Secure your own server
Intermediate 路 9 min read
Updates, SSH keys, a firewall and fail2ban: the four things every home server needs.
1. Keep it updated
Most break-ins use flaws that already have fixes. Turn on automatic security updates and you've beaten a big chunk of attacks.
sudo apt update && sudo apt upgrade -y
sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrades2. Log in with keys, not passwords
Run these on your own computer, not the server. Then check you can log in without a password before turning passwords off.
ssh-keygen -t ed25519
ssh-copy-id user@your-server-ip
# On the server, in /etc/ssh/sshd_config set:
# PasswordAuthentication no
sudo systemctl restart ssh3. Turn on the firewall
Allow SSH first, or you'll lock yourself out. Then allow only the services you actually run.
sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw enable
sudo ufw status4. Ban repeat offenders
fail2ban watches login logs and temporarily blocks IPs that keep failing. It works out of the box for SSH.
sudo apt install fail2ban
sudo fail2ban-client status sshdBonus: watch your logs
Check your logs every few days. Thousands of hits from one IP usually means a bot. A login at 3am from another country means you need to act.