ZERVERZ
Start
tutorial

Complete Guide to VPS Server Setup for Privacy

Learn how to configure your new VPS server with security-first practices, from initial SSH hardening to firewall configuration.

SERVERZ Team
Author
Aug 01, 2025
Published
12 min
Read Time
#VPS Setup#Privacy#SSH Security#Linux Administration

Complete Guide to VPS Server Setup for Privacy

Setting up a VPS for maximum privacy requires careful configuration from the moment you first connect. This comprehensive guide walks you through hardening your server while maintaining usability.

Initial Server Access

When you first deploy your VPS through SERVERZ, you'll receive SSH credentials to access your server. The first step is securing this access.

## 1. Create a Non-Root User

First, create a dedicated user account (as root):

TERMINAL
adduser serverzuser
usermod -aG sudo serverzuser

## 2. Set Up SSH Key Authentication

On your local machine, generate an SSH key pair if you don't have one:

TERMINAL
ssh-keygen -t ed25519 -C "[email protected]"

Copy your public key to the server:

TERMINAL
ssh-copy-id -p 22 serverzuser@your-server-ip

Test key authentication:

TERMINAL
ssh -p 22 serverzuser@your-server-ip

## 3. Configure SSH Security

Once logged in with your key, edit the SSH configuration:

TERMINAL
sudo nano /etc/ssh/sshd_config

Apply these security settings:

CONFIG
Port 2847
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2

## 4. Open Firewall for New SSH Port FIRST

Before restarting SSH, configure the firewall:

TERMINAL
sudo ufw allow 2847/tcp  # New SSH port
sudo ufw allow 22/tcp    # Keep old port temporarily
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable

## 5. Apply SSH Changes

Restart SSH service:

TERMINAL
sudo systemctl restart sshd

Test new connection in a NEW terminal (keep current session open):

TERMINAL
ssh -p 2847 serverzuser@your-server-ip

Once confirmed working, remove old SSH port from firewall:

TERMINAL
sudo ufw delete allow 22/tcp

Operating System Updates

Keep your system current with security patches:

## Ubuntu/Debian:

TERMINAL
sudo apt update && sudo apt upgrade -y
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgrades

Enable automatic security updates by selecting "Yes" when prompted.

## CentOS/RHEL:

TERMINAL
sudo yum update -y
sudo yum install yum-cron
sudo systemctl enable --now yum-cron

Network Security

## Kernel Network Parameters

Edit /etc/sysctl.conf to add security parameters:
TERMINAL
sudo nano /etc/sysctl.conf

Add these lines:

INI
# Disable IPv6 (if not needed)
net.ipv6.conf.all.disable_ipv6 = 1
net.ipv6.conf.default.disable_ipv6 = 1

# TCP SYN Cookie Protection
net.ipv4.tcp_syncookies = 1

# IP Spoofing Protection
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1

# Ignore ICMP Redirects
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0

# Disable Source Packet Routing
net.ipv4.conf.all.accept_source_route = 0
net.ipv6.conf.all.accept_source_route = 0

Apply the changes immediately:

TERMINAL
sudo sysctl -p

Monitoring and Logging

Set up basic monitoring to detect suspicious activity:

## Install and configure fail2ban:

TERMINAL
sudo apt install fail2ban
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local

Edit /etc/fail2ban/jail.local:

TERMINAL
sudo nano /etc/fail2ban/jail.local

Find and update the [sshd] section:

INI
[sshd]
enabled = true
port = 2847  # Your custom SSH port
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600
findtime = 600

Start and enable fail2ban:

TERMINAL
sudo systemctl restart fail2ban
sudo systemctl enable fail2ban

Check fail2ban status:

TERMINAL
sudo fail2ban-client status
sudo fail2ban-client status sshd

Privacy Considerations

## DNS Configuration

Configure persistent privacy-focused DNS servers.

# For Ubuntu 18.04+ with systemd-resolved:

TERMINAL
sudo nano /etc/systemd/resolved.conf

Update the configuration:

INI
[Resolve]
DNS=1.1.1.1 1.0.0.1
FallbackDNS=9.9.9.9 149.112.112.112
DNSOverTLS=yes

Restart the service:

TERMINAL
sudo systemctl restart systemd-resolved
sudo systemctl status systemd-resolved

# For older systems or without systemd-resolved:

TERMINAL
sudo apt install resolvconf
echo "nameserver 1.1.1.1" | sudo tee -a /etc/resolvconf/resolv.conf.d/head
echo "nameserver 1.0.0.1" | sudo tee -a /etc/resolvconf/resolv.conf.d/head
sudo resolvconf -u

## NTP Security

Configure secure time synchronization:
TERMINAL
sudo apt install chrony
sudo systemctl enable chrony

Web Server Setup (Optional)

If you're hosting web content, configure nginx with security headers:

TERMINAL
sudo apt install nginx

Add security headers to /etc/nginx/sites-available/default:

NGINX CONFIG
add_header X-Frame-Options DENY;
add_header X-Content-Type-Options nosniff;
add_header X-XSS-Protection "1; mode=block";
add_header Strict-Transport-Security "max-age=31536000; includeSubDomains" always;

Final Security Checks

## 1. Verify Open Ports

TERMINAL
sudo netstat -tulpn | grep LISTEN

## 2. Check Running Services

TERMINAL
sudo systemctl list-units --type=service --state=running

## 3. Review User Accounts

TERMINAL
cat /etc/passwd

Backup Strategy

Set up automated backups of critical data:

## Create backup directory and script:

TERMINAL
sudo mkdir -p /backup
sudo nano /usr/local/bin/backup.sh

Add this backup script:

BASH SCRIPT
#!/bin/bash
# Automated backup script with rotation

# Variables
BACKUP_DIR="/backup"
DATE=$(date +%Y%m%d_%H%M%S)
BACKUP_FILE="$BACKUP_DIR/server_backup_$DATE.tar.gz"
RETENTION_DAYS=7

# Create backup
tar -czf "$BACKUP_FILE" \
    --exclude='/home/*/.cache' \
    --exclude='/home/*/.local/share/Trash' \
    /home /etc /var/log 2>/dev/null

# Remove old backups
find "$BACKUP_DIR" -name "server_backup_*.tar.gz" -mtime +$RETENTION_DAYS -delete

# Log backup status
if [ $? -eq 0 ]; then
    echo "$(date): Backup successful - $BACKUP_FILE" >> /var/log/backup.log
else
    echo "$(date): Backup failed" >> /var/log/backup.log
fi

Make it executable and set up cron:

TERMINAL
sudo chmod +x /usr/local/bin/backup.sh
sudo crontab -e

Add this line for daily backups at 2 AM:

TERMINAL
0 2 * * * /usr/local/bin/backup.sh

Test the backup script:

TERMINAL
sudo /usr/local/bin/backup.sh
ls -lh /backup/

Additional Security Hardening

## Install and Configure auditd

Monitor system calls and track security events:
TERMINAL
sudo apt install auditd
sudo systemctl enable auditd
sudo auditctl -e 1

## Secure Shared Memory

Prevent execution from /tmp:
TERMINAL
sudo nano /etc/fstab

Add this line:

CONFIG
tmpfs /run/shm tmpfs defaults,noexec,nosuid 0 0

## Configure Log Rotation

Ensure logs don't fill up disk space:
TERMINAL
sudo nano /etc/logrotate.d/rsyslog

Verify these settings:

CONFIG
/var/log/syslog
/var/log/auth.log
{
    rotate 4
    weekly
    missingok
    notifempty
    compress
    delaycompress
    postrotate
        /usr/lib/rsyslog/rsyslog-rotate
    endscript
}

Conclusion

Following these steps provides a solid foundation for a privacy-focused VPS. This guide emphasizes:

  • Defense in depth: Multiple layers of security
  • Principle of least privilege: Minimal access rights
  • Security through obscurity: Non-standard ports and configurations
  • Continuous monitoring: Active threat detection
Remember: SERVERZ provides the infrastructure, but server security is ultimately your responsibility. Regular maintenance, monitoring, and staying informed about security updates are essential for long-term security.

## Quick Security Checklist

  • [ ] SSH key authentication configured
  • [ ] Password authentication disabled
  • [ ] Non-standard SSH port configured
  • [ ] Firewall enabled with minimal open ports
  • [ ] fail2ban monitoring SSH attempts
  • [ ] Automatic security updates enabled
  • [ ] Regular backups scheduled
  • [ ] System logs being monitored
Last updated: August 1, 2025

Ready to Deploy Your Private VPS?

Join thousands of developers who trust SERVERZ for anonymous, secure hosting.

ZERVERZ
Privacy-First Infrastructure

Deploy privacy infrastructure in seconds. WireGuard VPN servers with 5 pre-configured devices, private AI models with OpenWebUI, or custom VPS. No personal data required, cryptocurrency payments only, expert support always available.

Data Collection
ZERO
Payment Privacy
CRYPTO ONLY
Service Status
VPS Platform:ONLINE
Payment System:ACTIVE
Quick Deploy:READY
Expert Support:AVAILABLE
ZERVERZ:~/$ status --all
© 2026 Serverz LLC
Sitemap
Privacy by design