Elige las opciones y descarga un script bash comentado, listo para revisar y ejecutar en tu VPS Debian o Ubuntu.
No cierres tu sesión SSH actual
Antes de cerrar esta terminal, abre una segunda y confirma que puedes conectarte con la nueva configuración. Un error en el firewall o en SSH puede dejarte fuera de tu propio servidor.
Script generado
#!/usr/bin/env bash
set -euo pipefail
# Generated by the SecuryBlack VPS hardening generator.
# Review every line before running it. Written for Debian/Ubuntu (apt + ufw) —
# other distros are not supported yet.
#
# IMPORTANT: keep this SSH session open. Open a SECOND terminal and confirm
# you can log in before closing this one — a mistake in the SSH or firewall
# config below can lock you out of your own server.
echo "1/4 Allowing SSH before enabling the firewall..."
sudo ufw allow 22/tcp
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
echo "Enabling UFW..."
sudo ufw --force enable
echo "2/4 Installing fail2ban..."
sudo apt-get update
sudo apt-get install -y fail2ban
sudo systemctl enable --now fail2ban
echo "3/4 Hardening sshd_config..."
sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin prohibit-password/' /etc/ssh/sshd_config
sudo sed -i 's/^#\?PasswordAuthentication.*/PasswordAuthentication no/' /etc/ssh/sshd_config
sudo systemctl restart sshd
echo "4/4 Enabling unattended security upgrades..."
sudo apt-get install -y unattended-upgrades
sudo dpkg-reconfigure -f noninteractive unattended-upgrades
echo "Done. Do NOT close this session — open a new terminal and confirm you can log in before disconnecting."FerroSentry aplica este mismo hardening en menos de un minuto al conectar tu servidor, y lo vigila en continuo después — si algo cambia, te avisa.