How to Secure a VPS
How to Secure a VPS: Essential Security Practices A VPS gives you full control over your server — which is powerful, but also means…
How to Secure a VPS: Essential Security Practices
A VPS gives you full control over your server — which is powerful, but also means you are responsible for securing it. A misconfigured or neglected VPS can become an easy target for attackers. This guide covers the essential security practices you should follow to keep your VPS safe.
1. Keep Your System Updated
One of the most important security practices is keeping your operating system and software up to date. Security patches fix vulnerabilities that attackers actively exploit. Set up automatic updates or make it a habit to update regularly:
# Debian/Ubuntu
sudo apt update && sudo apt upgrade -y
# Enable automatic security updates
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
For your applications (web server, database, PHP, Node.js, etc.), keep them updated as well. Outdated software is one of the most common entry points for attackers.
2. Use SSH Keys Instead of Passwords
Password-based SSH authentication is vulnerable to brute-force attacks. Switch to key-based authentication:
- Generate a key pair on your local machine:
ssh-keygen -t ed25519 - Copy the public key to your VPS:
ssh-copy-id user@server-ip - Disable password authentication in
/etc/ssh/sshd_config:PasswordAuthentication no PubkeyAuthentication yes - Restart SSH:
sudo systemctl restart ssh
Key-based authentication is significantly more secure than passwords and eliminates the risk of brute-force attacks on SSH.
3. Change the Default SSH Port
Port 22 is the default SSH port and is constantly scanned by bots. Changing it to a non-standard port (e.g., 2222) reduces the noise from automated attacks. This is not a strong security measure on its own, but it helps reduce the number of brute-force attempts you see in your logs.
4. Configure the Firewall
Only open the ports you need. For a typical web server, that is ports 80 (HTTP), 443 (HTTPS), and your SSH port. Close everything else. Use UFW (Uncomplicated Firewall) on Debian/Ubuntu:
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
A properly configured firewall is one of the most effective ways to protect your VPS.
5. Install Fail2Ban
Fail2Ban is a tool that automatically bans IP addresses that show malicious behavior, such as repeated failed login attempts. It is especially effective against brute-force attacks on SSH and web login forms:
sudo apt install fail2ban -y
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
Fail2Ban monitors log files and bans offending IPs for a configurable period. It is a simple but effective layer of protection.
6. Use HTTPS (SSL/TLS)
Encrypting traffic between your server and visitors is essential. Use Let’s Encrypt for free SSL certificates:
sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d yourdomain.com
Let’s Encrypt certificates are automatically renewed, so you do not need to worry about expiration. HTTPS protects your visitors’ data and is also a ranking factor for search engines.
7. Create a Regular User and Limit Root Access
Instead of logging in as root every time, create a regular user with sudo privileges. This reduces the risk of accidental damage and limits the damage an attacker can do if they compromise a regular account:
sudo adduser myuser
sudo usermod -aG sudo myuser
Log in as your regular user and use sudo when you need administrative privileges.
8. Keep Software Minimal
Every piece of software you install is a potential attack surface. Only install what you need. If you are not using a particular service, do not install it. A minimal system is a more secure system.
9. Monitor Your System
Regularly check your system for signs of compromise:
- Check logged-in users:
whoandw - Check running processes:
toporhtop - Check SSH logs:
sudo tail -f /var/log/auth.log - Check for unexpected files: Look in
/tmp,/var/tmp, and home directories. - Check cron jobs:
crontab -landsudo crontab -l
Set up monitoring tools or alerts for resource usage and security events. If something looks wrong, investigate immediately.
10. Set Up Backups
Security is not just about preventing attacks — it is also about being able to recover if something goes wrong. Regular backups are essential:
- Back up your website files and database regularly.
- Store backups off-site (cloud storage, another server).
- Test your backups periodically to ensure they can be restored.
A backup strategy is your last line of defense. If your VPS is compromised or a file is corrupted, a recent backup allows you to recover quickly.
11. Use Strong Passwords
For any service that requires a password (database, admin panel, email), use a strong, unique password. Avoid common passwords and reuse. A password manager can help you generate and store strong passwords.
12. Stay Informed
Security is an ongoing process. Stay informed about new vulnerabilities and best practices. Subscribe to security newsletters, follow relevant communities, and keep an eye on security advisories for the software you use.
Conclusion
Securing a VPS is not a one-time task — it is an ongoing process. By following the practices in this guide, you can significantly reduce the risk of your VPS being compromised. The most important habits are: keep your system updated, use SSH keys, configure the firewall, use HTTPS, and set up backups. At AuroraCloud Shop, all VPS plans include root access, which means you have the tools to secure your server properly. Browse the VPS plans to get started.
Explore VPS Plans
Apply what you learned with a plan that fits your project.