Securing and maintaining your Linux VPS: firewall, fail2ban and updates

Published on 21/08/2026 Updated on 06/10/2026 84 views
Pare-feu VPS Linux fail2ban

A VPS has a public IP address: within an hour of going live, bots are already trying to log in. Three measures keep the vast majority of those attempts away, and a fourth stops you learning about an outage from an unhappy customer.

How do I set up the firewall on my Linux VPS?

With ufw on Debian and Ubuntu, firewalld on AlmaLinux, Rocky and CentOS Stream: deny everything by default, then open only SSH and the ports that are genuinely public.

On Debian and Ubuntu, with ufw:

apt install ufw
ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose

On AlmaLinux, Rocky and CentOS Stream, with firewalld:

dnf install firewalld
systemctl enable --now firewalld
firewall-cmd --permanent --add-service=ssh
firewall-cmd --permanent --add-service=http --add-service=https
firewall-cmd --reload
firewall-cmd --list-all

Allow SSH before enabling the firewall. The order above is not decorative: turning on a restrictive policy without an SSH rule cuts your access instantly. If that happens, the rescue console remains your way in.

Only open ports for genuinely public services. A database should almost never listen to the outside: bind it to 127.0.0.1 and administer it through an SSH tunnel.

How do I block repeated login attempts with fail2ban?

fail2ban reads the logs, spots repeated authentication failures and bans the offending address at firewall level.

apt install fail2ban        # Debian, Ubuntu
dnf install fail2ban        # AlmaLinux, Rocky, CentOS Stream

Create /etc/fail2ban/jail.local — never edit jail.conf, it is overwritten by updates:

[DEFAULT]
bantime  = 1h
findtime = 10m
maxretry = 5
ignoreip = 127.0.0.1/8 YOUR_OWN_IP

[sshd]
enabled = true

Then:

systemctl enable --now fail2ban
fail2ban-client status sshd

Filling ignoreip with your own address stops you banning yourself after a few unlucky attempts.

How do I install security updates on my server?

Manually with apt upgrade or dnf upgrade, or automatically with unattended-upgrades on Debian and Ubuntu and dnf-automatic on AlmaLinux, Rocky and CentOS Stream.

Manually, on a regular basis:

apt update && apt upgrade      # Debian, Ubuntu
dnf upgrade                    # AlmaLinux, Rocky, CentOS Stream

Automatically, for security patches only:

apt install unattended-upgrades && dpkg-reconfigure -plow unattended-upgrades
dnf install dnf-automatic && systemctl enable --now dnf-automatic.timer

Automation does not excuse you from looking: some patches need a service or kernel restart before they actually take effect.

systemctl list-units --failed
needrestart          # Debian, Ubuntu

How do I keep an eye on what is running on my VPS?

With systemctl and journalctl for service state and logs, df -h for disk space, and the Graphs tab in the client area for the overall picture.

systemctl status nginx        # state of a service
journalctl -u nginx -n 50     # its last 50 log lines
journalctl -p err -b          # errors since boot
df -h                         # disk space

A full disk is the most common and the quietest failure: logs stop being written, databases refuse writes, and nothing announces it until someone looks. Keep an eye on df -h and trim old logs with journalctl --vacuum-time=14d.

The Graphs tab in the client area is a useful complement: a CPU curve pinned at the ceiling for hours, unusual outbound traffic or memory saturation all show up immediately.

Does By-Hoster back up my VPS for me?

The client area offers no backup service for VPS. The snapshots available in the tab of that name are a safety net for a risky operation, not a backup: they live on the same storage as the machine. Plan a copy of your genuinely irreplaceable data outside the VPS, and test a restore from time to time.

Was this article helpful?