SSH and managing a server: connecting, keys, copying files, config, hardening and firewalls
SSH (Secure Shell) lets you control a remote computer securely over the internet, as if you were typing on its keyboard. It's how developers deploy websites, how administrators manage cloud servers, and how network engineers reach Linux devices. Everything you type is encrypted, so passwords and data can't be read by anyone in between, even on public Wi-Fi.
This unit takes you from your first connection to a properly secured server.
How SSH works
- The SSH server (
sshd) runs on the remote machine, listening on port 22 by default. - The SSH client (
ssh) runs on your computer: built into Linux, macOS and Windows 10/11 (PowerShell or Windows Terminal). PuTTY and MobaXterm are graphical alternatives on Windows. - When you first connect, the server shows its host key fingerprint. Accepting it stores it in
~/.ssh/known_hosts; if it changes later, SSH warns you (possible impersonation, or the server was rebuilt).
Connecting
ssh username@server-ip
ssh deploy@203.0.113.10
ssh -p 2222 deploy@203.0.113.10 # a non-standard port
exit # disconnect (or Ctrl+D)Cloud providers give you an IP address and either a password or a key at creation.
SSH keys: better than passwords
A key pair has a private key (stays on your computer, secret) and a public key (copied to servers). Keys are far stronger than passwords and can't be guessed by bots.
ssh-keygen -t ed25519 -C "wanjiku laptop"
# saves ~/.ssh/id_ed25519 (private) and ~/.ssh/id_ed25519.pub (public)
# set a passphrase to protect the private key if the laptop is stolenCopy the public key to the server:
ssh-copy-id deploy@203.0.113.10This appends your public key to ~/.ssh/authorized_keys on the server. Without ssh-copy-id (e.g. on Windows), paste the contents of id_ed25519.pub into that file manually and set permissions (chmod 700 ~/.ssh, chmod 600 ~/.ssh/authorized_keys).
Use ssh-agent so you type the passphrase once per session: eval "$(ssh-agent -s)" then ssh-add.
The SSH config file
Create ~/.ssh/config on your computer:
Host shop
HostName 203.0.113.10
User deploy
Port 22
IdentityFile ~/.ssh/id_ed25519
Host school-portal
HostName portal.example.co.ke
User adminNow just type ssh shop. The aliases work with scp, rsync and Git too.
Copying files
scp index.html shop:/var/www/site/ # upload a file
scp shop:/var/log/nginx/error.log . # download
scp -r website/ shop:/var/www/ # a folder
rsync -avz website/ shop:/var/www/site/ # sync only changes (fast, resumable)
rsync -avz --delete website/ shop:/var/www/site/ # also delete files removed locally (careful)
rsync -avzn website/ shop:/var/www/site/ # -n: dry run, show what would happenrsync is the professional choice for deployments and backups. SFTP (in FileZilla or WinSCP) gives a drag-and-drop view over the same SSH connection.
Remote commands and tunnels
ssh shop "df -h && uptime" # run a command and return
ssh -L 8080:localhost:3306 shop # local port 8080 -> server's MySQL (3306) securelyTunnels let you reach services (like a database admin tool) that aren't exposed to the internet.
Hardening a new server
Bots try to log in to every public server within minutes of it going online. Do this on day one:
1. Update and create a normal user
ssh root@203.0.113.10
apt update && apt upgrade -y
adduser deploy
usermod -aG sudo deploy # allow admin commands with sudo2. Add your key for the new user
From your computer: ssh-copy-id deploy@203.0.113.10, then test ssh deploy@203.0.113.10 in a new terminal before going further.
3. Disable root login and passwords
Edit the SSH server configuration:
sudo nano /etc/ssh/sshd_configSet:
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yesCheck and apply:
sudo sshd -t # test the config for errors
sudo systemctl restart ssh # the service is "ssh" on Ubuntu ("sshd" on some distros)4. Firewall with UFW
sudo ufw allow OpenSSH # allow SSH BEFORE enabling!
sudo ufw allow 80/tcp # HTTP
sudo ufw allow 443/tcp # HTTPS
sudo ufw enable
sudo ufw status verboseOnly open the ports you need. Databases (3306 MySQL, 5432 PostgreSQL) should normally not be open to the internet.
5. Fail2ban
sudo apt install fail2ban
sudo systemctl enable --now fail2ban
sudo fail2ban-client status sshdFail2ban watches logs and temporarily bans IP addresses with repeated failed logins.
6. Automatic security updates
sudo apt install unattended-upgrades
sudo dpkg-reconfigure --priority=low unattended-upgradesChecking who's logged in and login attempts
who # who's logged in now
last # recent logins
sudo journalctl -u ssh --since today # SSH service logs
sudo grep "Failed password" /var/log/auth.log | tailFirst-day VPS checklist
- Update packages.
- Create a sudo user; add your SSH key.
- Disable root login and password authentication.
- Enable UFW (SSH, 80, 443 only).
- Install Fail2ban and unattended-upgrades.
- Set the timezone:
sudo timedatectl set-timezone Africa/Nairobi. - Set up backups (provider snapshots + off-server copies).
- Install your stack (Nginx/Apache, PHP, database) and configure HTTPS (the hosting subject covers this).
Think about it: You disabled password login, restarted SSH, closed your only session, and now ssh deploy@server says "Permission denied (publickey)". What probably went wrong, and how do you recover?Show answer
Your public key wasn't correctly in /home/deploy/.ssh/authorized_keys (or the permissions on .ssh were wrong). Recover through the cloud provider's web/recovery console, fix the key file and permissions (700/600, owned by deploy), then test from a second terminal before closing the console.
Summary
- SSH gives encrypted remote access on port 22; the client is built into Linux, macOS and Windows.
- Use key pairs:
ssh-keygen -t ed25519,ssh-copy-id; keep the private key secret with a passphrase. ~/.ssh/configcreates shortcuts; scp, rsync and SFTP copy files; tunnels reach private services.- Harden servers: sudo user, keys only,
PermitRootLogin no,PasswordAuthentication no, UFW, Fail2ban, automatic updates. - Test new SSH settings from a second session before closing the first.
Check yourself
What is the default SSH port number?
Show answer
22
Which command creates an SSH key pair?
Show answer
ssh-keygen
Which command copies your public key to a server?
Show answer
ssh-copy-id
Which file on the server lists public keys allowed to log in?
Show answer
authorized_keys
Which sshd_config setting stops root from logging in? (three words)
Show answer
PermitRootLogin no
Which tool bans IP addresses after repeated failed logins?
Show answer
Fail2ban