Production Linux Server Hardening Checklist: SSH, UFW, Fail2ban & CIS Benchmarks

Deploying a public Linux VPS without defensive hardening leaves it vulnerable to automated credential stuffing, brute force scans, and privilege escalation exploits within minutes of coming online. In this checklist, we enforce a Defense-in-Depth security architecture conforming to Center for Internet Security (CIS) Level 1 benchmarks.

Enterprise Linux Server Hardening & Defense-in-Depth Architecture
Fig 1: 4-Layer Defense-in-Depth: Cryptographic SSH, Ingress UFW, Fail2ban Jails & CIS Kernel Audit.

1. Step 1: Cryptographic SSH Key Enforcement

Disable all password-based SSH authentication and force modern elliptic curve keys in /etc/ssh/sshd_config:

# /etc/ssh/sshd_config Hardening
PasswordAuthentication no
ChallengeResponseAuthentication no
PermitRootLogin prohibit-password
PubkeyAuthentication yes
X11Forwarding no
MaxAuthTries 3
ClientAliveInterval 300
ClientAliveCountMax 2
KexAlgorithms curve25519-sha256,curve25519-sha256@libssh.org
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com

Generate keys using ssh-keygen -t ed25519 -a 100 on your local workstation and verify connection before restarting the SSH daemon via sudo systemctl reload sshd.

2. Step 2: Uncomplicated Firewall (UFW) Ingress Isolation

Enforce a strict default-deny ingress policy and expose only necessary public web services:

# Reset and enforce default deny
sudo ufw default deny incoming
sudo ufw default allow outgoing
# Allow HTTP and HTTPS
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# Restrict SSH to custom management subnet if applicable
sudo ufw allow 22/tcp
# Enable and inspect
sudo ufw enable
sudo ufw status verbose

3. Step 3: Automated Rate Limiting with Fail2ban

Configure Fail2ban to monitor authentication logs and Nginx HTTP error streams, automatically dropping offending IP addresses via iptables:

# /etc/fail2ban/jail.local
[DEFAULT]
bantime = 86400
findtime = 600
maxretry = 3
banaction = ufw
[sshd]
enabled = true
port = 22
filter = sshd
logpath = /var/log/auth.log
[nginx-botsearch]
enabled = true
port = http,https
filter = nginx-botsearch
logpath = /var/log/nginx/*error.log
maxretry = 2

4. Step 4: CIS Auditing & Unattended Security Upgrades

Enable automatic unattended security patching and perform periodic compliance auditing:

# Enable automated security updates
sudo apt install unattended-upgrades update-notifier-common
sudo dpkg-reconfigure --priority=low unattended-upgrades
# Verify /etc/apt/apt.conf.d/50unattended-upgrades
Unattended-Upgrade::Allowed-Origins {
    "${distro_id}:${distro_codename}-security";
};
Unattended-Upgrade::AutoFixInterruptedDpkg "true";
Unattended-Upgrade::MinimalSteps "true";
Unattended-Upgrade::Automatic-Reboot "false";

5. Step 5: Shared Memory & Filesystem Mount Hardening

Attackers who gain restricted shell access frequently execute malicious binaries out of world-writable directories such as /tmp and /dev/shm. Protect these mountpoints by adding defensive flags to /etc/fstab:

# /etc/fstab Hardening
tmpfs /tmp tmpfs defaults,nosuid,nodev,noexec,mode=1777 0 0
tmpfs /var/tmp tmpfs defaults,nosuid,nodev,noexec,mode=1777 0 0
tmpfs /dev/shm tmpfs defaults,nosuid,nodev,noexec 0 0

The noexec flag prevents the execution of any binary or script directly from the directory, neutralizing common web application shell drops.

6. Step 6: Kernel Self-Protection & Network Security via Sysctl

Harden the Linux network stack against IP spoofing, SYN flood attacks, and ICMP redirect manipulation by configuring /etc/sysctl.d/50-security.conf:

# Reverse Path Filtering (Mitigate IP Spoofing)
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
# Ignore ICMP Broadcast Requests & Smurf Attacks
net.ipv4.icmp_echo_ignore_broadcasts = 1
# Disable ICMP Redirect Acceptance (Mitigate Man-in-the-Middle)
net.ipv4.conf.all.accept_redirects = 0
net.ipv4.conf.default.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
# Prevent Rogue Source-Routed Packets
net.ipv4.conf.all.accept_source_route = 0
net.ipv4.conf.default.accept_source_route = 0
# Protect Hardlinks and Symlinks against TOCTOU Race Conditions
fs.protected_hardlinks = 1
fs.protected_symlinks = 1
# Maximize Address Space Layout Randomization (ASLR)
kernel.randomize_va_space = 2

7. Step 7: Automated Compliance Auditing with Lynis

Regularly audit system compliance against CIS benchmarks using Lynis, an open-source security auditing tool:

# Install and run Lynis security audit
sudo apt install lynis
sudo lynis audit system --quick
# Review Lynis hardening index and generated warnings
grep "Hardening index" /var/log/lynis.log
grep "WARNING" /var/log/lynis.log

Aim for a Lynis Hardening Index score of 80 or higher on production web hosting environments.

Frequently Asked Questions

Is changing the default SSH port (22) sufficient for server protection?

Changing the SSH port to a non-standard port (e.g., 2222) reduces automated bot scans in access logs, but it is merely security through obscurity. A simple port scan with Nmap will immediately discover the listening SSH service. Cryptographic key enforcement, disabling root password login, and Fail2ban rate limiting provide genuine security.

How do I unban an administrator IP address accidentally locked out by Fail2ban?

If an administrator enters incorrect credentials and triggers a jail ban, connect from a secondary whitelisted IP or the hosting provider out-of-band console, then execute:

sudo fail2ban-client set sshd unbanip 203.0.113.50

You can also permanently whitelist administrative office IP subnets by adding them to the ignoreip directive in /etc/fail2ban/jail.local.

What is the difference between CIS Benchmark Level 1 and Level 2?

CIS Level 1 provides defensive security controls that can be applied with minimal risk of breaking normal operating software. Level 2 enforces defense-in-depth measures (such as strict mandatory access control policies, restricted kernel modules, and aggressive filesystem isolation) that require customized application tuning to prevent operational conflicts.

Why is Address Space Layout Randomization (ASLR = 2) critical?

Setting kernel.randomize_va_space = 2 randomizes the memory addresses of the stack, VDSO page, shared memory libraries, and data segment. This prevents memory corruption exploits (such as buffer overflows and Return-Oriented Programming attacks) from predicting executable memory targets.

Summary & Cloud Security Baseline

Hardening a Linux server requires a layered defensive posture. By implementing cryptographic SSH key pairs, strict ingress firewall isolation, Fail2ban intrusion prevention, protected shared memory mounts, and CIS benchmark auditing, systems administrators ensure production instances remain resilient against automated exploitation.

Deploy Pre-Hardened Cloud VPS

Deploy hardened Linux instances with built-in DDoS filtering, NVMe storage, and isolated virtual networks on WinWinHost.

Explore Hardened Cloud VPS →

WinWinHost News & Tutorials

Unlimited Website Edits via Autonomous AI

WinWinHost launches Unlimited Website Edits powered by autonomous AI engineering. Get continuous content revisions, mobile UI polish, technical SEO, and Core Web Vitals optimization with zero hourly fees and zero downtime.

New Product: Autonomous AI Web Developer Agent for $10/mo

WinWinHost introduces autonomous AI Web Developer Agents for just $10/month per domain. Each dedicated agent continuously monitors site health, resolves layout regressions, optimizes PageSpeed scores, and executes code updates with zero developer hourly fees.

Link Directory Plugin Released

Link Directory Plugin was released and we hope that this can help you to make a link directory website from your wordpress installation in just a few minutes.Right now the plugin has a lot of features but we are working to make even more options available to you.

Monetize Your Website

If you want to monetize your website via a payday loan affiliate network then you should know that are some nice networks out there like WinWinHost Network that can be a profitable way for your business.

Payday Loan Affiliate Plugin Released

Now you can earn money by generating leads with your wordpress website. We have created an wordpress plugin that adds a Payday Loan form to your website that you can customize in many ways.

What you can do with a domain name

Getting your own domain is really a huge step for anyone who wants to have an online presence. It changes the whole way a person work. Many people get domain names for individual reasons

The Shift to Edge Computing and Its Impact on Web Hosting

Explore how edge computing and distributed content delivery networks are redefining the speed, security, and scalability of modern web hosting.

WordPress Stats and Global Use

WordPress powers over 43% of the web. Learn more about the latest CMS market share growth metrics and global usage stats.

Google+ - The New Social Network

Google said it would begin the project of building a social networking platform that can compete against the more known Facebook and makes online communication a reality today.

Microsoft Office 365

Microsoft announced the launch of a cloud service called Office 365 which will bring together Microsoft Office, Microsoft Lync Online, Microsoft Exchange Online, and Microsoft SharePoint Online.

How to maintain your web hosting reseller account

One of the most efficient business on the Internet at this moment is selling web space known as web hosting reseller. It is the perfect solution for those who want to sell web space with a small investment.

Advantages of reselling Windows server space

Generally when you want to become a web hosting reseller you should consider everything carefully before starting to provide such services. It is better to decide if it is in your advantage to provide space on a Windows server.

About SEO

All the companies/individuals who have contact with the online environment and manage to make profit from its activities on the Internet, always want to improve the performance of his websites and this can be best done by using SEO.

ICANN approves new suffixes

ICANN (Internet Corporation for Assigned Names and Numbers) approved the measure after which anyone can register domains with custom suffixes.

Need Help?

Have questions about our hosting plans or custom software development? Reach out to our experts anytime.