---
title: "First VPS setup on Ubuntu and Debian: security in 15 minutes"
description: "What to do right after buying a Linux VPS: updates, your own user, SSH key login, no passwords and no root, UFW firewall, fail2ban and swap. Commands for Ubuntu and Debian."
url: https://tihost.io/en/blog/vps-first-setup
language: en
section: "Guides"
published: 2026-09-24
updated: 2026-10-05
publisher: Tihost (https://tihost.io)
---

# First VPS setup on Ubuntu and Debian: security in 15 minutes

> **In short:** Right after the VPS starts, update the system, create a sudo user, set up SSH key login and disable password and root logins, then enable the UFW firewall and fail2ban. It takes 15 minutes, and after that the password brute-forcing that bots run against every server on the internet stops being a threat.

**Key takeaways:**

- The first setup of an Ubuntu or Debian VPS takes about 15 minutes: system updates, a sudo user, SSH key login, no password or root login, the UFW firewall and fail2ban.
- Password and root logins on a Linux server are disabled with a file `/etc/ssh/sshd_config.d/00-hardening.conf` containing `PasswordAuthentication no` and `PermitRootLogin no` - and only after SSH key login has been tested.
- The UFW firewall should be enabled only after the `ufw allow OpenSSH` rule, otherwise UFW cuts off the current SSH session; ports 80 and 443 are opened only if the server will host a website.
- On Debian 12 the SSH log goes only to systemd, so fail2ban protecting SSH is configured with `backend = systemd`.
- On a VPS with 2 GB of RAM, a 2 GB swap file keeps processes from being killed during a short load spike, but it does not replace memory.

> Commands are checked for Ubuntu 22.04/24.04 and Debian 12. This guide does not apply to Windows Server - you connect to it over RDP as Administrator.

## Step 1. Connect to the server

The IP address and root password are shown in the panel under «My Servers» and in the Telegram bot. Connect from a terminal - macOS, Linux and Windows 10/11 have an SSH client built in (clients, keys and common errors are covered in the [SSH connection guide](https://tihost.io/en/blog/ssh-connect-to-vps)):

```bash
ssh root@SERVER_IP
```

## Step 2. Update the system

The system image was built before the latest security fixes came out, so install all updates first:

```bash
apt update && apt upgrade -y
```

## Step 3. Create your own user

Working as root all the time is risky: every mistake runs with full rights. Create a user (`deploy` below, any name works) and give it sudo:

```bash
adduser deploy
usermod -aG sudo deploy
```

## Step 4. Set up SSH key login

On your own computer (not the server), create a key and send its public part to the server. macOS and Linux:

```bash
ssh-keygen -t ed25519
ssh-copy-id deploy@SERVER_IP
```

Windows PowerShell has no `ssh-copy-id` - this line does the same:

`PowerShell`:

```
type $env:USERPROFILE\.ssh\id_ed25519.pub | ssh deploy@SERVER_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys"
```

Check that `ssh deploy@SERVER_IP` logs you in without a password. Only then move on to the next step.

## Step 5. Disable password and root login

The settings go into a separate file in `sshd_config.d`: Ubuntu may ship a cloud-init file there that re-enables passwords, and a file prefixed `00-` is read first and wins. `sshd -t` checks the configuration before the restart:

```bash
sudo tee /etc/ssh/sshd_config.d/00-hardening.conf > /dev/null <<'EOF'
PasswordAuthentication no
PermitRootLogin no
EOF
sudo sshd -t && sudo systemctl restart ssh
```

> Keep the current session open until you have checked key login in a new terminal window. If you do lose access, open «Console (VNC)» on the server page in the panel: it works without SSH, right in the browser.

## Step 6. Enable the UFW firewall

Allow SSH before enabling the firewall, or it will cut off your session. Open ports 80 and 443 only if the server will host a website:

```bash
sudo apt install -y ufw
sudo ufw allow OpenSSH
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo ufw status
```

> Docker publishes container ports around UFW rules. If you install Docker, read the ports section of the [Docker guide](https://tihost.io/en/blog/install-docker-ubuntu-debian).

## Step 7. Install fail2ban

fail2ban blocks addresses that keep failing to log in. On Debian 12 the SSH log goes only to systemd, which is why the config sets `backend = systemd`:

```bash
sudo apt install -y fail2ban python3-systemd
sudo tee /etc/fail2ban/jail.local > /dev/null <<'EOF'
[sshd]
enabled = true
backend = systemd
EOF
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshd
```

## Step 8. Turn on automatic security updates

The `unattended-upgrades` package installs security fixes on its own every day. Install it and confirm in the dialog that appears:

```bash
sudo apt install -y unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades
```

## Step 9. Add swap on a small plan

With 2 GB of RAM, a swap file keeps processes from being killed during a short load spike. It does not replace memory: if swap is in constant use, move to a [larger plan](https://tihost.io/en/blog/starter-vps).

```bash
sudo fallocate -l 2G /swapfile
sudo chmod 600 /swapfile
sudo mkswap /swapfile
sudo swapon /swapfile
echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
```

**Launch a server in 2 minutes.** AMD Ryzen 9, NVMe and DDoS protection in Germany, Finland and Poland. Pay with crypto or card. [Order a Server](https://tihost.io/login)

## FAQ

### Which user does the VPS come with?

Tihost Linux servers come with root, Windows Server with Administrator. The password is shown in the panel and the bot and can be changed with «Change Password».

### What if I locked myself out of SSH?

Open «Console (VNC)» on the server page in the panel: it is the server's screen in the browser and needs no SSH. Log in and fix the SSH or firewall settings.

### Do I need fail2ban if password login is disabled?

With password login disabled, fail2ban is no longer critical, but useful: it cuts log noise and brute-force load and protects other services if you add rules for them.

### Should I change the SSH port?

Changing the SSH port reduces automated login attempts but does not replace key login. What matters is keys instead of passwords and no root login.

### How do I connect to a VPS over SSH from Windows?

Windows 10 and 11 have the OpenSSH client built in: open PowerShell and run `ssh root@SERVER_IP` with the server address from the panel. Keys, PuTTY and common connection errors are covered in the [SSH guide](https://tihost.io/en/blog/ssh-connect-to-vps).

---

Updated 2026-10-05 · https://tihost.io/en/blog/vps-first-setup
