前的 root 连接作为保险。

步骤 4:禁用 root 登录与 SSH 密码验证

较新的版本(Debian 12、Ubuntu 22.04 以上、Rocky/AlmaLinux 9)会读取 /etc/ssh/sshd_config.d/ 中的配置文件,且以最先读到的值为准。因此请使用排序靠前的文件名,例如 01-hardening.conf,才能覆盖云镜像在 50-cloud-init.conf 中打开的密码登录。旧系统请直接在 /etc/ssh/sshd_config 修改相同配置。

sudo nano /etc/ssh/sshd_config.d/01-hardening.conf

PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes

检查语法并重启 SSH:

sudo sshd -t
# Debian / Ubuntu
sudo systemctl restart ssh
# CentOS / Rocky / AlmaLinux
sudo systemctl restart sshd

再从新的终端测试:ssh [email protected] 应该会被拒绝,而 ssh [email protected] 仍可登录。

步骤 5:设置防火墙,只开放必要端口

默认拒绝所有入站连接,再只开放 SSH 与实际运行的服务(建站则开放 80 与 443)。启用防火墙 之前 一定要先允许 SSH;若已修改 SSH 端口,请改为允许新端口。

# Debian / Ubuntu (ufw)
sudo apt install ufw
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable

# CentOS / Rocky / AlmaLinux (firewalld)
sudo dnf install firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --permanent --remove-service=cockpit
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

ufw 与 firewalld 都会把规则同时应用到 IPv4 与 JUSTG VPS 的免费 IPv6 地址。

步骤 6:安装 fail2ban 拦截暴力破解

即使已禁用密码登录,fail2ban 仍可让日志保持干净并封禁扫描器。它会监控验证失败记录,并暂时封禁来源 IP。systemd 后端直接读取 journal,两大发行版系列都适用。

# Debian / Ubuntu
sudo apt install fail2ban python3-systemd

# CentOS / Rocky / AlmaLinux
sudo dnf install epel-release
sudo dnf install fail2ban python3-systemd

sudo nano /etc/fail2ban/jail.local

[sshd]
enabled  = true
backend  = systemd
maxretry = 5
findtime = 10m
bantime  = 1h

sudo systemctl enable --now fail2ban
sudo systemctl restart fail2ban
sudo fail2ban-client status sshd

步骤 7:启用自动安全更新

大多数入侵利用的都是早已有补丁的漏洞。让服务器自动安装安全更新:Debian/Ubuntu 使用 unattended-upgrades,CentOS/Rocky/AlmaLinux 使用 dnf-automatic。

# Debian / Ubuntu
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
sudo unattended-upgrade --dry-run --debug

# CentOS / Rocky / AlmaLinux
sudo dnf install dnf-automatic
sudo nano /etc/dnf/automatic.conf
#   upgrade_type = security
#   apply_updates = yes
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers dnf-automatic.timer

内核更新仍需重启才会生效。请定期安排短暂的维护重启,或在 Debian/Ubuntu 检查 /var/run/reboot-required 是否存在。

常见问题

禁用密码登录后把自己锁在外面了,怎么办?

从 JUSTG 客户中心 打开 VNC 控制台登录,修正 /etc/ssh/sshd_config.d/ 中的配置文件或防火墙规则。控制台不依赖 SSH 与防火墙。

需要同时修改 SSH 端口吗?

把 SSH 移出 22 端口可以减少日志噪音,但本身并非真正的安全措施。若要修改,请先更新防火墙;在启用 SELinux 的 Rocky/AlmaLinux 上还要运行 semanage port -a -t ssh_port_t -p tcp 2222。

Windows VPS 也适用吗?

思路相同:保持 Windows Update 打开、使用高强度的 Administrator 密码,并在 Windows Defender 防火墙中只允许您自己的 IP 使用 RDP。

如需协助加固服务器安全,请提交工单联系 JUSTG 技术支持。

这篇文章有帮助吗?
帮助中心
AlipayUnionPayVISAMastercardPayPalUSDTstripe