In the following article, we will look at the basic steps to achieve security on a Linux server. Although it focuses mostly on Debian and Ubuntu, it is worth checking out because it can be applied to other Linux distributions as well.

- Update your server.
First, you need to update your local repositories, upgrade your operating system and installed applications, applying the latest patches.
- Create a new privileged user account.
Next, create a new account . You should never log in to your server as root. Instead, create your own account (“
- Upload the SSH key.
You will need to use an SSH key to connect to your new server. You can upload the pre-generated SSH key to your new server using the ssh-copy-id command:
$ ssh-copy-id<username> @ip_address
This way you can connect to your new server without requiring a password.
- Secure SSH.
- Disable SSH password authentication
- Restrict remote root login.
- Restrict access to IPv4 or IPv6.
- Turn on a firewall.
Now you need to install a firewall, enable it, and configure it to only allow the network traffic you specify. Uncomplicated Firewall (UFW) is an easy-to-use interface to iptables that greatly simplifies the process of configuring a firewall.
You can install UFW with:
$ sudo apt install ufw
By default, UFW denies all incoming connections and allows all outgoing connections. This means that any application on your server can reach the internet, but anything trying to reach your server cannot connect.

- Install Fail2ban.
Fail2ban is an application that examines server logs looking for repeated or automated attacks. If an attack is found, it will turn the firewall on to block the attacker's IP address, either permanently or for a specified period of time.
- Removal of unused services to the network.
Almost all Linux server operating systems come with a few network services enabled. You usually want to keep most of them on. However, there are a few you might want to remove.
How to remove an unused service (“<service_name> ”) will vary depending on your operating system and the package manager used.
To remove an unused service in Debian/Ubuntu:
$ sudo apt purge<service_name>
To remove an unused service on Red Hat/CentOS:
$ sudo yum remove<service_name>
The above are the minimum actions that will strengthen a Linux server. Additional security should be implemented depending on the way each server operates.
