Complete Guide to VPS Server Setup for Privacy
Setting up a VPS for maximum privacy requires careful configuration from the moment you first connect. This comprehensive guide walks you through hardening your server while maintaining usability.
Initial Server Access
When you first deploy your VPS through SERVERZ, you'll receive SSH credentials to access your server. The first step is securing this access.
## 1. Create a Non-Root User
First, create a dedicated user account (as root):
adduser serverzuser
usermod -aG sudo serverzuser
## 2. Set Up SSH Key Authentication
On your local machine, generate an SSH key pair if you don't have one:
ssh-keygen -t ed25519 -C "[email protected]"
Copy your public key to the server:
ssh-copy-id -p 22 serverzuser@your-server-ip
Test key authentication:
ssh -p 22 serverzuser@your-server-ip
## 3. Configure SSH Security
Once logged in with your key, edit the SSH configuration:
sudo nano /etc/ssh/sshd_config
Apply these security settings:
Port 2847
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
## 4. Open Firewall for New SSH Port FIRST
Before restarting SSH, configure the firewall:
sudo ufw allow 2847/tcp # New SSH port
sudo ufw allow 22/tcp # Keep old port temporarily
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable
## 5. Apply SSH Changes
Restart SSH service:
sudo systemctl restart sshd
Test new connection in a NEW terminal (keep current session open):
ssh -p 2847 serverzuser@your-server-ip
Once confirmed working, remove old SSH port from firewall:
sudo ufw delete allow 22/tcp
Operating System Updates
Keep your system current with security patches:
## Ubuntu/Debian:
sudo apt update && sudo apt upgrade -y
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades
Enable automatic security updates by selecting "Yes" when prompted.
## CentOS/RHEL:
sudo yum update -y
sudo yum install yum-cron
sudo systemctl enable --now yum-cron
Network Security
## Kernel Network Parameters
Edit/etc/sysctl.conf to add security parameters:
sudo nano /etc/sysctl.conf
Add these lines:
# Disable IPv6 (if not needed)
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1
# TCP SYN Cookie Protection
net.ipv4.tcp_syncookies = 1
# IP Spoofing Protection
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
# Ignore ICMP Redirects
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
# Disable Source Packet Routing
net.ipv4.conf.all.accept_source_route = 0
net.ipv6.conf.all.accept_source_route = 0
Apply the changes immediately:
sudo sysctl -p
Monitoring and Logging
Set up basic monitoring to detect suspicious activity:
## Install and configure fail2ban:
sudo apt install fail2ban
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
Edit /etc/fail2ban/jail.local:
sudo nano /etc/fail2ban/jail.local
Find and update the [sshd] section:
[sshd]
enabled = true
port = 2847 # Your custom SSH port
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600
findtime = 600
Start and enable fail2ban:
sudo systemctl restart fail2ban
sudo systemctl enable fail2ban
Check fail2ban status:
sudo fail2ban-client status
sudo fail2ban-client status sshd
Privacy Considerations
## DNS Configuration
Configure persistent privacy-focused DNS servers.# For Ubuntu 18.04+ with systemd-resolved:
sudo nano /etc/systemd/resolved.conf
Update the configuration:
[Resolve]
DNS=1.1.1.1 1.0.0.1
FallbackDNS=9.9.9.9 149.112.112.112
DNSOverTLS=yes
Restart the service:
sudo systemctl restart systemd-resolved
sudo systemctl status systemd-resolved
# For older systems or without systemd-resolved:
sudo apt install resolvconf
echo "nameserver 1.1.1.1" | sudo tee -a /etc/resolvconf/resolv.conf.d/head
echo "nameserver 1.0.0.1" | sudo tee -a /etc/resolvconf/resolv.conf.d/head
sudo resolvconf -u
## NTP Security
Configure secure time synchronization:sudo apt install chrony
sudo systemctl enable chrony
Web Server Setup (Optional)
If you're hosting web content, configure nginx with security headers:
sudo apt install nginx
Add security headers to /etc/nginx/sites-available/default:
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;
Final Security Checks
## 1. Verify Open Ports
sudo netstat -tulpn | grep LISTEN
## 2. Check Running Services
sudo systemctl list-units --type=service --state=running
## 3. Review User Accounts
cat /etc/passwd
Backup Strategy
Set up automated backups of critical data:
## Create backup directory and script:
sudo mkdir -p /backup
sudo nano /usr/local/bin/backup.sh
Add this backup script:
#!/bin/bash
# Automated backup script with rotation
# Variables
BACKUP_DIR="/backup"
DATE=$(date +%Y%m%d_%H%M%S)
BACKUP_FILE="$BACKUP_DIR/server_backup_$DATE.tar.gz"
RETENTION_DAYS=7
# Create backup
tar -czf "$BACKUP_FILE" \
--exclude='/home/*/.cache' \
--exclude='/home/*/.local/share/Trash' \
/home /etc /var/log 2>/dev/null
# Remove old backups
find "$BACKUP_DIR" -name "server_backup_*.tar.gz" -mtime +$RETENTION_DAYS -delete
# Log backup status
if [ $? -eq 0 ]; then
echo "$(date): Backup successful - $BACKUP_FILE" >> /var/log/backup.log
else
echo "$(date): Backup failed" >> /var/log/backup.log
fi
Make it executable and set up cron:
sudo chmod +x /usr/local/bin/backup.sh
sudo crontab -e
Add this line for daily backups at 2 AM:
0 2 * * * /usr/local/bin/backup.sh
Test the backup script:
sudo /usr/local/bin/backup.sh
ls -lh /backup/
Additional Security Hardening
## Install and Configure auditd
Monitor system calls and track security events:sudo apt install auditd
sudo systemctl enable auditd
sudo auditctl -e 1
## Secure Shared Memory
Prevent execution from /tmp:sudo nano /etc/fstab
Add this line:
tmpfs /run/shm tmpfs defaults,noexec,nosuid 0 0
## Configure Log Rotation
Ensure logs don't fill up disk space:sudo nano /etc/logrotate.d/rsyslog
Verify these settings:
/var/log/syslog
/var/log/auth.log
{
rotate 4
weekly
missingok
notifempty
compress
delaycompress
postrotate
/usr/lib/rsyslog/rsyslog-rotate
endscript
}
Conclusion
Following these steps provides a solid foundation for a privacy-focused VPS. This guide emphasizes:
- Defense in depth: Multiple layers of security
- Principle of least privilege: Minimal access rights
- Security through obscurity: Non-standard ports and configurations
- Continuous monitoring: Active threat detection
## Quick Security Checklist
- [ ] SSH key authentication configured
- [ ] Password authentication disabled
- [ ] Non-standard SSH port configured
- [ ] Firewall enabled with minimal open ports
- [ ] fail2ban monitoring SSH attempts
- [ ] Automatic security updates enabled
- [ ] Regular backups scheduled
- [ ] System logs being monitored