Setup & operation
How do I stop SSH brute-force attacks?
Disable password authentication entirely — brute force against key-based SSH is not possible. Add fail2ban to reduce log noise, and consider moving SSH off port 22 to cut scanner volume by roughly 95%. The strongest option is putting SSH behind WireGuard so it is never exposed to the public internet.
Changing the port is not security by itself, but it is genuinely effective noise reduction: the vast majority of automated scanners only try 22. Combined with key-only authentication, the residual risk is negligible.
The correct end state for a sensitive server is no public SSH listener at all. Bind sshd to a WireGuard interface, and administration requires the tunnel first. Nothing on the public internet can even attempt authentication.
7 answers in Setup & operation
- How do I connect to a VPS with SSH? Run ssh root@your-server-ip from any terminal on macOS, Linux or Windows 10 and later. Use the key you supplied at provisioning, or the password email…
- How do I secure a new VPS? Five steps cover the overwhelming majority of real-world compromises: key-based SSH with password authentication disabled, no direct root login, a def…
- How do I set up a firewall on a VPS? Use nftables on modern Linux, or ufw as a friendlier front end. Set the default inbound policy to drop, allow established and related connections, the…
- Can I install any operating system on a VPS? On KVM, yes. OnionVPS provides templates for Ubuntu, Debian, AlmaLinux, Rocky, Fedora, Arch, Alpine, NixOS, FreeBSD, OpenBSD, Windows Server, Proxmox …
- Can I upload my own ISO? Yes, on every plan, at no cost and with no approval step. Upload the ISO from the panel or point us at a URL, attach it as virtual media, and boot fro…
- What is KVM virtualisation? KVM (Kernel-based Virtual Machine) is full hardware virtualisation built into the Linux kernel, using processor extensions to run each guest with its …