First Thing on a New VPS: a 5-Step SSH Hardening Checklist
Published 10/8/2026, 04:15:10 · Updated 10/8/2026, 04:15:10
After you get a new VPS, the first thing to do is not install software — it is to harden SSH. These five steps block the vast majority of automated scans and brute-force attempts.
1. Change the password immediately
- The initial password is on the order details page. Change it right after logging in; a long random password is best.
2. Switch to key-based login
- Generate a key locally (ssh-keygen) and put the public key into ~/.ssh/authorized_keys on the instance.
- Once key login works, turn off password login (PasswordAuthentication no).
3. Disable root password login
- Allowing root to use a key while forbidding root password login is the cheapest protection there is.
- Alternatively, use a normal account with sudo.
4. Install fail2ban
- It automatically bans source IPs that repeatedly fail to authenticate.
- On NAT, fail2ban reads the instance's own logs, so it works the same way.
5. Stay updated, minimise services
- Patch regularly; expose only the services and ports you actually need.
- Note: on NAT the public port is assigned by the system, so changing sshd's internal port does not "hide" the service — focus on authentication instead.
Verify
- Open a second terminal and test key login before closing the old session, so you do not lock yourself out.
Next steps
- More troubleshooting in the Help Center
- Other questions in the FAQ
