Panduan

Amankan VPS baru dalam 10 menit

Pemula10 menit bacaDiperbarui 18 Juni 2026
Jawaban singkat

Lima perubahan menghilangkan hampir semua serangan otomatis terhadap server baru: SSH berbasis kunci dengan sandi dinonaktifkan, tanpa login root langsung, firewall default-deny yang mencakup IPv4 dan IPv6, pembaruan keamanan otomatis, dan fail2ban. Bersama-sama, ini memakan waktu sekitar sepuluh menit dan lebih penting daripada fitur penyedia mana pun.

01 Hasilkan dan pasang kunci SSH

Do this from your own machine, not the server. Ed25519 keys are shorter and faster than RSA and are supported everywhere that matters.

ssh-keygen -t ed25519 -C "onionvps-$(date +%Y%m)"
ssh-copy-id -i ~/.ssh/id_ed25519.pub root@YOUR_SERVER_IP

02 Buat pengguna non-root

Working as root all the time removes a useful safety net and makes every mistake maximally expensive.

adduser --gecos "" ops
usermod -aG sudo ops
rsync --archive --chown=ops:ops ~/.ssh /home/ops

03 Perkuat daemon SSH

Disable password authentication entirely — brute force against key-only SSH is not possible. Keep a second terminal connected while you do this, so a mistake does not lock you out.

cat >/etc/ssh/sshd_config.d/99-hardening.conf <<'EOF'
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication no
AllowUsers ops
EOF
sshd -t && systemctl reload ssh

04 Atur firewall default-deny

Cover IPv6 as well as IPv4. Every OnionVPS instance has a routed /64, so a v4-only ruleset leaves every service publicly reachable over v6.

ufw default deny incoming
ufw default allow outgoing
ufw allow 22/tcp
ufw allow 80,443/tcp
ufw enable
ufw status verbose   # confirm IPv6 shows as enabled

05 Aktifkan pembaruan keamanan otomatis

Unattended upgrades close the window between a patch being published and you noticing it exists.

apt install -y unattended-upgrades
dpkg-reconfigure -plow unattended-upgrades

06 Pasang fail2ban dan ambil snapshot

fail2ban mostly reduces log noise once passwords are disabled, but it is cheap. Then snapshot the configured state — that becomes your known-good baseline.

apt install -y fail2ban && systemctl enable --now fail2ban

Pertanyaan yang sering diajukan

Haruskah saya mengubah port SSH?

Ini adalah pengurangan kebisingan, bukan keamanan, tetapi pengurangan kebisingan yang efektif — sebagian besar pemindai hanya mencoba port 22. Dengan autentikasi kunci saja, risiko sisa dapat diabaikan.

Bagaimana jika saya terkunci?

Gunakan konsol VNC out-of-band di panel kontrol. Ini terhubung ke konsol serial virtual dan berfungsi tanpa jaringan sama sekali.