What is the best way to secure a new Linux server?

Updated October 2026 · How we answer

Short answerThere is no single best way, but a strong baseline includes: update the system, create a non-root user with sudo, disable password SSH logins, set up a firewall, and enable automatic security updates.

Initial hardening steps

Start by updating all packages. Then create a regular user account with sudo privileges and disable direct root SSH login. Edit `/etc/ssh/sshd_config` to set `PermitRootLogin no` and `PasswordAuthentication no`, then restart SSH. Use SSH keys instead of passwords.

Configure a host firewall. On Ubuntu, `ufw` is common: allow OpenSSH, then enable it. On RHEL-based systems, use `firewalld`. Only open ports you actually need, such as 22 (SSH), 80 (HTTP), and 443 (HTTPS).

  • Update all packages
  • Create a non-root sudo user
  • Disable root SSH login and password authentication
  • Set up a firewall (ufw or firewalld)
  • Enable automatic security updates
  • Install fail2ban to block brute-force attempts

Ongoing maintenance

Security is not a one-time task. Regularly apply updates, monitor logs for suspicious activity, and remove unused services. Tools like `fail2ban` can automatically ban IPs after repeated failed logins.

For production servers, consider additional layers: SELinux or AppArmor, intrusion detection (e.g., AIDE), and centralized logging. The right level depends on your threat model and compliance needs.

Common mistakes

  • Leaving password authentication enabled for SSH, which invites brute-force attacks.
  • Opening all firewall ports or disabling the firewall entirely for convenience.
  • Forgetting to test SSH key login before disabling password authentication, locking yourself out.
From our shopsTitan Case: Premium MagSafe iPhone cases with a precision fit.