Back to articles

First security steps on your VPS

September 2, 2026
VPS

A new VPS has a public IP from the very first minute, and a public IP gets automated login attempts within hours. None of this is an attack aimed at you — it's continuous scanning that tries common passwords on every address that responds. This is the minimum to avoid being an easy target.

1. Update the system

The installed image was built on a certain date; everything fixed after that is still open on your machine.

apt update && apt upgrade -y

On AlmaLinux, Rocky Linux and CentOS:

dnf upgrade -y

2. Change the root password

passwd

Use a long, unique password generated by a password manager. The password from the credentials email passed through an inbox and shouldn't stay valid.

3. Create an unprivileged user

Working as root all the time turns any typo into damage. Create a regular user and give it admin access on demand:

adduser myname
usermod -aG sudo myname

On AlmaLinux and Rocky Linux, the group is wheel instead of sudo.

4. Use an SSH key instead of a password

A key can't be guessed, and it takes your machine out of reach of password scans. The step by step is in How to access your Linux VPS via SSH.

With the key working — and only after confirming it in a second terminal window — disable password login in /etc/ssh/sshd_config:

PasswordAuthentication no
PermitRootLogin prohibit-password

Reload the service:

systemctl restart sshd
⚠️Warning: If you lock yourself out, the way back in is the VirtFusion panel's VNC console, which connects directly to the machine and doesn't depend on SSH.

5. Close ports that don't need to be open

Every open port is more attack surface. Open only what your application uses.

On Ubuntu and Debian, with ufw:

ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable

On AlmaLinux and Rocky Linux, with firewalld:

firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload

6. Install Fail2ban

It reads the authentication logs and blocks IPs that get the password wrong several times in a row.

apt install fail2ban -y
systemctl enable --now fail2ban

The default configuration already covers SSH.

7. If your VPS runs Windows Server

  • Change the Administrator password on first login.
  • Restrict the Remote Desktop firewall rule to your IP, if it's static.
  • Create an admin account with a different name and disable Administrator — it's the user every scan tries first.
  • Keep Windows Update on.

8. What RedHosting already does for you

  • Two-layer Anti-DDoS protection: the GC network, with up to 20 Tbps of capacity, and an A10 appliance at the edge.
  • Daily automatic backup of the VPS.
  • 24/7 support in Portuguese, English, Spanish and German.

This protection handles the traffic that reaches the machine. The password, the firewall and the programs running inside it remain the responsibility of whoever manages it — that's the split on a VPS with root access.

Frequently asked questions

Do I really need to deal with security on a new VPS? +
Yes. A public IP starts receiving automated login attempts within hours. It's not a targeted attack — it's scanning that tries common passwords on every address that responds.
If I lock myself out, how do I get back in? +
Through the VirtFusion panel's VNC console, which connects directly to the machine and doesn't depend on SSH or firewall configuration.
Isn't RedHosting's Anti-DDoS protection enough? +
It handles the traffic that reaches the machine. The password, the firewall and the programs running inside it remain the responsibility of whoever manages it — that's the split on a VPS with root access.