Any server with a public IP receives SSH login attempts within minutes. Most are automated and harmless, but a weak configuration turns that noise into a real risk. These are the changes I apply on every new VPS.
1. Use keys, disable passwords
Generate an Ed25519 key on your machine and copy it to the server before touching the daemon configuration:
ssh-keygen -t ed25519 -C "laptop"
ssh-copy-id user@server
2. Use a drop-in file, not the main config
Recent OpenSSH versions read /etc/ssh/sshd_config.d/*.conf. A dedicated file survives package upgrades and keeps your changes in one place:
# /etc/ssh/sshd_config.d/00-hardening.conf
PermitRootLogin no
PasswordAuthentication no
KbdInteractiveAuthentication no
PubkeyAuthentication yes
MaxAuthTries 3
LoginGraceTime 20
AllowUsers ubuntu
The 00- prefix matters: for most options the first value read wins, so your file must come before distribution defaults.
3. Test before you disconnect
Validate the syntax, reload, and open a second session before closing the first one:
sudo sshd -t && sudo systemctl reload ssh
4. Add Fail2Ban and a firewall
Fail2Ban bans addresses that keep failing authentication, and UFW limits exposure to the ports you actually serve:
sudo ufw allow 22/tcp
sudo ufw allow 80,443/tcp
sudo ufw enable
sudo apt install fail2ban
What not to rely on
Changing the port reduces log noise but is not a security control. Treat keys, disabled passwords and a patched OpenSSH as the real defenses, and review journalctl -u ssh from time to time.