Servers
Secure your server in 10 minutes
The five habits that protect a server from most attacks.
All guides
- 1
Update the system
Install security updates right after delivery, then regularly.
apt update && apt upgrade -y - 2
Use an SSH key
Add your SSH key (see the dedicated guide), then disable password login.
sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config && systemctl restart ssh - 3
Turn on the network firewall
In your server's Firewall tab, turn it on: only the ports you open are reachable (SSH, web…).
- 4
Block password guessing
Fail2ban automatically bans addresses that try too many passwords.
apt install -y fail2ban && systemctl enable --now fail2ban - 5
Plan backups
Take a snapshot before every big change, and turn on automatic backups for daily copies.