Table of contents [Show]
In my experience as a system administrator, I've seen too many times how companies trust that a newly installed Linux server is secure by default. Nothing could be further from the truth. Hardening and periodic maintenance are two sides of the same coin: without a hardened base, any subsequent patch is a patch on sand; without maintenance, even the most robust system degrades until it becomes a sieve. This article is a practical guide based on my field experience, with concrete steps and mistakes you should avoid.

The first principle of hardening is simple: if you don't need it, remove it. This applies to services, packages, users, and ports. Before touching anything, perform a complete inventory of the system: what services are listening, what ports are open, and what packages are installed. Tools like ss -tulpn, netstat, or local nmap will give you a clear picture.
On many distributions, services like cups, avahi-daemon, or bluetooth come enabled without anyone using them. Disable them with systemctl disable --now. Each disabled service is one less door for an attacker.
Don't wait until you have an incident to configure iptables or nftables. A default policy of denying all incoming traffic and allowing only what's necessary (SSH, HTTP/HTTPS, etc.) is the foundation of any secure server. Also remember to filter outgoing traffic to prevent data exfiltration.
Access to the server is the most critical point. There are no excuses here: password authentication must be eliminated or, at least, complemented with SSH keys and two-factor authentication. In my opinion, using passwords for SSH is an unnecessary risk in production environments.
/etc/ssh/sshd_config and set PermitRootLogin no. Use a user with sudo privileges.ssh-keygen and copy the public key to the server. Disable password authentication (PasswordAuthentication no).
The Linux kernel offers a series of parameters that can harden the system. For example, enable sysctl to protect against certain attacks:
net.ipv4.tcp_syncookies = 1 to mitigate SYN floods.net.ipv4.conf.all.rp_filter = 1 to enable reverse path filtering.kernel.randomize_va_space = 2 for address space layout randomization (ASLR).Additionally, for web services like Nginx or Apache, apply HTTP security headers (HSTS, X-Frame-Options, CSP) and disable directory listing. If you use databases, run them with a user without privileges and on an isolated network.
Hardening is not a one-time event; it's a cycle. Regular maintenance includes:
No matter how hardened your server is, if vulnerability management is deficient. As I mentioned in my article on AI-powered vulnerability scanning, automation is key to staying up to date. Establish a process to track CVEs related to your stack and prioritize based on real exposure.

Hardening and maintenance of Linux servers are not tasks that are done once and forgotten. They require constant discipline and a curiosity to learn from each incident. At ForgeNEX, in our Computer Security category, we promote this culture. Remember: security is a process, not a product. Start with the basics, automate the repetitive, and never underestimate the value of good documentation.