A VPS has a public IP address: within an hour of going live, bots are already trying to log in. Three measures keep the vast majority of those attempts away, and a fourth stops you learning about an outage from an unhappy customer.
How do I set up the firewall on my Linux VPS?
With ufw on Debian and Ubuntu, firewalld on AlmaLinux, Rocky and CentOS Stream: deny everything by default, then open only SSH and the ports that are genuinely public.
On Debian and Ubuntu, with ufw:
apt install ufw
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose
On AlmaLinux, Rocky and CentOS Stream, with firewalld:
dnf install firewalld
systemctl enable --now firewalld
firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload
firewall-cmd --list-all
Allow SSH before enabling the firewall. The order above is not decorative: turning on a restrictive policy without an SSH rule cuts your access instantly. If that happens, the rescue console remains your way in.
Only open ports for genuinely public services. A database should almost never listen to the outside: bind it to 127.0.0.1 and administer it through an SSH tunnel.
How do I block repeated login attempts with fail2ban?
fail2ban reads the logs, spots repeated authentication failures and bans the offending address at firewall level.
apt install fail2ban # Debian, Ubuntu
dnf install fail2ban # AlmaLinux, Rocky, CentOS Stream
Create /etc/fail2ban/jail.local — never edit jail.conf, it is overwritten by updates:
[DEFAULT]
bantime = 1h
findtime = 10m
maxretry = 5
ignoreip = 127.0.0.1/8 YOUR_OWN_IP
[sshd]
enabled = true
Then:
systemctl enable --now fail2ban
fail2ban-client status sshd
Filling ignoreip with your own address stops you banning yourself after a few unlucky attempts.
How do I install security updates on my server?
Manually with apt upgrade or dnf upgrade, or automatically with unattended-upgrades on Debian and Ubuntu and dnf-automatic on AlmaLinux, Rocky and CentOS Stream.
Manually, on a regular basis:
apt update && apt upgrade # Debian, Ubuntu
dnf upgrade # AlmaLinux, Rocky, CentOS Stream
Automatically, for security patches only:
apt install unattended-upgrades && dpkg-reconfigure -plow unattended-upgrades
dnf install dnf-automatic && systemctl enable --now dnf-automatic.timer
Automation does not excuse you from looking: some patches need a service or kernel restart before they actually take effect.
systemctl list-units --failed
needrestart # Debian, Ubuntu
How do I keep an eye on what is running on my VPS?
With systemctl and journalctl for service state and logs, df -h for disk space, and the Graphs tab in the client area for the overall picture.
systemctl status nginx # state of a service
journalctl -u nginx -n 50 # its last 50 log lines
journalctl -p err -b # errors since boot
df -h # disk space
A full disk is the most common and the quietest failure: logs stop being written, databases refuse writes, and nothing announces it until someone looks. Keep an eye on df -h and trim old logs with journalctl --vacuum-time=14d.
The Graphs tab in the client area is a useful complement: a CPU curve pinned at the ceiling for hours, unusual outbound traffic or memory saturation all show up immediately.
Does By-Hoster back up my VPS for me?
The client area offers no backup service for VPS. The snapshots available in the tab of that name are a safety net for a risky operation, not a backup: they live on the same storage as the machine. Plan a copy of your genuinely irreplaceable data outside the VPS, and test a restore from time to time.