How to Secure a New Linux VPS in 10 Minutes: SSH Keys, Firewall, Fail2ban, Auto Updates

14 min read 2 views 0
On this page

A new VPS with a public IP starts receiving automated login attempts within minutes of going online. This checklist shows how to secure a new Linux VPS in about 10 minutes: update packages, create a sudo user, switch to SSH key login, disable root password login, allow only the ports you need in the firewall, block brute-force attacks with fail2ban and turn on automatic security updates. Commands are given for Debian/Ubuntu and for CentOS/Rocky Linux/AlmaLinux, and work on any JUSTG cloud server in Johannesburg, Moscow, Tokyo or Seoul.

Step 1: Update all packages

Log in as root (see our SSH login guide) and install the latest security patches before doing anything else:

# Debian / Ubuntu
apt update && apt upgrade -y

# CentOS / Rocky / AlmaLinux
dnf upgrade -y

# reboot if a new kernel was installed
reboot

Step 2: Create a new sudo user

Working as root all day makes every typo dangerous, and root is the first username attackers try. Create a normal user (here deploy) with sudo rights. On Debian/Ubuntu the admin group is sudo; on RHEL-based systems it is wheel.

# Debian / Ubuntu
adduser deploy
usermod -aG sudo deploy

# CentOS / Rocky / AlmaLinux
useradd -m deploy
passwd deploy
usermod -aG wheel deploy

Step 3: Set up SSH key authentication

SSH keys are far stronger than passwords and cannot be guessed. Generate a key pair on your own computer, not on the server, and copy the public key to the new user. Protect the private key with a passphrase when asked.

# on your own computer (Windows PowerShell, macOS, Linux)
ssh-keygen -t ed25519 -C "my-laptop"

# macOS / Linux: copy the public key to the server
ssh-copy-id [email protected]

# Windows PowerShell (no ssh-copy-id)
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh [email protected] "mkdir -p ~/.ssh && chmod 700 ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"

Open a new terminal and make sure you can log in with the key and use sudo:

ssh [email protected]
sudo whoami
Do not continue until key login works for the new user. Keep your current root session open as a safety net until you have tested every change below.

Step 4: Disable root login and SSH password authentication

Modern releases (Debian 12, Ubuntu 22.04+, Rocky/AlmaLinux 9) read drop-in files from /etc/ssh/sshd_config.d/. The first value found wins, so use a file name that sorts early, such as 01-hardening.conf, to override cloud images that enable passwords in 50-cloud-init.conf. On older systems, change the same lines directly in /etc/ssh/sshd_config.

sudo nano /etc/ssh/sshd_config.d/01-hardening.conf

PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes

Check the syntax and restart SSH:

sudo sshd -t
# Debian / Ubuntu
sudo systemctl restart ssh
# CentOS / Rocky / AlmaLinux
sudo systemctl restart sshd

Test again from a new terminal. ssh [email protected] should now be refused, while ssh [email protected] still works.

Step 5: Configure the firewall to allow only needed ports

Deny everything incoming by default, then open only SSH and the services you actually run (80 and 443 for a website). Always allow SSH before enabling the firewall. If you changed the SSH port, allow that port instead.

# Debian / Ubuntu (ufw)
sudo apt install ufw
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable

# CentOS / Rocky / AlmaLinux (firewalld)
sudo dnf install firewalld
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http --add-service=https
sudo firewall-cmd --permanent --remove-service=cockpit
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

Both ufw and firewalld apply these rules to IPv4 and to the free IPv6 address of your JUSTG VPS.

Step 6: Install fail2ban to block brute-force attacks

Even with password login disabled, fail2ban keeps logs clean and blocks scanners. It watches authentication failures and bans the source IP for a while. The systemd backend reads the journal, which works on both distribution families.

# Debian / Ubuntu
sudo apt install fail2ban python3-systemd

# CentOS / Rocky / AlmaLinux
sudo dnf install epel-release
sudo dnf install fail2ban python3-systemd

sudo nano /etc/fail2ban/jail.local

[sshd]
enabled  = true
backend  = systemd
maxretry = 5
findtime = 10m
bantime  = 1h

sudo systemctl enable --now fail2ban
sudo systemctl restart fail2ban
sudo fail2ban-client status sshd

Step 7: Enable automatic security updates

Most compromises use vulnerabilities that already have a patch. Let the server install security updates on its own: unattended-upgrades on Debian/Ubuntu, dnf-automatic on CentOS/Rocky/AlmaLinux.

# Debian / Ubuntu
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
sudo unattended-upgrade --dry-run --debug

# CentOS / Rocky / AlmaLinux
sudo dnf install dnf-automatic
sudo nano /etc/dnf/automatic.conf
#   upgrade_type = security
#   apply_updates = yes
sudo systemctl enable --now dnf-automatic.timer
systemctl list-timers dnf-automatic.timer

Kernel updates still need a reboot. Plan a short maintenance reboot from time to time, or check /var/run/reboot-required on Debian/Ubuntu.

FAQ

I locked myself out after disabling password login. How do I get back in?

Open the VNC console from the JUSTG client area, log in there and fix the file in /etc/ssh/sshd_config.d/ or the firewall rules. The console does not depend on SSH or the firewall.

Should I also change the SSH port?

Moving SSH away from port 22 reduces log noise but is not real security on its own. If you do it, update the firewall first and, on Rocky/AlmaLinux with SELinux, run semanage port -a -t ssh_port_t -p tcp 2222.

Does this work on Windows VPS too?

The ideas are the same: keep Windows Update on, use a strong Administrator password, and limit RDP in Windows Defender Firewall to your own IP addresses.

If you need help securing your server, please submit a ticket to JUSTG technical support.

Was this answer helpful?