Knowledge base article
Contents (7 sections)

Securing a Linux server comes down to a few habits: keep it updated, log in with keys instead of passwords, and let a firewall allow only the services you actually run. This page is the short version for your own VPS or server, with the commands that are current in 2026. The full checklists live in two longer guides.

For the full guides

The complete server checklist (SSH, fail2ban, monitoring, backups, tuning) is in essential security and optimisation tips for your VPS. How firewalls work, and what is already done for you on Domain India hosting, is in the ultimate guide to firewalls.

Key takeaways

On a server you manage, update the system, create a sudo user, log in with an SSH key, turn off root and password logins, and block all inbound traffic except the ports you serve. Use firewalld on AlmaLinux or Rocky Linux and ufw on Ubuntu or Debian; both drive nftables underneath. On Domain India shared hosting the server firewall is managed for you and you can't change it.

1. Shared hosting or your own server?

Everything below needs root access. On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server, its firewall and its security software are managed by us for every account on the server, so customers don't configure them. On a Domain India VPS you have root access and the security of the server is yours: VPS plans are self-managed.

2. The basics that stop most attacks

  • Run a supported OS. CentOS Linux has reached end of life. Use a current release such as AlmaLinux or Rocky Linux 9 or 10, Ubuntu 24.04 LTS, or Debian 12 or 13.
  • Update regularly: sudo dnf upgrade --refresh on AlmaLinux or Rocky, sudo apt update && sudo apt full-upgrade on Ubuntu or Debian. Turn on automatic security updates (dnf-automatic or unattended-upgrades).
  • Use a normal user with sudo, not root, for daily work: sudo useradd -m -G wheel alice on RHEL-based systems, sudo adduser alice then sudo usermod -aG sudo alice on Ubuntu or Debian.
  • Keep SELinux or AppArmor on. If something is blocked, read the denial in the logs and fix the rule or label; don't switch the protection off.

3. Lock down SSH

Create a key on your own computer, copy it to the server, test a new login, and only then turn off passwords and root login.

bash
# On your computer
ssh-keygen -t ed25519 -C "[email protected]"
ssh-copy-id alice@your-server-ip
text
# /etc/ssh/sshd_config.d/10-hardening.conf on the server
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no

Check the file with sudo sshd -t, reload with sudo systemctl reload sshd (the service is ssh on Ubuntu), and keep your current session open until a new login works. The full walk-through, including fail2ban and two-factor SSH, is in the SSH security hardening checklist.

4. Choose your firewall tool

Modern Linux filters traffic with nftables in the kernel. You normally manage it through a friendlier front end.

ToolDefault onUse it when
firewalldAlmaLinux, Rocky Linux, RHELMost RHEL-family servers; zones and services with firewall-cmd
ufwUbuntuMost Ubuntu and Debian servers; simple allow and deny rules
nftables (nft)Kernel framework under bothYou want one hand-written ruleset file
iptablesLegacyOnly for old scripts; on current systems it is a compatibility layer over nftables

Use one tool per server. Running two front ends side by side causes rules that fight each other.

5. A safe starting ruleset

Block everything inbound, then open SSH, HTTP and HTTPS.

bash
# AlmaLinux / Rocky Linux (firewalld)
sudo systemctl enable --now firewalld
sudo firewall-cmd --permanent --add-service={ssh,http,https}
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

# Ubuntu / Debian (ufw)
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw limit 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
sudo ufw enable
sudo ufw status verbose

To block one address with firewalld, use a rich rule: sudo firewall-cmd --permanent --add-rich-rule='rule family="ipv4" source address="203.0.113.10" drop'. Note that --remove-port only removes a port you opened earlier; it does not block anything.

Two traps that expose servers

Never open database ports such as 3306 or 5432 to the internet; bind the database to 127.0.0.1 and reach it through an SSH tunnel. And Docker publishes container ports around ufw and firewalld, so publish them on 127.0.0.1 (for example -p 127.0.0.1:5432:5432) unless they must be public.

For hand-written nftables rules and a no-lockout way to apply them, see modern firewall management with nftables.

6. Brute-force protection and logs

Add fail2ban to ban addresses that keep failing logins: enable the [sshd] jail in /etc/fail2ban/jail.local with backend = systemd. You may read older guides recommending CSF. ConfigServer stopped developing CSF in 2025, so for a new server use your distribution's firewall plus fail2ban instead.

Read the logs with journalctl: sudo journalctl -u sshd --since today for SSH (-u ssh on Ubuntu), and sudo firewall-cmd --set-log-denied=all or sudo ufw logging on to record dropped packets. After each change, scan the server from another machine (nmap -Pn your-server-ip) to confirm only the intended ports answer.

7. Where Domain India fits

Shared hosting. The firewall and server security are handled for you. The ports customers need are open, and MySQL 3306 is closed from outside; the measured list is in Domain India hosting port numbers. If you think the firewall is blocking you, open a ticket with your public IP address and the time it happened. Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo); it is off by default, so ask support to enable it for your account.

VPS. Self-managed with root access, so everything on this page is yours to set up. cPanel isn't offered on VPS; the checkout offers no panel, CyberPanel, Webuzo or DirectAdmin.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details
Which firewall should I use on AlmaLinux or Rocky Linux?

firewalld, the default. It uses nftables underneath and is managed with firewall-cmd. Use ufw on Ubuntu and Debian.

Is iptables still used?

On current distributions iptables is a compatibility layer over nftables. Use firewalld, ufw or nft for new servers and keep iptables only for old scripts.

Should I still install CSF on a new server?

ConfigServer stopped developing CSF in 2025. For a new server, use your distribution's firewall (firewalld or ufw, or nftables directly) together with fail2ban.

Can I change the firewall on Domain India shared hosting?

No. The server firewall on shared hosting is managed by Domain India for every account on the server. If you think it is blocking you, open a support ticket with your public IP address and the time of the problem.

Does Domain India manage security on my VPS?

No. Domain India VPS plans are self-managed, so updates, firewall rules, SSH settings and backups are your responsibility.

Ready to secure your own server? Compare VPS plans, work through the full VPS security checklist, or open a support ticket if you think our shared-hosting firewall is blocking you. Our team is also on live chat around the clock.

Run a server you control

KVM virtualization, full root access and NVMe storage, with your choice of Linux and an optional control panel.

See VPS plans

Ready when you are

Get cPanel hosting from ₹125/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app