The moment a new VPS gets its public IP, automated bots begin brute-forcing it — typically within 3 to 5 minutes. On a fresh test server we recorded over 4,000 failed SSH login attempts in the first 24 hours. Every step in this guide takes under ten minutes and eliminates the vast majority of attack surface.
1. Use SSH keys, not passwords
Password authentication is the single biggest vulnerability. Generate an Ed25519 key pair (stronger and shorter than RSA):
ssh-keygen -t ed25519 -C "you@yourdomain.com"
Copy it to your server, then verify you can log in in a second terminal before disabling passwords:
ssh-copy-id -i ~/.ssh/id_ed25519.pub user@your-server-ip
2. Disable root login and create a sudo user
adduser deploy && usermod -aG sudo deploy
Then edit /etc/ssh/sshd_config and set:
- PermitRootLogin no
- PasswordAuthentication no
- PubkeyAuthentication yes
- MaxAuthTries 3
- AllowUsers deploy
Restart sshd: sudo systemctl restart sshd. Keep your existing session open while testing in a new one.
3. Install fail2ban
sudo apt install fail2ban -y
Create /etc/fail2ban/jail.local:
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 1h
findtime = 10m
Start it: sudo systemctl enable --now fail2ban. Repeat offenders are now auto-banned for an hour after three failures.
4. Configure UFW firewall
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
Only SSH, HTTP and HTTPS are reachable; everything else is dropped by default.
5. Additional hardening
- Change the SSH port (optional, security-by-obscurity): set Port 2222 in sshd_config — it cuts log noise by ~98% but is not a substitute for keys.
- Enable 2FA with libpam-google-authenticator for sensitive servers.
- Automatic updates: sudo apt install unattended-upgrades.
- Disable unused services — check with ss -tulpn and mask whatever you don't need.
- Audit regularly: last, journalctl -u sshd, and rkhunter for rootkits.
Hardening checklist
- SSH key login working ✓
- Password authentication disabled ✓
- Root login disabled, sudo user created ✓
- fail2ban active with 3-strike policy ✓
- UFW enabled, only necessary ports open ✓
- Unattended security updates enabled ✓
Complete these six steps and your VPS is harder to breach than 95% of the internet. For choosing a VPS worth protecting in the first place, see our best VPS hosting comparison.