Lazo Lab Sign up

Guides

Secure your own server

Intermediate 路 9 min read

Updates, SSH keys, a firewall and fail2ban: the four things every home server needs.

1. Keep it updated

Most break-ins use flaws that already have fixes. Turn on automatic security updates and you've beaten a big chunk of attacks.

sudo apt update && sudo apt upgrade -y
sudo apt install unattended-upgrades
sudo dpkg-reconfigure unattended-upgrades

2. Log in with keys, not passwords

Run these on your own computer, not the server. Then check you can log in without a password before turning passwords off.

ssh-keygen -t ed25519
ssh-copy-id user@your-server-ip

# On the server, in /etc/ssh/sshd_config set:
# PasswordAuthentication no
sudo systemctl restart ssh

3. Turn on the firewall

Allow SSH first, or you'll lock yourself out. Then allow only the services you actually run.

sudo ufw allow OpenSSH
sudo ufw allow 80/tcp
sudo ufw enable
sudo ufw status

4. Ban repeat offenders

fail2ban watches login logs and temporarily blocks IPs that keep failing. It works out of the box for SSH.

sudo apt install fail2ban
sudo fail2ban-client status sshd

Bonus: watch your logs

Check your logs every few days. Thousands of hits from one IP usually means a bot. A login at 3am from another country means you need to act.