{"id":6983,"date":"2021-04-19T03:18:00","date_gmt":"2021-04-19T03:18:00","guid":{"rendered":"https:\/\/green.cloud\/docs\/docly-documentation\/content\/secure-your-kvm-vps\/"},"modified":"2026-01-19T00:45:42","modified_gmt":"2026-01-19T00:45:42","slug":"secure-your-kvm-vps","status":"publish","type":"docs","link":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/","title":{"rendered":"How to secure your KVM VPS"},"content":{"rendered":"<p><strong>This guide provides some general tips for securing a Linux-based\u00a0server.<\/strong><\/p>\n<p><iframe title=\"How to secure your KVM VPS (Linux-based server) | VPS Tutorial\" width=\"1170\" height=\"658\" src=\"https:\/\/www.youtube.com\/embed\/_0Cmr5zzBso?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<h3>1. Update your system regularly<\/h3>\n<p>The first thing you should do to secure your server is to update the local repositories, upgrade the operating system, and installed applications by applying the latest patches.<\/p>\n<p>This update will take place in two\u00a0steps:<\/p>\n<ul>\n<li>Updating the package\u00a0list<\/li>\n<\/ul>\n<pre>apt-get update<\/pre>\n<ul>\n<li>Updating the actual\u00a0package<\/li>\n<\/ul>\n<pre>apt-get upgrade<\/pre>\n<h3>2. Changing the default SSH port<\/h3>\n<p>By default,\u00a0<strong>port 22<\/strong> is used to establish an SSH connection. This port is automatically configured during the installation of your operating system, therefore server hacking attempts by robots will target this port. Modifying this setting by using a different port is a simple measure to protect your server against automated attacks<\/p>\n<p>To do this, modify the service configuration\u00a0file:<\/p>\n<pre>vi \/etc\/ssh\/sshd_config<\/pre>\n<p>Find the following or similar lines:<\/p>\n<p><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-22561 size-full\" src=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_54-1.png\" alt=\"\" width=\"645\" height=\"374\" srcset=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_54-1.png 645w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_54-1-300x174.png 300w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_54-1-20x12.png 20w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_54-1-32x19.png 32w\" sizes=\"(max-width: 645px) 100vw, 645px\" \/><\/p>\n<p>Replace\u00a0<strong>port 22<\/strong> with a new port. <strong>Please do not enter a port number already used on your system!<\/strong><\/p>\n<h4>Open the firewall port<\/h4>\n<p>Since each server, you will use a different firewall application. So please choose the corresponding applications below to open the port.<\/p>\n<ul>\n<li>For servers using Firewalld<\/li>\n<\/ul>\n<p>If you use Firewalld open the port and reload with the following command.<\/p>\n<pre>firewall-cmd --permanent --zone=public --add-port=NewPort\r\nfirewall-cmd --reload\/tcp<\/pre>\n<ul>\n<li>For servers using ufw (UIbuntu\/Debian)<\/li>\n<\/ul>\n<p>If you use ufw enter the following command to change the port<\/p>\n<pre>ufw allow NewPort\/tcp<\/pre>\n<ul>\n<li>For servers using iptables<\/li>\n<\/ul>\n<p>With iptables, enter the following commands sequentially to open the port, start and check the opened port.<\/p>\n<pre>iptables -I INPUT -p tcp -m tcp --dport 'NewPort' -j ACCEPT\r\nservice iptables restart\r\niptables -L -n<\/pre>\n<p>Then restart your service.<\/p>\n<pre>systemctl restart sshd<\/pre>\n<p>To establish an SSH connection after this change, enter the following command:<\/p>\n<pre>ssh root@IP_address_of_the_server -p NewPort<\/pre>\n<h3>3. Limit SSH access to specific clients by IP address<\/h3>\n<p>Linux provides two files\u00a0<em>hosts.allow<\/em>\u00a0and\u00a0<em>hosts.deny<\/em> to allow and deny access to SSH port. You simply need to add your trusted IP addresses to hosts.allow file, and add suspicious IP addresses in hosts.deny file.<\/p>\n<ul>\n<li class=\"wp-block-heading\">\n<h5>Allow SSH Access<\/h5>\n<\/li>\n<\/ul>\n<p>Open terminal and run the following command to open hosts.allow file.<\/p>\n<pre class=\"wp-block-preformatted\"># nano \/etc\/hosts.allow<\/pre>\n<p>Add the following line to allow access from ip 192.168.0.96<\/p>\n<pre class=\"wp-block-preformatted\">sshd: 192.168.0.96<\/pre>\n<p>If you want to allow access from multiple IP addresses, add them in a comma-separated manner<\/p>\n<pre class=\"wp-block-preformatted\">sshd: 192.168.0.2, 192.168.0.3, 192.168.0.4<\/pre>\n<p>If you want to allow access from range of IP addresses use the\u00a0CIDR notation to allow an IP address range. Here is an example to allow ip address 192.168.0.0-192.168.0.255 and 192.168.100.0-192.168.100.255<\/p>\n<pre class=\"wp-block-preformatted\">sshd: 192.168.0.0\/24, 192.168.100.0\/24<\/pre>\n<ul>\n<li class=\"wp-block-heading\">\n<h5>Restrict SSH Access<\/h5>\n<\/li>\n<\/ul>\n<p>Similarly, open terminal and run the following command to open hosts.deny file.<\/p>\n<pre># nano \/etc\/hosts.deny<\/pre>\n<p>Add the following line to deny access from ip\u00a0 192.168.0.96<\/p>\n<pre class=\"wp-block-preformatted\">sshd: 192.168.0.96<\/pre>\n<p>If you want to restrict access from multiple IP addresses, add them in a comma-separated manner<\/p>\n<pre class=\"wp-block-preformatted\">sshd: 192.168.0.2, 192.168.0.3, 192.168.0.4<\/pre>\n<p>If you want to restrict access from range of IP addresses use the CIDR notation to allow an IP address range. Here is an example to restrict ip address 192.168.0.0-192.168.0.255 and 192.168.100.0-192.168.100.255<\/p>\n<pre>sshd: 192.168.0.0\/24, 192.168.100.0\/24<\/pre>\n<p>If you want to block all addresses other than the ones mentioned hosts.allow file, then add the following line in host.deny file.<\/p>\n<pre class=\"wp-block-preformatted\">sshd: ALL<\/pre>\n<p>This will protect your website brute force attacks and other malicious methods used by hackers.<\/p>\n<h4>4. Use SSH Key authentication, turn off password authentication<\/h4>\n<p>This configuration is highly recommended for use in securely connecting SSH to the Linux VPS\/Cloud Server system. By default for each VPS\/Cloud Server you will log in with the root username or regular user and the root password that the provider sent you when renting the VPS, however using a password always has 2 big risks:<\/p>\n<ul>\n<li>You will completely lose your VPS\/Cloud Server system if your password is revealed.<\/li>\n<li>Bad guys can use Brute Force attacks to detect passwords.<\/li>\n<\/ul>\n<p>Therefore, we encourage you to become familiar with SSH Key to log in to VPS\/Cloud Server, as well as use it to authenticate connections from outside for more safety. So turn off the password authentication configuration and make sure to enable SSH Key authentication.<\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"dl6blPdVeu\"><p><a href=\"https:\/\/green.cloud\/docs\/how-do-i-add-an-ssh-key-to-my-vps-solusvm\/\">How do I add an SSH key to my VPS? (SolusVM)<\/a><\/p><\/blockquote>\n<p><iframe class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"&#8220;How do I add an SSH key to my VPS? (SolusVM)&#8221; &#8212; GreenCloud Documentation\" src=\"https:\/\/green.cloud\/docs\/how-do-i-add-an-ssh-key-to-my-vps-solusvm\/embed\/#?secret=iqTuDHZwIz#?secret=dl6blPdVeu\" data-secret=\"dl6blPdVeu\" width=\"600\" height=\"338\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<h4>5. Maximum number of incorrect login attempts<\/h4>\n<p>As we often know, password sniffing, also known as Brute Force attack on an SSH service, is quite dangerous if your password is too simple. So we should limit the number of times a user can enter an incorrect password when trying to SSH login to a Linux system. Configure the section below with your desired value. If the specified number of times is exceeded, the SSH Server will disconnect the user.<\/p>\n<p>Open \/etc\/ssh\/sshd_config file and change this line:<\/p>\n<pre>MaxAuthTries 3<\/pre>\n<p>Here we assume a maximum of 3 time incorrect entries are allowed<\/p>\n<h4>6. Install Fail2ban<\/h4>\n<p>Fail2ban is an application that examines server logs looking for repeated or automated attacks.<\/p>\n<p>You can install Fail2ban by typing:<\/p>\n<pre>apt-get install fail2ban<\/pre>\n<p><img decoding=\"async\" class=\"alignnone wp-image-22565 size-full\" src=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57.png\" alt=\"\" width=\"900\" height=\"400\" srcset=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57.png 900w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57-300x133.png 300w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57-768x341.png 768w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57-20x9.png 20w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/04\/Screenshot_57-32x14.png 32w\" sizes=\"(max-width: 900px) 100vw, 900px\" \/><\/p>\n<p>Then copy the included configuration file:<\/p>\n<pre>cp \/etc\/fail2ban\/jail.conf \/etc\/fail2ban\/jail.conf.backup<\/pre>\n<p>And restart Fail2ban:<\/p>\n<pre>systemctl restart fail2ban<\/pre>\n<h4>7. Utilize backups and test them regularly<\/h4>\n<p>Offsite backups are essential for Linux servers. In the event of an intrusion, these can ensure that critical data remains accessible. They are particularly valuable in the event of ransomware attacks.<\/p>\n<p>The application rsync is a popular option for backing up data on Linux. It comes with a host of features that allows you to make daily backups or exclude certain files from being copied. It is extremely versatile, so it serves as a great option for Linux server security strategies. Feel free to use it on a local basis for backing up files.<\/p>\n<p>To install rsync, use the command:<\/p>\n<pre>apt-get install rsync<\/pre>\n<p>Don\u2019t forget to check up on the amount of storage space currently used as well as how much is still available.<\/p>\n<p><a href=\"https:\/\/green.cloud\/9zcf\"><br \/>\n<img decoding=\"async\" src=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/03\/2-2.png\" srcset=\"https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/03\/2-2.png 640w, https:\/\/green.cloud\/docs\/wp-content\/uploads\/2021\/03\/2-2-300x50.png 300w\" alt=\"\" \/> <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This guide provides some general tips for securing a Linux-based\u00a0server. 1. Update your system regularly The first thing you should do to secure your server is to update the local repositories, upgrade the operating system, and installed applications by applying the latest patches. This update will take place in two\u00a0steps: Updating the package\u00a0list apt-get update [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":7012,"parent":33583,"menu_order":2,"comment_status":"open","ping_status":"closed","template":"","doc_tag":[197,187,199],"class_list":["post-6983","docs","type-docs","status-publish","has-post-thumbnail","hentry","doc_tag-kvm","doc_tag-linux","doc_tag-os"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to secure your KVM VPS - GreenCloud Documentation<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to secure your KVM VPS - GreenCloud Documentation\" \/>\n<meta property=\"og:description\" content=\"This guide provides some general tips for securing a Linux-based\u00a0server. 1. Update your system regularly The first thing you should do to secure your server is to update the local repositories, upgrade the operating system, and installed applications by applying the latest patches. This update will take place in two\u00a0steps: Updating the package\u00a0list apt-get update [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/\" \/>\n<meta property=\"og:site_name\" content=\"GreenCloud Documentation\" \/>\n<meta property=\"article:modified_time\" content=\"2026-01-19T00:45:42+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/\",\"url\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/\",\"name\":\"How to secure your KVM VPS - GreenCloud Documentation\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2021-04-19T03:18:00+00:00\",\"dateModified\":\"2026-01-19T00:45:42+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/secure-your-kvm-vps\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"GreenCloud Documents\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/docs\\\/greencloud-documents\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Linux Operating Systems\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/linux-operating-systems\\\/\"},{\"@type\":\"ListItem\",\"position\":4,\"name\":\"Linux Security\",\"item\":\"https:\\\/\\\/green.cloud\\\/docs\\\/greencloud-documents\\\/linux-security\\\/\"},{\"@type\":\"ListItem\",\"position\":5,\"name\":\"How to secure your KVM VPS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/green.cloud\\\/docs\\\/#website\",\"url\":\"https:\\\/\\\/green.cloud\\\/docs\\\/\",\"name\":\"GreenCloud Documentation\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/green.cloud\\\/docs\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to secure your KVM VPS - GreenCloud Documentation","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/","og_locale":"en_US","og_type":"article","og_title":"How to secure your KVM VPS - GreenCloud Documentation","og_description":"This guide provides some general tips for securing a Linux-based\u00a0server. 1. Update your system regularly The first thing you should do to secure your server is to update the local repositories, upgrade the operating system, and installed applications by applying the latest patches. This update will take place in two\u00a0steps: Updating the package\u00a0list apt-get update [&hellip;]","og_url":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/","og_site_name":"GreenCloud Documentation","article_modified_time":"2026-01-19T00:45:42+00:00","twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/","url":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/","name":"How to secure your KVM VPS - GreenCloud Documentation","isPartOf":{"@id":"https:\/\/green.cloud\/docs\/#website"},"primaryImageOfPage":{"@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/#primaryimage"},"image":{"@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/#primaryimage"},"thumbnailUrl":"","datePublished":"2021-04-19T03:18:00+00:00","dateModified":"2026-01-19T00:45:42+00:00","breadcrumb":{"@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/green.cloud\/docs\/secure-your-kvm-vps\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/green.cloud\/docs\/"},{"@type":"ListItem","position":2,"name":"GreenCloud Documents","item":"https:\/\/green.cloud\/docs\/docs\/greencloud-documents\/"},{"@type":"ListItem","position":3,"name":"Linux Operating Systems","item":"https:\/\/green.cloud\/docs\/linux-operating-systems\/"},{"@type":"ListItem","position":4,"name":"Linux Security","item":"https:\/\/green.cloud\/docs\/greencloud-documents\/linux-security\/"},{"@type":"ListItem","position":5,"name":"How to secure your KVM VPS"}]},{"@type":"WebSite","@id":"https:\/\/green.cloud\/docs\/#website","url":"https:\/\/green.cloud\/docs\/","name":"GreenCloud Documentation","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/green.cloud\/docs\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/6983","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/comments?post=6983"}],"version-history":[{"count":9,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/6983\/revisions"}],"predecessor-version":[{"id":23249,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/6983\/revisions\/23249"}],"up":[{"embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/docs\/33583"}],"wp:attachment":[{"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/media?parent=6983"}],"wp:term":[{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/green.cloud\/docs\/wp-json\/wp\/v2\/doc_tag?post=6983"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}