Setup & operation
How do I set up a firewall on a VPS?
Short answer
Use nftables on modern Linux, or ufw as a friendlier front end. Set the default inbound policy to drop, allow established and related connections, then allow only the ports you actually serve. Always allow your SSH port before enabling the policy, or the console will be your only way back in.
Remember IPv6. A ruleset that only covers IPv4 leaves every service reachable over v6, and every instance here has a routed /64. ufw handles both by default; hand-written nftables rules need an ip6 table or an inet table.
Test before you commit. A common pattern is to schedule a job that flushes the rules in ten minutes, apply the new policy, verify you are still connected, then cancel the job.
- ufw default deny incoming; ufw default allow outgoing
- ufw allow 22/tcp (or your chosen port) before ufw enable
- ufw allow 80,443/tcp for web services
- Confirm IPv6 is covered — check ufw status verbose or your nft ruleset
See also: IPv6
7 answers in Setup & operation
- How do I connect to a VPS with SSH? Run ssh root@your-server-ip from any terminal on macOS, Linux or Windows 10 and later. Use the key you supplied at provisioning, or the password email…
- How do I secure a new VPS? Five steps cover the overwhelming majority of real-world compromises: key-based SSH with password authentication disabled, no direct root login, a def…
- How do I stop SSH brute-force attacks? Disable password authentication entirely — brute force against key-based SSH is not possible. Add fail2ban to reduce log noise, and consider moving SS…
- Can I install any operating system on a VPS? On KVM, yes. OnionVPS provides templates for Ubuntu, Debian, AlmaLinux, Rocky, Fedora, Arch, Alpine, NixOS, FreeBSD, OpenBSD, Windows Server, Proxmox …
- Can I upload my own ISO? Yes, on every plan, at no cost and with no approval step. Upload the ISO from the panel or point us at a URL, attach it as virtual media, and boot fro…
- What is KVM virtualisation? KVM (Kernel-based Virtual Machine) is full hardware virtualisation built into the Linux kernel, using processor extensions to run each guest with its …