Skip to content

How to secure your VPS in 15 minutes ​

Bots start scanning a new server within minutes after it goes online. These steps close the most common ways in and work on Ubuntu and Debian.

1. Install updates ​

bash
apt update && apt upgrade -y

Turn on automatic security updates:

bash
apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

2. Log in with a key, not a password ​

An SSH key is practically impossible to guess. How to create one and disable password login is explained in connect via SSH.

3. Enable a firewall ​

UFW blocks all incoming connections except the ones you allow. Allow SSH first, otherwise you lock yourself out:

bash
apt install -y ufw
ufw allow OpenSSH
ufw enable
ufw status

Open only the ports you need. For WireGuard:

bash
ufw allow 51820/udp

For a website:

bash
ufw allow 80/tcp
ufw allow 443/tcp

4. Install fail2ban ​

fail2ban blocks IP addresses that fail to log in many times:

bash
apt install -y fail2ban
systemctl enable --now fail2ban
fail2ban-client status sshd

SSH protection is active right after installation.

5. Do not work as root ​

Create a regular user with admin rights:

bash
adduser admin
usermod -aG sudo admin

Copy your SSH key to that user, log in with it and run admin commands with sudo.

6. Keep copies of your data elsewhere ​

OBLAKO does not back up servers. Copy important data to your computer or cloud storage regularly, for example with rsync or restic.

7. Watch the load ​

The Metrics tab in the panel shows CPU, memory, disk and network charts. A sudden load spike with no reason can be a sign of a compromise.

Locked out?

If a firewall rule cut your SSH access, open the Console tab in the panel and fix the rules. See managing your server.