Skip to main content
A Linux VPS with a public IP address gets automated SSH password-guessing from the moment it boots. You have full root access, so securing the server is up to you. Do these steps right after your first sign-in:
  1. Install all updates.
  2. Create a user with sudo rights.
  3. Sign in with an SSH key.
  4. Turn off password and root logins over SSH.
  5. Turn on a firewall that allows SSH.
  6. Install security updates automatically.
  7. Check which services listen on the network.
Commands are shown for the root account. From a sudo user, put sudo in front of them. Replace alice with your own username. FreeBSD uses different tools, so these commands don’t apply to it.
A mistake in the SSH or firewall steps can lock you out. Keep the server’s page in the Billing Portal open: the Console button gives you the server’s screen and keyboard in your browser, even when SSH is blocked. Sign in there as root with its password to undo a change. If you don’t know the root password, use Reset password first; the server must be running.

Update the system

If a new kernel was installed, restart the server with reboot.

Create a sudo user

Use your own account for daily work and keep root for recovery.
adduser asks for a password for the new user.
Check that it works. This asks for alice’s password and should print root:

Sign in with an SSH key

If you don’t use a key yet, create one and add it to the server: see Sign in with an SSH key. For future installs, save it on the SSH keys page of the Billing Portal. Keys added in the Billing Portal or with ssh-copy-id root@YOUR_IP belong to root. To use the same keys for your new user, run as root:
On AlmaLinux, Rocky Linux, Oracle Linux, CentOS Stream and Fedora, also run restorecon -R /home/alice/.ssh so SELinux lets SSH read the file. From your computer, check that ssh alice@YOUR_IP signs you in without a password.

Turn off password and root login

Once your key works, stop SSH from accepting passwords. Bots can then no longer guess their way in.
Keep your current SSH session open until you have tested a new one. Restarting SSH doesn’t close existing sessions, so you can still undo a mistake. If you do get locked out, use the Console in the Billing Portal.
1

Choose where to put the settings

Run:
If it prints a line with /etc/ssh/sshd_config.d/*.conf, create a settings file that is read before the others:
If it prints nothing, open /etc/ssh/sshd_config in an editor and set PermitRootLogin prohibit-password and PasswordAuthentication no. Change the existing lines instead of adding second copies: SSH uses the first value it reads.prohibit-password still lets root sign in with a key. If you sign in as your sudo user, use PermitRootLogin no to block root over SSH entirely.
2

Check the configuration

sshd -t prints nothing when the configuration is valid. The second command should show passwordauthentication no. If kbdinteractiveauthentication or challengeresponseauthentication shows yes, set it to no the same way, because it can also accept passwords.
3

Restart SSH

4

Test in a new terminal

Without closing your current session, open a new terminal on your computer and check that your key still works:
Then check that passwords are refused:
This should end with Permission denied (publickey). If it asks for a password, password login is still on: go back to the second step.
Reset password in the Billing Portal still sets the root password. With password login off, that password works in the Console, not over SSH.

Turn on a firewall

Allow SSH before you turn the firewall on. If you moved SSH to another port, allow that port instead of 22.
Open more ports as you need them, for example ufw allow 443/tcp for a website.

Block repeated sign-in attempts (optional)

Once password login is off, password-guessing can’t succeed, so this is optional. If you want to block addresses that keep trying, install fail2ban from your distribution’s packages (on AlmaLinux, Rocky Linux and Oracle Linux it comes from the EPEL repository) and turn on its sshd jail. See the fail2ban project for setup.

Install security updates automatically

Answer Yes. By default it installs security updates only.

Check what is listening

List every service that accepts network connections:
On Alpine Linux, use netstat -tulpn. Services bound to 0.0.0.0, [::] or * accept connections from the internet unless the firewall blocks them; 127.0.0.1 and [::1] are local only. Stop anything you don’t need, for example systemctl disable --now SERVICE, or on Alpine rc-service SERVICE stop and rc-update del SERVICE.
Outgoing port 25 (SMTP) is blocked by default. To send email directly from your server, open a ticket with a business justification.

Connect to your Linux VPS via SSH

Manage SSH keys

Reset server password

Supported Linux distributions

Last modified on October 11, 2026