1. Đổi password root mạnh:
passwd root
2. Cài và cấu hình UFW Firewall:
apt install -y ufw
ufw default deny incoming
ufw default allow outgoing
ufw allow 22 # SSH - QUAN TRỌNG làm trước!
ufw allow 80
ufw allow 443
ufw enable
ufw status verbose
3. Đổi port SSH:
nano /etc/ssh/sshd_config
# Sửa: Port 2222
ufw allow 2222
systemctl restart sshd
Mở terminal mới test trước khi đóng session cũ!
4. Cài Fail2ban:
apt install -y fail2ban
cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
Sửa section [sshd] trong jail.local:
[sshd]
enabled = true
maxretry = 5
bantime = 3600
systemctl restart fail2ban
fail2ban-client status sshd
5. Tắt SSH password (dùng SSH key):
Đảm bảo đã setup SSH key trước! Sau đó sửa /etc/ssh/sshd_config:
PasswordAuthentication no
PermitRootLogin prohibit-password
systemctl restart sshd Có thể bạn cần xem thêm
Bài viết đã được kiểm duyệt bởi VPS HC Team
Cập nhật lần cuối: 15/06/2026