At Right Servers Inc., we prioritize the security of your VPS and dedicated servers. This article covers essential steps to harden your server after initial setup.

Step 1: Create a Sudo User and Disable Root SSH Login

Disabling direct root login via SSH reduces the risk of unauthorized access. First, create a sudo user:

  1. Connect to your server via SSH as root.
  2. Create a new user: adduser <username>
  3. Set a strong password: passwd <username>
  4. Add the user to the sudo group: usermod -aG sudo <username> (on CentOS/RHEL: usermod -aG wheel <username>)

Then disable root SSH login:

  1. Edit the SSH config: nano /etc/ssh/sshd_config
  2. Set PermitRootLogin no
  3. Restart SSH: systemctl restart sshd

Test that your sudo user can connect before closing the root SSH session.

Step 2: Use SSH Keys Instead of Passwords

SSH key authentication is more secure than passwords. To set it up:

  1. Generate a key pair on your local machine: ssh-keygen -t ed25519
  2. Copy the public key to your server: ssh-copy-id <username>@<server_ip>
  3. On the server, edit /etc/ssh/sshd_config and set PasswordAuthentication no
  4. Restart SSH: systemctl restart sshd

The AutoVM control panel also displays your server's current SSH public key in the SSH Key tab for reference.

Step 3: Set Up a Firewall

A firewall controls incoming and outgoing network traffic. For Linux, ufw (Ubuntu/Debian) or firewalld (CentOS/RHEL) are easier alternatives to raw iptables:

  • Ubuntu/Debian: ufw allow 22/tcp && ufw enable
  • CentOS/RHEL: firewall-cmd --permanent --add-port=22/tcp && firewall-cmd --reload

Only open ports for services you actively run (e.g. 80/443 for web, 25/587 for mail).

Step 4: Keep Your OS Updated

Regularly update your operating system and installed packages:

  • Debian/Ubuntu: apt update && apt upgrade -y
  • CentOS/RHEL/AlmaLinux: dnf update -y

Step 5: Disable Unused Services

Services not in use are unnecessary attack surface:

  • List running services: systemctl list-units --type=service --state=running
  • Disable a service: systemctl disable <service_name>

Step 6: Change the SSH Port

Changing the default SSH port (22) reduces automated bot attacks:

  1. Edit /etc/ssh/sshd_config and change the Port directive.
  2. Update your firewall to allow the new port.
  3. Restart SSH: systemctl restart sshd

Additional Resources

If you need help hardening your server, contact support@rightservers.com or open a ticket from the client portal.

Помог ли вам данный ответ? 0 Пользователи нашли это полезным (0 голосов)