---
title: "First security steps on your VPS"
description: "The minimum to do in the first hours of a new VPS: update the system, create an unprivileged user, swap the password for an SSH key and close ports that don't need to be open."
url: "https://redhosting.com.br/en/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps"
type: "article"
language: "en"
category: "VPS"
published: "2026-09-02"
translations:
  pt-BR: "https://redhosting.com.br/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps.md"
  en: "https://redhosting.com.br/en/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps.md"
  es: "https://redhosting.com.br/es/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps.md"
  de: "https://redhosting.com.br/de/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps.md"
---

# First security steps on your VPS

The minimum to do in the first hours of a new VPS: update the system, create an unprivileged user, swap the password for an SSH key and close ports that don't need to be open.

- RedHosting knowledge base guide — category: VPS
- HTML page: https://redhosting.com.br/en/base-de-conhecimento/primeiros-passos-de-seguranca-na-sua-vps
- Published on: 2026-09-02 · Language: en

A new VPS has a public IP from the very first minute, and a public IP gets automated login attempts within hours. None of this is an attack aimed at you — it's continuous scanning that tries common passwords on every address that responds. This is the minimum to avoid being an easy target.

## 1. Update the system

The installed image was built on a certain date; everything fixed after that is still open on your machine.

```
apt update && apt upgrade -y
```

On AlmaLinux, Rocky Linux and CentOS:

```
dnf upgrade -y
```

## 2. Change the root password

```
passwd
```

Use a long, unique password generated by a password manager. The password from the credentials email passed through an inbox and shouldn't stay valid.

## 3. Create an unprivileged user

Working as root all the time turns any typo into damage. Create a regular user and give it admin access on demand:

```
adduser myname
usermod -aG sudo myname
```

On AlmaLinux and Rocky Linux, the group is `wheel` instead of `sudo`.

## 4. Use an SSH key instead of a password

A key can't be guessed, and it takes your machine out of reach of password scans. The step by step is in [How to access your Linux VPS via SSH](/en/base-de-conhecimento/como-acessar-sua-vps-linux-via-ssh).

With the key working — **and only after confirming it in a second terminal window** — disable password login in `/etc/ssh/sshd_config`:

```
PasswordAuthentication no
PermitRootLogin prohibit-password
```

Reload the service:

```
systemctl restart sshd
```

  ⚠️**Warning**: If you lock yourself out, the way back in is the VirtFusion panel's VNC console, which connects directly to the machine and doesn't depend on SSH.

## 5. Close ports that don't need to be open

Every open port is more attack surface. Open only what your application uses.

On Ubuntu and Debian, with `ufw`:

```
ufw allow OpenSSH
ufw allow 80/tcp
ufw allow 443/tcp
ufw enable
```

On AlmaLinux and Rocky Linux, with `firewalld`:

```
firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http
firewall-cmd --permanent --add-service=https
firewall-cmd --reload
```

## 6. Install Fail2ban

It reads the authentication logs and blocks IPs that get the password wrong several times in a row.

```
apt install fail2ban -y
systemctl enable --now fail2ban
```

The default configuration already covers SSH.

## 7. If your VPS runs Windows Server

- Change the `Administrator` password on first login.
- Restrict the Remote Desktop firewall rule to your IP, if it's static.
- Create an admin account with a different name and disable `Administrator` — it's the user every scan tries first.
- Keep Windows Update on.

## 8. What RedHosting already does for you

- **Two-layer Anti-DDoS protection**: the GC network, with up to 20 Tbps of capacity, and an A10 appliance at the edge.
- **Daily automatic backup** of the VPS.
- **24/7 support** in Portuguese, English, Spanish and German.

This protection handles the traffic that reaches the machine. The password, the firewall and the programs running inside it remain the responsibility of whoever manages it — that's the split on a VPS with root access.

## Frequently asked questions

**Do I really need to deal with security on a new VPS?**

Yes. A public IP starts receiving automated login attempts within hours. It's not a targeted attack — it's scanning that tries common passwords on every address that responds.

**If I lock myself out, how do I get back in?**

Through the VirtFusion panel's VNC console, which connects directly to the machine and doesn't depend on SSH or firewall configuration.

**Isn't RedHosting's Anti-DDoS protection enough?**

It handles the traffic that reaches the machine. The password, the firewall and the programs running inside it remain the responsibility of whoever manages it — that's the split on a VPS with root access.

## Navigation — VPS (article 6 of 6)

- Previous article: [Ryzen 9 VPS or Xeon VPS: which one to choose](https://redhosting.com.br/en/base-de-conhecimento/vps-ryzen-9-ou-vps-xeon-qual-escolher.md) — https://redhosting.com.br/en/base-de-conhecimento/vps-ryzen-9-ou-vps-xeon-qual-escolher
- Back to the knowledge base: https://redhosting.com.br/en/base-de-conhecimento

---

Need help with these steps? RedHosting's 24/7 support: suporte@redhosting.com.br · WhatsApp +55 11 98833-3902 · https://redhosting.com.br/discord

More guides: https://redhosting.com.br/en/base-de-conhecimento.md
