[{"data":1,"prerenderedAt":117},["ShallowReactive",2],{"seo-verification":3,"blog-heberger-bastion-host-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"id":7,"slug":8,"title":9,"excerpt":10,"readTime":11,"views":12,"isPinned":13,"publishedAt":14,"category":15,"categories":21,"featuredImage":23,"bgImage":24,"posterImage":25,"relatedSolution":26,"intro":28,"sections":29,"ctaTitle":72,"ctaBody":73,"ctaButton":74,"ctaUrl":75,"relatedPosts":76},158,"heberger-bastion-host-vps","Bastion Host on VPS: securing your SSH access","Deploy a Bastion Host on a ServOrbit VPS: a hardened SSH entry point, centralized access, logs and security rules.",7,0,false,"2026-07-05T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},8,"Security & Monitoring","securite-monitoring","bg-rose-500\u002F10 text-rose-400","security",[22],{"id":16,"name":17,"slug":18,"color":19,"icon":20},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Fheberger-bastion-host-vps-poster.svg",{"categorySlug":20,"appSlug":27},"bastion-host","An SSH bastion avoids exposing each server directly on the Internet: administrators go through a hardened, logged and easy-to-audit entry point. On a ServOrbit VPS, this role stays clear: a stable IP, OpenSSH, named keys and minimal firewall rules. This guide presents a lean setup, useful for a small team as well as for an agency administering several machines.",[30,34,43,46,65,69],{"type":31,"title":32,"body":33},"h2","Why go through an SSH bastion?","A bastion reduces the attack surface: instead of opening SSH on each server, you concentrate access on a dedicated machine. Keys, users and logs are simpler to control, and internal servers can stay closed to the public network.",{"type":35,"title":36,"items":37},"ul","What this template brings",[38,39,40,41,42],"A single entry point for administrator SSH access.","Named keys rather than a shared password.","A simple foundation for logging connections and sensitive commands.","Reduced network exposure for the application servers behind the bastion.","A foundation compatible with the classic tools: OpenSSH, ProxyJump, UFW and Fail2Ban.",{"type":31,"title":44,"body":45},"Requirements before opening it to the team","Plan for a lightweight but isolated VPS, a clear list of authorized people, individual SSH keys and a firewall rule that opens only the necessary SSH port. For a distributed team, also document the username format and the revocation procedure.",{"type":47,"title":48,"steps":49},"steps","Deploy a bastion properly",[50,53,56,59,62],{"title":51,"body":52},"Create the dedicated VPS","Select the Bastion Host template in the ServOrbit Marketplace or start from a minimal Ubuntu. Keep this server dedicated to SSH access: no website, no database, no ancillary services.",{"title":54,"body":55},"Set up the named keys","Add one key per administrator in `~\u002F.ssh\u002Fauthorized_keys`. Avoid shared accounts: in case of a departure or rotation, you must be able to remove a single key without blocking the whole team.",{"title":57,"body":58},"Harden OpenSSH","Disable password authentication, block direct root login and limit authorized users with `AllowUsers` or `AllowGroups` in `sshd_config`.",{"title":60,"body":61},"Configure ProxyJump","On administrator workstations, add a `ProxyJump` entry in `~\u002F.ssh\u002Fconfig`. Internal servers remain accessible over SSH through the bastion, with no public port open.",{"title":63,"body":64},"Monitor and revoke","Enable Fail2Ban if the SSH port remains exposed and regularly check `\u002Fvar\u002Flog\u002Fauth.log`. Immediately remove keys that are no longer used.",{"type":66,"title":67,"body":68},"tip","ServOrbit tip","Keep the bastion small, predictable and separate from the rest. Its value comes from its simplicity: the fewer services it hosts, the easier it is to audit.",{"type":66,"title":70,"body":71},"The official documentation","For advanced configuration, options specific to the tool, and version changes, refer to the \u003Ca href=\"https:\u002F\u002Fman.openbsd.org\u002Fsshd_config\" target=\"_blank\" rel=\"noopener noreferrer\">official OpenSSH documentation\u003C\u002Fa>. This guide covers deployment on a ServOrbit VPS; the vendor's documentation remains the reference for fine-tuning.","Centralize your SSH access on a ServOrbit VPS","The Bastion Host template gives you a clear entry point to administer your servers without exposing each machine directly on the Internet.","Deploy the bastion","\u002Fvps-cloud",[77,92,104],{"id":78,"slug":79,"title":80,"excerpt":81,"readTime":82,"views":83,"isPinned":13,"publishedAt":84,"category":85,"categories":86,"featuredImage":23,"bgImage":24,"posterImage":88,"relatedSolution":89},109,"proteger-vps-fail2ban","Fail2Ban Enhanced on VPS: blocking repeated attacks","Link Fail2Ban Enhanced to the ServOrbit catalog: SSH\u002FNginx banning, readable logs and official documentation.",6,633,"2026-03-03T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},[87],{"id":16,"name":17,"slug":18,"color":19,"icon":20},"\u002Fblog\u002Fcovers\u002Fproteger-vps-fail2ban-poster.svg",{"categorySlug":90,"appSlug":91},"securite","fail2ban-enhanced",{"id":93,"slug":94,"title":95,"excerpt":96,"readTime":11,"views":12,"isPinned":13,"publishedAt":97,"category":98,"categories":99,"featuredImage":23,"bgImage":24,"posterImage":101,"relatedSolution":102},141,"installer-wireguard-vps","WireGuard on a VPS: a fast, lean and private VPN","Deploy WireGuard on a ServOrbit VPS: fast tunnels, readable configuration, client QR codes and private remote access.","2026-02-04T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},[100],{"id":16,"name":17,"slug":18,"color":19,"icon":20},"\u002Fblog\u002Fcovers\u002Finstaller-wireguard-vps-poster.svg",{"categorySlug":90,"appSlug":103},"wireguard-server",{"id":105,"slug":106,"title":107,"excerpt":108,"readTime":16,"views":109,"isPinned":13,"publishedAt":110,"category":111,"categories":112,"featuredImage":23,"bgImage":24,"posterImage":114,"relatedSolution":115},108,"securiser-vps-crowdsec","Securing your VPS with CrowdSec","Deploy CrowdSec on your VPS to block attacks thanks to behavioral detection and a shared community blocklist.",596,"2026-03-04T00:00:00+00:00",{"id":16,"name":17,"slug":18,"color":19,"icon":20},[113],{"id":16,"name":17,"slug":18,"color":19,"icon":20},"\u002Fblog\u002Fcovers\u002Fsecuriser-vps-crowdsec-poster.svg",{"categorySlug":90,"appSlug":116},"crowdsec",1785628434017]