All articles
Guides

First VPS setup on Ubuntu and Debian: security in 15 minutes

In short

Right after the VPS starts, update the system, create a sudo user, set up SSH key login and disable password and root logins, then enable the UFW firewall and fail2ban. It takes 15 minutes, and after that the password brute-forcing that bots run against every server on the internet stops being a threat.

Key takeaways
  • The first setup of an Ubuntu or Debian VPS takes about 15 minutes: system updates, a sudo user, SSH key login, no password or root login, the UFW firewall and fail2ban.
  • Password and root logins on a Linux server are disabled with a file /etc/ssh/sshd_config.d/00-hardening.conf containing PasswordAuthentication no and PermitRootLogin no - and only after SSH key login has been tested.
  • The UFW firewall should be enabled only after the ufw allow OpenSSH rule, otherwise UFW cuts off the current SSH session; ports 80 and 443 are opened only if the server will host a website.
  • On Debian 12 the SSH log goes only to systemd, so fail2ban protecting SSH is configured with backend = systemd.
  • On a VPS with 2 GB of RAM, a 2 GB swap file keeps processes from being killed during a short load spike, but it does not replace memory.

Step 1. Connect to the server

The IP address and root password are shown in the panel under «My Servers» and in the Telegram bot. Connect from a terminal - macOS, Linux and Windows 10/11 have an SSH client built in (clients, keys and common errors are covered in the SSH connection guide):

bash
ssh root@SERVER_IP

Step 2. Update the system

The system image was built before the latest security fixes came out, so install all updates first:

bash
apt update && apt upgrade -y

Step 3. Create your own user

Working as root all the time is risky: every mistake runs with full rights. Create a user (deploy below, any name works) and give it sudo:

bash
adduser deploy
usermod -aG sudo deploy

Step 4. Set up SSH key login

On your own computer (not the server), create a key and send its public part to the server. macOS and Linux:

bash
ssh-keygen -t ed25519
ssh-copy-id deploy@SERVER_IP

Windows PowerShell has no ssh-copy-id - this line does the same:

PowerShell
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh deploy@SERVER_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"

Check that ssh deploy@SERVER_IP logs you in without a password. Only then move on to the next step.

Step 5. Disable password and root login

The settings go into a separate file in sshd_config.d: Ubuntu may ship a cloud-init file there that re-enables passwords, and a file prefixed 00- is read first and wins. sshd -t checks the configuration before the restart:

bash
sudo tee /etc/ssh/sshd_config.d/00-hardening.conf > /dev/null <<'EOF'
PasswordAuthentication no
PermitRootLogin no
EOF
sudo sshd -t && sudo systemctl restart ssh

Step 6. Enable the UFW firewall

Allow SSH before enabling the firewall, or it will cut off your session. Open ports 80 and 443 only if the server will host a website:

bash
sudo apt install -y ufw
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo ufw status

Step 7. Install fail2ban

fail2ban blocks addresses that keep failing to log in. On Debian 12 the SSH log goes only to systemd, which is why the config sets backend = systemd:

bash
sudo apt install -y fail2ban python3-systemd
sudo tee /etc/fail2ban/jail.local > /dev/null <<'EOF'
[sshd]
enabled = true
backend = systemd
EOF
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd

Step 8. Turn on automatic security updates

The unattended-upgrades package installs security fixes on its own every day. Install it and confirm in the dialog that appears:

bash
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

Step 9. Add swap on a small plan

With 2 GB of RAM, a swap file keeps processes from being killed during a short load spike. It does not replace memory: if swap is in constant use, move to a larger plan.

bash
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
Launch a server in 2 minutes

AMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card.

Order a Server

FAQ

Which user does the VPS come with?

Tihost Linux servers come with root, Windows Server with Administrator. The password is shown in the panel and the bot and can be changed with «Change Password».

What if I locked myself out of SSH?

Open «Console (VNC)» on the server page in the panel: it is the server's screen in the browser and needs no SSH. Log in and fix the SSH or firewall settings.

Do I need fail2ban if password login is disabled?

With password login disabled, fail2ban is no longer critical, but useful: it cuts log noise and brute-force load and protects other services if you add rules for them.

Should I change the SSH port?

Changing the SSH port reduces automated login attempts but does not replace key login. What matters is keys instead of passwords and no root login.

How do I connect to a VPS over SSH from Windows?

Windows 10 and 11 have the OpenSSH client built in: open PowerShell and run ssh root@SERVER_IP with the server address from the panel. Keys, PuTTY and common connection errors are covered in the SSH guide.