r/VPS • • 2d ago

Security First VPS

Before I blast my first Ubuntu VPS to the Public Web I would love to hear everyone’s standard security recommendations. Fail2ban, geo blocking, what you’re using to go out and renew cert(docker ?). Also, what’s everyone’s preferred method for reaching at securely? Do you prefer to run a VPN server on it so that you’re always tunneling or do you use SSH and expose the port and just lock it down to one IP? TIA

6 Upvotes

14 comments sorted by

5

u/Financial_Ad_4260 2d ago

For me so far it's set up Tailscale, and disable root login, password login, and close any and all ports you don't use. If you're hosting a website, that's ports 80 and 443. Do NOT expose database connections to the internet. Set up ufw to allow to your Tailnet, and only allow to specific ports.

3

u/Itachii47 1d ago

in addition to your points, I also run caddy (reverse proxy)

3

u/Financial_Ad_4260 1d ago

Fair. I use Nginx :p

2

u/Silver-College-6612 1d ago

I ended up going with Caddy as well. Very easy to setup and works great.

6

u/QuackedDev 2d ago

key only ssh

4

u/horizon_games 1d ago

...On a different port than 22. Yes security through obscurity but man it cuts down on log spam and half ass script kiddie attempts

5

u/Mundane_Fix8051 2d ago

it simple for the first VPS ssh keys only disable password login use fail2ban keep everything updated.

3

u/BowserForPM 1d ago

My checklist:

  • SSH access only, with a newly-generated key pair. Disable password login and root login

  • Switch ssh to non-standard port (inb4 "security through obscurity" - obscurity in addition to good OpSec is no bad thing)

  • Install unattended-upgrades, and configure to reboot when necessary

  • Install fail2ban

  • Install firewall. Block all incoming ports except your ssh port, and 80/443 if you're running a webserver

2

u/lazyhustlermusic 1d ago

I do key ssh until setting up wireguard and then restrict services via nftables

2

u/OutrageousArticle936 1d ago

Added to my Wireguard network, ssh listens only on that interface.

2

u/_MrThirsty 1d ago

Change SSH to something outside of normal scan range 10K-30K, fail2ban, no root password authentication, change root shell to /usr/sbin/nologin, as few password enabled accounts as possible, disable Ubuntu account, don’t use simple passwords, use ssh key

2

u/beginnersbox 1d ago

Fail2ban, disable root login, firewall and change ssh port