LinuxSecurityUFWFail2banSSHHardening
Linux VPS Security Hardening: SSH Keys, UFW Firewall & Fail2ban
Altivora Security Team
11 min read
1. Disable Password Authentication & Root Login
In /etc/ssh/sshd_config:
PermitRootLogin prohibit-password
PasswordAuthentication no
Port 2222
2. Configure UFW Firewall
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw allow 2222/tcp comment 'Custom SSH'
sudo ufw allow 80/tcp comment 'HTTP'
sudo ufw allow 443/tcp comment 'HTTPS'
sudo ufw enable
3. Install & Configure Fail2ban
Automatically ban IPs that trigger multiple failed authentication attempts:
[sshd]
enabled = true
port = 2222
maxretry = 3
bantime = 1d
findtime = 10m
High-Performance Infrastructure
Deploy with Altivora Hosting
Gen4 NVMe Soft RAID storage, AMD EPYC & Intel Xeon compute cores, unmetered bandwidth, and automated DDoS mitigation.
Related Technical Guides
Cloudflare Spectrum
How Cloudflare Spectrum L4 Reverse Proxy Neutralizes Game Server DDoS
Understand how Anycast Layer 4 proxying protects raw TCP and UDP ports from volumetric attacks while maintaining ultra-low gaming latency.
Read guide→
Cloudflare Spectrum
Protecting Game Servers with Cloudflare Spectrum: Setup & Proxy Protocol
Guide to setting up Cloudflare Spectrum for game servers and enabling Proxy Protocol v2 to preserve real player IP addresses.
Read guide→
PostgreSQL
Self-Hosting PostgreSQL 16 & Redis on NVMe VPS: Hardening & Backup Guide
Step-by-step configuration for running production PostgreSQL and Redis on Linux KVM VPS with SSL encryption and backups.
Read guide→
Ready to upgrade your infrastructure?
Experience the Altivora difference with 99.99% uptime SLA and 60-second setup.
