Harden infrastructure security.

Logo Bastion Host

Bastion Host

A secure, hardened SSH entry point to your infrastructure, with centralised auditing.

1 GB RAM 1 vCPU Port 22 (SSH) Available

Tech stack

SSHfail2banauditdUFW
Minimum RAM1 GB
Minimum CPU1 vCPU
Default port22 (SSH)
Compatible OSubuntu-24.04

A bastion (SSH jump host) is the single, hardened entry point through which all administrative connections to your private servers pass. Rather than exposing every machine, you expose only one reinforced host that is monitored and logged — drastically reducing your infrastructure's attack surface.

Deployed on a dedicated VPS, this template configures and hardens the SSH service (attempt limiting, connection grace periods, disabling of unnecessary options), installs fail2ban to automatically ban malicious IPs, and enables system auditing (auditd) and a UFW firewall. SSH forwarding stays enabled to act as a jump to your internal servers, while keeping a centralised access log.

Key features

Hardened SSH: attempt limiting, grace period, unnecessary options disabled
fail2ban: automatic IP banning after repeated failures
System auditing (auditd) for traceability of access and commands
Pre-configured UFW firewall (SSH allowed, everything else closed)
SSH forwarding retained for jumping to private servers
Attack surface reduced to a single monitored entry point

When to use this solution?

1

Access to private servers

Centralise all administrative connections through a single hardened host, instead of exposing each server on the Internet.

2

Access traceability

Keep a centralised log of who connects, when and to which servers, for auditing and compliance.

3

Attack surface reduction

Close direct SSH access to your internal machines and expose only a single reinforced, monitored entry point.

Deploy Bastion Host on your VPS

Guide optimized for ServOrbit Cloud VPS.

01

Create the VPS

A VPS with 1 GB RAM, Ubuntu 22.04. The "Bastion Host" template hardens SSH and installs fail2ban, auditd and UFW automatically.

02

Add your public key

Add your public SSH key to the bastion (~/.ssh/authorized_keys) before disabling password authentication.

03

Configure the jump

From your machine, use the bastion as a ProxyJump (ssh -J bastion utilisateur@serveur-prive) to reach your internal servers.

04

Lock down direct access

Restrict SSH access on your private servers to the bastion's IP through their firewall, to close off any direct connection.

Frequently asked questions

A bastion is a hardened server that acts as the single entry point to a private infrastructure. All administrative connections pass through it, which reduces the attack surface and centralises auditing.

Harden infrastructure security.

Activate Bastion Host on your infrastructure.

Dedicated Cloud VPS — IPv4 included, European datacenter, support included. Your data never leaves your server.

Recommended configuration: 1 GB RAM · 1 vCPU

Need help?

Browse our help center and FAQ, or write to our team — support in French, English and Arabic.