Securing a Linux server comes down to a few habits: keep it updated, log in with keys instead of passwords, and let a firewall allow only the services you actually run. This page is the short version for your own VPS or server, with the commands that are current in 2026. The full checklists live in two longer guides.
The complete server checklist (SSH, fail2ban, monitoring, backups, tuning) is in essential security and optimisation tips for your VPS. How firewalls work, and what is already done for you on Domain India hosting, is in the ultimate guide to firewalls.
On a server you manage, update the system, create a sudo user, log in with an SSH key, turn off root and password logins, and block all inbound traffic except the ports you serve. Use firewalld on AlmaLinux or Rocky Linux and ufw on Ubuntu or Debian; both drive nftables underneath. On Domain India shared hosting the server firewall is managed for you and you can't change it.
1. Shared hosting or your own server?
Everything below needs root access. On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server, its firewall and its security software are managed by us for every account on the server, so customers don't configure them. On a Domain India VPS you have root access and the security of the server is yours: VPS plans are self-managed.
2. The basics that stop most attacks
- Run a supported OS. CentOS Linux has reached end of life. Use a current release such as AlmaLinux or Rocky Linux 9 or 10, Ubuntu 24.04 LTS, or Debian 12 or 13.
- Update regularly:
sudo dnf upgrade --refreshon AlmaLinux or Rocky,sudo apt update && sudo apt full-upgradeon Ubuntu or Debian. Turn on automatic security updates (dnf-automaticorunattended-upgrades). - Use a normal user with sudo, not root, for daily work:
sudo useradd -m -G wheel aliceon RHEL-based systems,sudo adduser alicethensudo usermod -aG sudo aliceon Ubuntu or Debian. - Keep SELinux or AppArmor on. If something is blocked, read the denial in the logs and fix the rule or label; don't switch the protection off.
3. Lock down SSH
Create a key on your own computer, copy it to the server, test a new login, and only then turn off passwords and root login.
# On your computer
ssh-keygen -t ed25519 -C "[email protected]"
ssh-copy-id alice@your-server-ip# /etc/ssh/sshd_config.d/10-hardening.conf on the server
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication noCheck the file with sudo sshd -t, reload with sudo systemctl reload sshd (the service is ssh on Ubuntu), and keep your current session open until a new login works. The full walk-through, including fail2ban and two-factor SSH, is in the SSH security hardening checklist.
4. Choose your firewall tool
Modern Linux filters traffic with nftables in the kernel. You normally manage it through a friendlier front end.
| Tool | Default on | Use it when |
|---|---|---|
| firewalld | AlmaLinux, Rocky Linux, RHEL | Most RHEL-family servers; zones and services with firewall-cmd |
| ufw | Ubuntu | Most Ubuntu and Debian servers; simple allow and deny rules |
| nftables (nft) | Kernel framework under both | You want one hand-written ruleset file |
| iptables | Legacy | Only for old scripts; on current systems it is a compatibility layer over nftables |
Use one tool per server. Running two front ends side by side causes rules that fight each other.
5. A safe starting ruleset
Block everything inbound, then open SSH, HTTP and HTTPS.
# AlmaLinux / Rocky Linux (firewalld)
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service={ssh,http,https}
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
# Ubuntu / Debian (ufw)
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verboseTo block one address with firewalld, use a rich rule: sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="203.0.113.10" drop'. Note that --remove-port only removes a port you opened earlier; it does not block anything.
Never open database ports such as 3306 or 5432 to the internet; bind the database to 127.0.0.1 and reach it through an SSH tunnel. And Docker publishes container ports around ufw and firewalld, so publish them on 127.0.0.1 (for example -p 127.0.0.1:5432:5432) unless they must be public.
For hand-written nftables rules and a no-lockout way to apply them, see modern firewall management with nftables.
6. Brute-force protection and logs
Add fail2ban to ban addresses that keep failing logins: enable the [sshd] jail in /etc/fail2ban/jail.local with backend = systemd. You may read older guides recommending CSF. ConfigServer stopped developing CSF in 2025, so for a new server use your distribution's firewall plus fail2ban instead.
Read the logs with journalctl: sudo journalctl -u sshd --since today for SSH (-u ssh on Ubuntu), and sudo firewall-cmd --set-log-denied=all or sudo ufw logging on to record dropped packets. After each change, scan the server from another machine (nmap -Pn your-server-ip) to confirm only the intended ports answer.
7. Where Domain India fits
Shared hosting. The firewall and server security are handled for you. The ports customers need are open, and MySQL 3306 is closed from outside; the measured list is in Domain India hosting port numbers. If you think the firewall is blocking you, open a ticket with your public IP address and the time it happened. Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo); it is off by default, so ask support to enable it for your account.
VPS. Self-managed with root access, so everything on this page is yours to set up. cPanel isn't offered on VPS; the checkout offers no panel, CyberPanel, Webuzo or DirectAdmin.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
Which firewall should I use on AlmaLinux or Rocky Linux?
firewalld, the default. It uses nftables underneath and is managed with firewall-cmd. Use ufw on Ubuntu and Debian.
Is iptables still used?
On current distributions iptables is a compatibility layer over nftables. Use firewalld, ufw or nft for new servers and keep iptables only for old scripts.
Should I still install CSF on a new server?
ConfigServer stopped developing CSF in 2025. For a new server, use your distribution's firewall (firewalld or ufw, or nftables directly) together with fail2ban.
Can I change the firewall on Domain India shared hosting?
No. The server firewall on shared hosting is managed by Domain India for every account on the server. If you think it is blocking you, open a support ticket with your public IP address and the time of the problem.
Does Domain India manage security on my VPS?
No. Domain India VPS plans are self-managed, so updates, firewall rules, SSH settings and backups are your responsibility.
Ready to secure your own server? Compare VPS plans, work through the full VPS security checklist, or open a support ticket if you think our shared-hosting firewall is blocking you. Our team is also on live chat around the clock.
KVM virtualization, full root access and NVMe storage, with your choice of Linux and an optional control panel.
See VPS plans