You just deployed a fresh Linux server — congratulations! Before you install anything else, take 15 minutes to lock it down. These ten steps stop the vast majority of automated attacks that hit every public IP within minutes of going online.
apt update && apt full-upgrade -y # Debian/Ubuntu
dnf upgrade -y # AlmaLinux/Rocky
adduser deploy
usermod -aG sudo deploy
Day-to-day work should never happen as root.
On your local machine run ssh-keygen -t ed25519, then copy the key with ssh-copy-id deploy@your-server. Test the login before the next step.
Edit /etc/ssh/sshd_config:
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
Then restart the service: systemctl restart ssh.
ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
Only open what you actually use. Everything else stays closed.
apt install fail2ban -y
The default configuration already bans IPs that brute-force SSH. For busy servers, raise the ban time in /etc/fail2ban/jail.local.
apt install unattended-upgrades -y
dpkg-reconfigure --priority=low unattended-upgrades
Accurate time matters for logs and TLS. timedatectl set-ntp true is usually all you need.
ss -tulpn
Anything listening on 0.0.0.0 that you don't recognise deserves investigation. Databases should listen on 127.0.0.1 unless you have a private network.
A server without backups is a countdown timer. See our guide to the 3-2-1 backup strategy on this blog.
On NetVO infrastructure, enterprise DDoS protection is already filtering traffic before it reaches your server — but host-level hardening is still your responsibility. Ten minutes now saves a very bad weekend later. Questions? Our engineers are available 24/7 through the ticket system.