VPS Security Guide: Harden Your Server Step by Step
Table of Contents
A freshly provisioned VPS is a target. Automated bots scan the internet constantly for open ports, default credentials, and unpatched software. This guide walks you through the essential security measures every VPS owner should implement immediately after setup.
1. Secure SSH Access
SSH is the primary way you access your server, making it the most important surface to harden.
Use SSH Keys Instead of Passwords
Password-based SSH login is vulnerable to brute-force attacks. SSH key authentication uses asymmetric cryptography and is virtually impossible to crack. Generate a key pair on your local machine, upload the public key to your server, and disable password authentication entirely.
Change the Default SSH Port
Moving SSH from port 22 to a non-standard port (e.g., 2222 or 49152) eliminates the vast majority of automated brute-force attempts. This is security through obscurity and should be combined with other measures, but it dramatically reduces log noise.
Disable Root Login
Create a regular user account with sudo privileges and disable direct root login via SSH. This adds an extra layer — an attacker must guess both the username and the key.
2. Configure a Firewall
A firewall controls which ports accept incoming and outgoing traffic. On Ubuntu/Debian, UFW (Uncomplicated Firewall) is the simplest option. On CentOS/RHEL, use firewalld.
A basic firewall configuration should:
- Allow your SSH port (custom or 22).
- Allow HTTP (80) and HTTPS (443) for web traffic.
- Deny all other incoming connections by default.
- Allow all outgoing connections (for updates and external API calls).
For cloud VPS providers, also configure the provider-level firewall (security groups, cloud firewalls) as an additional layer.
3. Automatic Security Updates
Unpatched software is one of the most common attack vectors. Enable unattended security updates so critical patches are applied automatically without waiting for manual intervention.
On Ubuntu/Debian, the unattended-upgrades package handles this. On CentOS, use dnf-automatic. Configure it to install security updates only — not all updates — to minimize the risk of breaking changes.
4. Install Fail2Ban
Fail2Ban monitors log files for repeated failed login attempts and automatically bans the offending IP addresses using firewall rules. It is one of the most effective tools against brute-force attacks.
Key configuration settings:
- maxretry — Number of failures before banning (recommended: 3-5).
- bantime — How long the ban lasts (recommended: 1 hour or more).
- findtime — Time window for counting failures (recommended: 10 minutes).
Fail2Ban can protect not just SSH but also web applications, mail servers, and FTP services.
5. User Account Security
- Never run applications as root. Create dedicated service users with minimal permissions.
- Use strong, unique passwords for any accounts that require them.
- Audit user accounts regularly and remove inactive ones.
- Set proper file permissions — web files should typically be owned by the web server user and set to 644 (files) and 755 (directories).
6. SSL/TLS Certificates
Every website on your VPS should use HTTPS. SSL certificates encrypt data in transit, preventing man-in-the-middle attacks and improving SEO rankings.
Let's Encrypt provides free SSL certificates that auto-renew. Certbot is the most popular client for obtaining and managing Let's Encrypt certificates. Install it, run the automated setup, and configure your web server to redirect all HTTP traffic to HTTPS.
7. Security Monitoring
You cannot defend against what you cannot see. Implement monitoring at multiple levels:
- Log monitoring — Centralize logs with tools like rsyslog or journald. Review auth logs regularly for suspicious activity.
- Intrusion detection — Tools like AIDE or Tripwire detect unauthorized changes to system files.
- Uptime monitoring — External services like UptimeRobot or Hetrix Tools alert you if your server goes down.
- Resource monitoring — Track CPU, RAM, and disk usage to spot anomalies that could indicate a compromised server (crypto miners, botnets).
8. Backup Strategy
Security is not just about prevention — it is also about recovery. A robust backup strategy ensures you can restore your server after a breach, hardware failure, or accidental deletion.
- Automate daily backups of critical data and weekly full-system snapshots.
- Store backups off-server — use a separate VPS, object storage (S3, Backblaze B2), or your provider's backup service.
- Test your restoration process regularly. A backup you have never tested is not a backup.
- Encrypt backup files, especially if stored with a third party.
VPS Security Checklist
| Task | Priority | Status |
|---|---|---|
| Switch SSH to key-based authentication | Critical | ☐ |
| Disable root SSH login | Critical | ☐ |
| Change default SSH port | High | ☐ |
| Configure UFW / firewalld | Critical | ☐ |
| Enable automatic security updates | Critical | ☐ |
| Install and configure Fail2Ban | High | ☐ |
| Install SSL/TLS certificates | Critical | ☐ |
| Set up automated backups | High | ☐ |
| Configure log monitoring | Medium | ☐ |
| Install intrusion detection (AIDE) | Medium | ☐ |
| Audit user accounts & permissions | Medium | ☐ |
Need a Secure VPS Provider?
See which providers include DDoS protection, firewalls, and backups out of the box.
Compare VPS Providers