Firewall & Security Hardening

VPS Security Hardening Checklist

By the Domain India teamPublished 6 min read
Knowledge base article
Contents (5 sections)

A new VPS can be reached from the whole internet the moment it goes live, and automated bots start trying its SSH port within minutes. This checklist is the short version: ten things to do, in order, before you put a website or app on it. It applies to a VPS where you have root access; on Domain India shared hosting (cPanel, DirectAdmin, Webuzo) the server is managed for you and you can't change its firewall or SSH settings.

For the full guides

The complete walk-through, with commands for Ubuntu, Debian, AlmaLinux and Rocky Linux, is in Essential security and optimization tips for your VPS. Every SSH setting is explained in the SSH security hardening checklist.

Key takeaways

Update the operating system and turn on automatic security updates, create a sudo user, log in with an SSH key, then switch off root and password logins. Allow only the ports you use through a firewall, add fail2ban, remove services you don't need, keep databases private and keep tested backups off the server. A Domain India VPS is self-managed, so every step here is yours to carry out.

1. The ten-step checklist

StepWhat to doDone when
1. Supported OSUse a current LTS release such as Ubuntu 24.04, Debian 12 or 13, AlmaLinux 9 or 10, or Rocky Linux 9 or 10The release still receives security updates
2. UpdatesInstall all updates, then turn on unattended-upgrades (Ubuntu, Debian) or dnf-automatic (AlmaLinux, Rocky)No security updates are waiting
3. Sudo userCreate your own user and add it to the sudo or wheel groupsudo whoami prints root
4. SSH keyRun ssh-keygen -t ed25519 on your computer, then ssh-copy-idKey login works in a new terminal
5. No root, no passwordsSet PermitRootLogin and PasswordAuthentication to nosshd -T shows both as no
6. Firewallufw or firewalld, deny incoming by defaultOnly SSH, 80, 443 and ports you really serve are open
7. fail2banEnable the sshd jail with backend = systemdfail2ban-client status sshd lists the jail
8. Unused servicesStop and disable what you don't usess -tulpn shows nothing you don't recognise
9. Private databasesBind MySQL or PostgreSQL to 127.0.0.1Ports 3306 and 5432 can't be reached from outside
10. BackupsCopies on another system, restored at least onceA test restore has worked
Printable checklist of ten VPS security steps, from supported OS and updates to firewall, fail2ban, private databases and tested backups
The ten steps as a printable checklist

2. SSH: the settings that matter

Put your SSH settings in a drop-in file such as /etc/ssh/sshd_config.d/00-hardening.conf, so a file like 50-cloud-init.conf can't switch password login back on:

text
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3

Then check the file and the settings sshd will actually use, and reload it:

bash
sudo sshd -t
sudo sshd -T | grep -Ei '^(permitrootlogin|passwordauthentication)'
sudo systemctl reload sshd    # the service is called ssh on Ubuntu and Debian
Test in a second terminal before you log out

Keep your current session open and log in again from a new terminal. There is no console page for your VPS in the client area, so if you lock yourself out you have to open a ticket and wait for support. For the same reason, use reboot, never poweroff: a VPS powered off from inside stays off until support starts it.

3. Firewall and brute-force protection

Deny incoming traffic by default and open only SSH, 80, 443 and the ports you really serve, with ufw on Ubuntu and Debian or firewalld on AlmaLinux and Rocky Linux. Add fail2ban with an sshd jail and your own static IP in ignoreip. If a control panel you install brings its own firewall, use that one and don't run two side by side. For a new server, don't start with CSF: ConfigServer stopped developing it in 2025. The exact commands are in the full VPS security guide.

4. Older advice you can drop

Many checklists online, including the earlier version of this page, still carry dated or risky steps:

Older adviceWhat to do now
Set UsePAM noLeave UsePAM at the distribution default. Key-only login doesn't need it switched off
Copy jail.conf to jail.local and edit itPut only your own changes in jail.local, with backend = systemd
Point fail2ban at /var/log/auth.logDebian 12 and later log to the systemd journal and have no auth.log by default
yum update on CentOSCentOS Linux is end of life; migrate to AlmaLinux or Rocky Linux and use dnf
Add a /run/shm line to /etc/fstabNot needed on current releases, and a wrong fstab line can stop the server booting
Nightly rkhunter scansRun a Lynis audit every few months instead; it reports what to fix

5. Running this on a Domain India VPS

Domain India VPS plans use KVM virtualisation with full root access and NVMe storage, and they are self-managed: updates, firewall rules, backups and the software you install are yours to look after. At checkout you can choose no control panel, CyberPanel, Webuzo or DirectAdmin; cPanel isn't offered on a VPS. To reboot, use SSH from inside the server. For a start, stop, reinstall or console access, open a ticket and support will do it.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Prices on the cards exclude 18% GST.

Rather not manage a server? Shared hosting keeps server security on our side, and the App Platform runs Node.js apps, or any app with a Dockerfile, without a server to maintain.

What should I do first on a new VPS?

Update the operating system, create a sudo user, add an SSH key, switch off root and password logins over SSH, and enable a firewall that allows only the ports you use. Test each SSH change from a second terminal before you log out.

Does Domain India secure my VPS for me?

No. Domain India VPS plans are self-managed. You are responsible for updates, firewall rules, backups and the software you install on the server.

What if I lock myself out of my VPS?

There is no console page for the VPS in the client area, so open a support ticket from the client area or the support page and support will help you regain access.

Ready to harden your server? Work through the full VPS security guide, lock down SSH with the SSH hardening checklist, or compare VPS plans. Questions first? Open a support ticket or use the 24/7 live chat.

Run a server you control

KVM virtualisation, full root access and NVMe storage, with your choice of Linux and an optional control panel.

See VPS plans

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
VPS Security Hardening Checklist (2026) | Domain India