VPS Guide

How to Secure a VPS

How to Secure a VPS: Essential Security Practices A VPS gives you full control over your server — which is powerful, but also means…

How to Secure a VPS: Essential Security Practices

A VPS gives you full control over your server — which is powerful, but also means you are responsible for securing it. A misconfigured or neglected VPS can become an easy target for attackers. This guide covers the essential security practices you should follow to keep your VPS safe.

1. Keep Your System Updated

One of the most important security practices is keeping your operating system and software up to date. Security patches fix vulnerabilities that attackers actively exploit. Set up automatic updates or make it a habit to update regularly:

# Debian/Ubuntu
sudo apt update && sudo apt upgrade -y

# Enable automatic security updates
sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

For your applications (web server, database, PHP, Node.js, etc.), keep them updated as well. Outdated software is one of the most common entry points for attackers.

2. Use SSH Keys Instead of Passwords

Password-based SSH authentication is vulnerable to brute-force attacks. Switch to key-based authentication:

  1. Generate a key pair on your local machine: ssh-keygen -t ed25519
  2. Copy the public key to your VPS: ssh-copy-id user@server-ip
  3. Disable password authentication in /etc/ssh/sshd_config:
    PasswordAuthentication no
    PubkeyAuthentication yes
  4. Restart SSH: sudo systemctl restart ssh

Key-based authentication is significantly more secure than passwords and eliminates the risk of brute-force attacks on SSH.

3. Change the Default SSH Port

Port 22 is the default SSH port and is constantly scanned by bots. Changing it to a non-standard port (e.g., 2222) reduces the noise from automated attacks. This is not a strong security measure on its own, but it helps reduce the number of brute-force attempts you see in your logs.

4. Configure the Firewall

Only open the ports you need. For a typical web server, that is ports 80 (HTTP), 443 (HTTPS), and your SSH port. Close everything else. Use UFW (Uncomplicated Firewall) on Debian/Ubuntu:

sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable

A properly configured firewall is one of the most effective ways to protect your VPS.

5. Install Fail2Ban

Fail2Ban is a tool that automatically bans IP addresses that show malicious behavior, such as repeated failed login attempts. It is especially effective against brute-force attacks on SSH and web login forms:

sudo apt install fail2ban -y
sudo systemctl enable fail2ban
sudo systemctl start fail2ban

Fail2Ban monitors log files and bans offending IPs for a configurable period. It is a simple but effective layer of protection.

6. Use HTTPS (SSL/TLS)

Encrypting traffic between your server and visitors is essential. Use Let’s Encrypt for free SSL certificates:

sudo apt install certbot python3-certbot-nginx -y
sudo certbot --nginx -d yourdomain.com

Let’s Encrypt certificates are automatically renewed, so you do not need to worry about expiration. HTTPS protects your visitors’ data and is also a ranking factor for search engines.

7. Create a Regular User and Limit Root Access

Instead of logging in as root every time, create a regular user with sudo privileges. This reduces the risk of accidental damage and limits the damage an attacker can do if they compromise a regular account:

sudo adduser myuser
sudo usermod -aG sudo myuser

Log in as your regular user and use sudo when you need administrative privileges.

8. Keep Software Minimal

Every piece of software you install is a potential attack surface. Only install what you need. If you are not using a particular service, do not install it. A minimal system is a more secure system.

9. Monitor Your System

Regularly check your system for signs of compromise:

  • Check logged-in users: who and w
  • Check running processes: top or htop
  • Check SSH logs: sudo tail -f /var/log/auth.log
  • Check for unexpected files: Look in /tmp, /var/tmp, and home directories.
  • Check cron jobs: crontab -l and sudo crontab -l

Set up monitoring tools or alerts for resource usage and security events. If something looks wrong, investigate immediately.

10. Set Up Backups

Security is not just about preventing attacks — it is also about being able to recover if something goes wrong. Regular backups are essential:

  • Back up your website files and database regularly.
  • Store backups off-site (cloud storage, another server).
  • Test your backups periodically to ensure they can be restored.

A backup strategy is your last line of defense. If your VPS is compromised or a file is corrupted, a recent backup allows you to recover quickly.

11. Use Strong Passwords

For any service that requires a password (database, admin panel, email), use a strong, unique password. Avoid common passwords and reuse. A password manager can help you generate and store strong passwords.

12. Stay Informed

Security is an ongoing process. Stay informed about new vulnerabilities and best practices. Subscribe to security newsletters, follow relevant communities, and keep an eye on security advisories for the software you use.

Conclusion

Securing a VPS is not a one-time task — it is an ongoing process. By following the practices in this guide, you can significantly reduce the risk of your VPS being compromised. The most important habits are: keep your system updated, use SSH keys, configure the firewall, use HTTPS, and set up backups. At AuroraCloud Shop, all VPS plans include root access, which means you have the tools to secure your server properly. Browse the VPS plans to get started.

Put It Into Practice

Explore VPS Plans

Apply what you learned with a plan that fits your project.

Aurora VPS 01
Linux
$8.00/mo
  • ⚙ 1 vCPU
  • 🗂 1 GB
  • 💾 20 GB NVMe
  • 🔀 1 TB
  • 📡 1 Gbps
  • 🌐 1 IPv4
View Plan
Aurora VPS 02
Linux
$12.00/mo
  • ⚙ 1 vCPU
  • 🗂 2 GB
  • 💾 40 GB NVMe
  • 🔀 2 TB
  • 📡 1 Gbps
  • 🌐 1 IPv4
View Plan