---
title: "How to secure SSH on a Linux VPS: keys, passwords, fail2ban | StreetHosting"
description: "SSH hardening for a public server: ED25519 keys, PermitRootLogin, PasswordAuthentication, AllowUsers, fail2ban and how it fits with a UFW firewall."
url: "https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps"
type: "page"
language: "en-US"
---

VPS · 4 min · Intermediate

Published on May 19, 2026 · Updated on May 20, 2026

# How to secure SSH on a Linux VPS

SSH is usually the first target on any VPS with a public IP. This guide walks through a practical routine that cuts the risk without complicating your day: an ED25519 key, password-free login, admin access through sudo, blocking of automated attempts and a periodic review of authorized keys.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Security and hardening](https://streethosting.com.br/en/guides/topics/security) [Linux administration](https://streethosting.com.br/en/guides/topics/linux)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=How%20to%20secure%20SSH%20on%20a%20Linux%20VPS%3A%20keys%2C%20passwords%2C%20fail2ban&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps "Share on LinkedIn") [](https://wa.me/?text=How%20to%20secure%20SSH%20on%20a%20Linux%20VPS%3A%20keys%2C%20passwords%2C%20fail2ban%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Fvps%2Fsecure-ssh-linux-vps "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps.md)

[Previous How to install Docker on Ubuntu 22.04 or 24.04 on a VPS (straight to the point)](https://streethosting.com.br/en/guides/vps/install-docker-ubuntu-vps) [Next UFW on Ubuntu VPS: firewall rules without losing SSH](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps)

In this guide 5 sections

* [A realistic threat model](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#modelo-de-ameaca-realista)
* [ED25519 keys and agent forwarding](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#chaves-ed25519-e-agent-forwarding)
* [A healthy minimal sshd\_config](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#sshd-config-minimo-saudavel)
* [fail2ban and rate limiting](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#fail2ban-e-rate-limit)
* [Ongoing operation and auditing](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#operacao-e-auditoria)

Quick answer

To harden SSH on a Linux VPS, the safest path is to generate an **ED25519** key, confirm key login in a second session, turn off remote passwords in `sshd_config`, forbid direct root login, allow only the users you need and add **fail2ban** alongside a consistent firewall. Follow these steps in order so you do not lock yourself out of the server.

## A realistic threat model[](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#modelo-de-ameaca-realista)

A new VPS typically starts receiving automated login attempts within minutes of exposing its IP. Most of these attacks use lists of leaked usernames and passwords. The goal is not a configuration that is perfect in theory, but one that removes the vectors that show up most often in production.

### What usually happens in practice

* Bots keep trying common combinations such as root, admin and ubuntu around the clock.
* Old keys stay in `authorized_keys` after the team changes.
* A service with excessive permissions makes lateral movement easier after a break-in.

## ED25519 keys and agent forwarding[](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#chaves-ed25519-e-agent-forwarding)

Create one key per person and per device. That makes auditing and revocation easier when someone leaves the team or loses a laptop. In a small setup, this organization alone prevents a good share of operational incidents.

1. Generate the key with a strong passphrase on the device you use every day.
2. Copy only the public key to the server and check the permissions on the `.ssh` directory.
3. Test the login in a parallel session before changing any policy.

Agent forwarding should be the exception. For hops between hosts, prefer ProxyJump when possible, since it is more predictable in an audit.

## A healthy minimal sshd\_config[](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#sshd-config-minimo-saudavel)

| Directive              | Suggested value         | Reason                             |
| ---------------------- | ----------------------- | ---------------------------------- |
| PasswordAuthentication | no                      | Eliminates remote password attacks |
| PermitRootLogin        | no or prohibit-password | Administration through sudo        |
| PubkeyAuthentication   | yes                     | Main authentication method         |
| AllowUsers             | explicit list           | Reduces unnecessary exposure       |

Back up the file before editing, validate it with `sshd -t` and only restart the service after you confirm the syntax is correct. On a VPS, this simple check keeps a typo from locking you out.

Never close your current session before opening a new SSH connection and confirming that it works with the newly applied rules.

## fail2ban and rate limiting[](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#fail2ban-e-rate-limit)

fail2ban watches for repeated failures and blocks IPs for a set period. It does not replace key authentication, but it greatly reduces the volume of automated attempts in your logs and the alert noise.

Set the parameters to match your situation. A team with a fixed IP can use more aggressive bans. A remote team on changing networks needs a more conservative setup to avoid blocking legitimate access.

Pair it with [UFW](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) rules that match your real SSH port, and also review the Docker integration when you have published containers.

## Ongoing operation and auditing[](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#operacao-e-auditoria)

SSH security is not a one-time task. Review `authorized_keys` every quarter, remove keys without a clear owner and document who has administrative access. This routine lowers the risk without adding complexity.

To keep hardening your VPS, read the guide on [installing Docker on Ubuntu](https://streethosting.com.br/en/guides/vps/install-docker-ubuntu-vps). To choose your hardware, also compare [Ryzen VPS vs Xeon VPS](https://streethosting.com.br/en/guides/vps/ryzen-vs-xeon-vps). Larger workloads may call for a [dedicated server](https://streethosting.com.br/en/dedicated).

* Private backup of sshd\_config before any change.
* Up to date list of authorized users in AllowUsers.
* Recovery console tested for emergencies.
* Security updates applied on a recurring schedule.

In this guide

* [A realistic threat model](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#modelo-de-ameaca-realista)
* [ED25519 keys and agent forwarding](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#chaves-ed25519-e-agent-forwarding)
* [A healthy minimal sshd\_config](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#sshd-config-minimo-saudavel)
* [fail2ban and rate limiting](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#fail2ban-e-rate-limit)
* [Ongoing operation and auditing](https://streethosting.com.br/en/guides/vps/secure-ssh-linux-vps#operacao-e-auditoria)

## Frequently asked questions

Does changing the SSH port help?

It cuts down the noise from simple bots, but it does not solve the main problem. Real security comes from a strong key, remote password login turned off and a list of allowed users.

Can I keep a password for emergencies?

The safest route is the provider's recovery console and a clear key policy. If a password is required for some reason, restrict access to a VPN or a specific IP range.

Can fail2ban block a legitimate IP?

Yes, behind a shared corporate NAT. Tune findtime and maxretry, and whitelist your team's stable IPs.

Is there 2FA for SSH?

There is, usually through PAM modules or a bastion host with MFA. It is well worth it for larger teams or environments with sensitive data, but it needs a better defined support process.

Next step

See Ryzen VPS

Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.

[See Ryzen VPS](https://streethosting.com.br/en/vps/ryzen)

[See dedicated servers Exclusive hardware in São Paulo with NVMe and Anti-DDoS.](https://streethosting.com.br/en/dedicated)

## Related guides

[VPS Beginner UFW on Ubuntu VPS: firewall rules without losing SSH UFW makes the Ubuntu firewall simpler, but one rule in the wrong order locks you out of your VPS. Learn how to enable it without losing SSH, open only what you need, deal with Docker, and get back in through the console if something goes wrong. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ufw-firewall-ubuntu-vps) [VPS Intermediate How to install Docker on Ubuntu 22.04 or 24.04 on a VPS (straight to the point) A stable Docker install on an Ubuntu VPS depends on the right package source and step by step validation. In this guide you set up the official repository, install Engine and Compose, test the daemon and apply basic security measures before deploying applications. 3 min Read guide](https://streethosting.com.br/en/guides/vps/install-docker-ubuntu-vps) [VPS Beginner Ryzen VPS vs Xeon VPS: which CPU to choose for your server Choosing between a Ryzen VPS and a Xeon VPS comes down to the workload, not the brand on its own. This guide compares the actual processors behind the two lines on clock speed, per-core performance, stability and ECC memory, with practical scenarios and the price of every plan. 10 min Read guide](https://streethosting.com.br/en/guides/vps/ryzen-vs-xeon-vps)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
