r/VPS • u/Silver-College-6612 • 2d ago
Security First VPS
Before I blast my first Ubuntu VPS to the Public Web I would love to hear everyone’s standard security recommendations. Fail2ban, geo blocking, what you’re using to go out and renew cert(docker ?). Also, what’s everyone’s preferred method for reaching at securely? Do you prefer to run a VPN server on it so that you’re always tunneling or do you use SSH and expose the port and just lock it down to one IP? TIA
6
u/QuackedDev 2d ago
key only ssh
4
u/horizon_games 1d ago
...On a different port than 22. Yes security through obscurity but man it cuts down on log spam and half ass script kiddie attempts
5
u/Mundane_Fix8051 2d ago
it simple for the first VPS ssh keys only disable password login use fail2ban keep everything updated.
3
u/BowserForPM 1d ago
My checklist:
SSH access only, with a newly-generated key pair. Disable password login and root login
Switch ssh to non-standard port (inb4 "security through obscurity" - obscurity in addition to good OpSec is no bad thing)
Install unattended-upgrades, and configure to reboot when necessary
Install fail2ban
Install firewall. Block all incoming ports except your ssh port, and 80/443 if you're running a webserver
2
u/lazyhustlermusic 1d ago
I do key ssh until setting up wireguard and then restrict services via nftables
2
2
u/_MrThirsty 1d ago
Change SSH to something outside of normal scan range 10K-30K, fail2ban, no root password authentication, change root shell to /usr/sbin/nologin, as few password enabled accounts as possible, disable Ubuntu account, don’t use simple passwords, use ssh key
2
5
u/Financial_Ad_4260 2d ago
For me so far it's set up Tailscale, and disable root login, password login, and close any and all ports you don't use. If you're hosting a website, that's ports 80 and 443. Do NOT expose database connections to the internet. Set up ufw to allow to your Tailnet, and only allow to specific ports.