Skip to content
Back to Blog
Security10 min read

Server Security Best Practices: Essential Beginner's Checklist

A practical starter guide for developers and sysadmins new to server security. Learn the fundamental steps to secure your Linux server from day one, with clear definitions and working examples.

Written by Abdul AbrorTechnical Hosting Support Engineer
Server Security Best Practices: Essential Beginner's Checklist
On this page

Securing a server can feel overwhelming when you're just starting out. You've provisioned your first VPS or dedicated server, logged in as root, and now you're staring at a command prompt wondering where to begin. The good news is that a handful of fundamental practices will dramatically improve your security posture, even if you've never administered a server before.

This guide walks you through an essential security checklist designed specifically for beginners. We'll define every term, explain why each step matters, and provide the exact commands you need to implement a working baseline security setup on a Linux server.

Understanding Server Security Fundamentals

Before diving into configuration, let's establish what we mean by server security and why it matters.

What Is a Server and Why Does It Need Security?

A server is a computer that provides services to other computers over a network. When you host a website, application, or email system, that server is directly connected to the internet and exposed to potential attackers scanning for vulnerabilities.

Server security is the practice of protecting your server from unauthorized access, data breaches, malware, and service disruptions. Without proper security measures, attackers can compromise your server within hours of it going online.

The Attack Surface

Your attack surface is the sum of all points where an unauthorized user could try to enter or extract data from your system. A fresh server typically exposes several potential entry points: SSH access, open network ports, default accounts, and outdated software packages. Our checklist systematically reduces this attack surface.

Essential Security Checklist for Beginners

Step 1: Secure SSH Access

SSH (Secure Shell) is the protocol you use to remotely access and manage your Linux server. It's also the primary target for automated attacks. Hardening SSH is your first and most critical security task.

Change the Default SSH Port

By default, SSH listens on port 22. Automated bots constantly scan this port looking for servers to attack. While changing the port isn't true security through obscurity alone, it dramatically reduces noise and failed login attempts in your logs.

Edit the SSH configuration file:

sudo nano /etc/ssh/sshd_config

Find the line that says #Port 22 and change it:

Port 2849

Choose any port between 1024 and 65535 that isn't already in use. Remember this number; you'll need it to connect.

Disable Root Login

The root user has complete system access with no restrictions. Allowing direct root login means attackers only need to guess one username. Instead, create a regular user account and use sudo for administrative tasks.

First, create a new user (replace youruser with your chosen username):

adduser youruser

Grant this user sudo privileges:

usermod -aG sudo youruser

Now disable root login by editing the SSH config:

sudo nano /etc/ssh/sshd_config

Find and change this line:

PermitRootLogin no

Use SSH Key Authentication

SSH keys provide cryptographic authentication that's far stronger than passwords. An SSH key pair consists of a private key (kept secret on your local machine) and a public key (placed on the server).

On your local machine, generate a key pair:

ssh-keygen -t ed25519 -C "[email protected]"

Press Enter to accept the default location, then set a strong passphrase. This creates two files: id_ed25519 (private) and id_ed25519.pub (public).

Copy the public key to your server:

ssh-copy-id -i ~/.ssh/id_ed25519.pub youruser@your_server_ip

Once key authentication works, disable password authentication entirely:

sudo nano /etc/ssh/sshd_config

Change this line:

PasswordAuthentication no

Restart SSH to apply all changes:

sudo systemctl restart sshd

Important: Test your new SSH configuration in a separate terminal window before closing your current session. If something is misconfigured, you'll still have access to fix it.

Step 2: Configure a Firewall

A firewall controls which network traffic is allowed to reach your server. Think of it as a bouncer that only lets in guests on the list.

Understanding UFW

UFW (Uncomplicated Firewall) is a beginner-friendly interface for managing firewall rules on Ubuntu and Debian-based systems. It's already installed on most distributions.

First, allow SSH before enabling the firewall (use your custom port if you changed it):

sudo ufw allow 2849/tcp

If you're running a web server, allow HTTP and HTTPS:

sudo ufw allow 80/tcp
sudo ufw allow 443/tcp

Now enable the firewall:

sudo ufw enable

Check your firewall status:

sudo ufw status verbose

The default UFW policy denies all incoming connections except those you explicitly allow, which is exactly what you want. Outgoing connections are allowed by default so your server can access the internet.

For CentOS/RHEL: Using firewalld

If you're using CentOS, Rocky Linux, or AlmaLinux, you'll use firewalld instead:

sudo firewall-cmd --permanent --add-service=ssh
sudo firewall-cmd --permanent --add-service=http
sudo firewall-cmd --permanent --add-service=https
sudo firewall-cmd --reload

Step 3: Keep Your System Updated

Software vulnerabilities are discovered constantly. Security updates patch these vulnerabilities before attackers can exploit them. An outdated server is an insecure server.

For Ubuntu/Debian Systems

Update the package list and install available updates:

sudo apt update
sudo apt upgrade -y

Enable automatic security updates:

sudo apt install unattended-upgrades
sudo dpkg-reconfigure -plow unattended-upgrades

This ensures critical security patches are applied automatically without waiting for manual intervention.

For CentOS/RHEL Systems

sudo yum update -y

Enable automatic updates:

sudo yum install yum-cron
sudo systemctl enable yum-cron
sudo systemctl start yum-cron

Schedule regular update checks weekly at minimum, even with automatic updates enabled.

Step 4: Install and Configure Fail2Ban

Fail2Ban monitors log files for repeated failed login attempts and automatically blocks the offending IP addresses by adding temporary firewall rules.

Install Fail2Ban:

sudo apt install fail2ban

Create a local configuration file:

sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
sudo nano /etc/fail2ban/jail.local

Find the [sshd] section and ensure it's enabled:

[sshd]
enabled = true
port = 2849
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600

Restart Fail2Ban:

sudo systemctl restart fail2ban

Check which IP addresses are currently banned:

sudo fail2ban-client status sshd

Fail2Ban significantly reduces the impact of brute-force attacks by automatically responding faster than any human could.

Step 5: Disable Unnecessary Services

Every running service is a potential attack vector. The principle of least privilege means only running what you actually need.

List all running services:

sudo systemctl list-units --type=service --state=running

For each service you don't recognize or need, research what it does before disabling. Common candidates for removal on a web server include Bluetooth services, printing services, and desktop environment components.

To disable a service:

sudo systemctl stop service-name
sudo systemctl disable service-name

Be conservative here. When in doubt, leave a service running until you understand its purpose.

Step 6: Set Up Basic Monitoring

You can't protect what you can't see. Basic monitoring helps you detect unusual activity and system issues before they become critical.

Monitor Login Attempts

Regularly review authentication logs:

sudo grep 'Failed password' /var/log/auth.log | tail -20

This shows recent failed login attempts. With Fail2Ban running, you should see these attempts drop dramatically.

Monitor Disk Usage

Full disks can cause service outages and prevent security updates:

df -h

This shows available disk space on all mounted filesystems. Keep at least 10-15% free space on your root partition.

Check for Listening Ports

Verify which services are listening on which ports:

sudo ss -tlnp

Every open port should correspond to a service you intentionally configured. Unexpected listening ports may indicate a compromise or misconfiguration.

Step 7: Configure a Local Backup Strategy

Security isn't just about preventing attacks; it's also about recovery. Regular backups ensure you can restore your server if something goes wrong.

For a simple automated backup solution, create a backup script:

#!/bin/bash
BACKUP_DIR="/var/backups"
DATE=$(date +%Y%m%d)

tar -czf $BACKUP_DIR/etc-backup-$DATE.tar.gz /etc
tar -czf $BACKUP_DIR/home-backup-$DATE.tar.gz /home

find $BACKUP_DIR -name "*-backup-*.tar.gz" -mtime +7 -delete

Save this as /usr/local/bin/backup.sh, make it executable, and schedule it with cron:

sudo chmod +x /usr/local/bin/backup.sh
sudo crontab -e

Add this line to run backups daily at 2 AM:

0 2 * * * /usr/local/bin/backup.sh

Store critical backups off-server using rsync, scp, or your hosting provider's backup service.

Common Mistakes to Avoid

As you implement these security measures, watch out for these common pitfalls:

Locking yourself out: Always test SSH configuration changes in a second terminal window before closing your current session. Keep your hosting provider's console access information handy as a backup.

Over-blocking the firewall: If you add a new service later, remember to open its port in the firewall. A properly configured service that's blocked by the firewall looks identical to a broken service.

Ignoring updates: Security is not a one-time setup. Schedule weekly time to review updates, logs, and monitoring alerts.

Using weak sudo passwords: Your regular user account can become root with sudo, so its password must be strong and unique.

Conclusion

Server security is a continuous practice, not a destination. The checklist you've just implemented establishes a solid security baseline that protects against the vast majority of automated attacks and common vulnerabilities. You've secured SSH access with keys and custom ports, configured a firewall to control network traffic, enabled automatic updates to patch vulnerabilities, deployed Fail2Ban to block brute-force attempts, and set up basic monitoring to detect issues early.

As you gain experience, you'll add more sophisticated measures like intrusion detection systems, security auditing tools, and advanced monitoring solutions. But these fundamentals remain the foundation of every secure server. Review and refine your security configuration regularly, stay informed about new threats in your hosting environment, and remember that the most secure system is one that's actively maintained. Your server is now significantly more secure than when you started, and you've built the knowledge to keep it that way.

FAQ

Do I really need to change the SSH port?

Changing the SSH port isn't a substitute for strong authentication, but it does reduce log noise and automated attack attempts. It's a worthwhile step that takes minutes to implement.

Can I use the same SSH key for multiple servers?

Technically yes, but it's better practice to generate unique keys for each server or at least each trust boundary. If one server is compromised, your other servers remain protected.

How often should I check my server logs?

Weekly manual reviews are a good baseline for beginners. As you become more comfortable, set up automated log analysis tools that alert you to specific events.

What if I forget my SSH key passphrase?

Without the passphrase, your private key is unusable. This is by design for security. You'll need to use your hosting provider's console access to add a new public key to your server.

Should I install antivirus on my Linux server?

Linux servers rarely need traditional antivirus software. Focus on the security fundamentals in this checklist instead. For malware scanning of user uploads or email, consider ClamAV.