Skip to main content
← Back to news

First Thing on a New VPS: a 5-Step SSH Hardening Checklist

Published 10/8/2026, 04:15:10 · Updated 10/8/2026, 04:15:10

After you get a new VPS, the first thing to do is not install software — it is to harden SSH. These five steps block the vast majority of automated scans and brute-force attempts.

1. Change the password immediately

  • The initial password is on the order details page. Change it right after logging in; a long random password is best.

2. Switch to key-based login

  • Generate a key locally (ssh-keygen) and put the public key into ~/.ssh/authorized_keys on the instance.
  • Once key login works, turn off password login (PasswordAuthentication no).

3. Disable root password login

  • Allowing root to use a key while forbidding root password login is the cheapest protection there is.
  • Alternatively, use a normal account with sudo.

4. Install fail2ban

  • It automatically bans source IPs that repeatedly fail to authenticate.
  • On NAT, fail2ban reads the instance's own logs, so it works the same way.

5. Stay updated, minimise services

  • Patch regularly; expose only the services and ports you actually need.
  • Note: on NAT the public port is assigned by the system, so changing sshd's internal port does not "hide" the service — focus on authentication instead.

Verify

  • Open a second terminal and test key login before closing the old session, so you do not lock yourself out.

Next steps