VPS ใหม่ที่เพิ่ง deploy มักมาพร้อมค่า default ที่ไม่ปลอดภัย เช่น เปิด root login, ใช้ password แทน key, ไม่มี firewall Server Hardening คือขั้นตอนปิดช่องโหว่เหล่านี้อย่างเป็นระบบก่อนที่ production traffic จะเข้ามา — ใช้เวลาไม่เกิน 30 นาที แต่ป้องกันปัญหาระยะยาวได้มาก
ทำไม Server Hardening ถึงสำคัญ
Bot ที่ scan port 22 (SSH) ทั่วอินเทอร์เน็ตทำงานตลอด 24 ชั่วโมง VPS ใหม่ที่ไม่ได้ Harden จะถูก Brute Force ภายในไม่กี่ชั่วโมงหลัง deploy สถิติจาก Shodan แสดงว่า VPS ที่เปิด root login และ password authentication จะถูกพยายาม login นับพัน - หมื่นครั้งต่อวัน
- ลด Attack Surface — ปิด port และ service ที่ไม่ใช้
- ป้องกัน Brute Force — ใช้ SSH Key + Fail2Ban
- รับ Security Patch อัตโนมัติ — unattended-upgrades
- จำกัดสิทธิ์ — ไม่ใช้ root โดยตรง ใช้ sudo แทน
ขั้นที่ 1 — อัปเดตระบบก่อนทำอย่างอื่น
sudo apt update && sudo apt upgrade -y
sudo apt autoremove -y
อัปเดตทันทีหลัง deploy เพราะ image บน cloud provider อาจเก่าหลายเดือน
ขั้นที่ 2 — สร้าง Non-root User
# สร้าง user ใหม่
sudo adduser deployer
# เพิ่มเข้า sudo group
sudo usermod -aG sudo deployer
# ทดสอบ sudo
su - deployer
sudo whoami # ต้องได้ "root"
หลังสร้าง user แล้ว login ผ่าน user ใหม่แทน root ทั้งหมดตั้งแต่นี้
ขั้นที่ 3 — SSH Key Authentication
สร้าง Key Pair บนเครื่องของคุณ (ไม่ใช่บน VPS)
# Ed25519 ปลอดภัยและเร็วกว่า RSA
ssh-keygen -t ed25519 -C "[email protected]"
# กด Enter 2 ครั้ง หรือใส่ passphrase
วาง Public Key บน VPS
# วิธีที่ 1: ssh-copy-id (ง่ายที่สุด)
ssh-copy-id -i ~/.ssh/id_ed25519.pub deployer@YOUR_VPS_IP
# วิธีที่ 2: Manual
cat ~/.ssh/id_ed25519.pub | ssh deployer@YOUR_VPS_IP "mkdir -p ~/.ssh && cat >> ~/.ssh/authorized_keys && chmod 600 ~/.ssh/authorized_keys"
ทดสอบ Key Login
ssh -i ~/.ssh/id_ed25519 deployer@YOUR_VPS_IP
# ต้องเข้าได้โดยไม่ถามรหัสผ่าน
สำคัญ: ทดสอบ SSH Key login ให้ได้ก่อนทำขั้นต่อไป อย่า Disable password auth ก่อนที่จะยืนยันว่า Key ทำงานได้ มิฉะนั้นอาจ lock ตัวเองออกจาก VPS
ขั้นที่ 4 — Harden SSH Config
sudo nano /etc/ssh/sshd_config
แก้ไขหรือเพิ่มบรรทัดต่อไปนี้:
# ปิด Root Login
PermitRootLogin no
# ปิด Password Authentication (ใช้ Key เท่านั้น)
PasswordAuthentication no
PubkeyAuthentication yes
# จำกัด Login Attempts
MaxAuthTries 3
MaxSessions 5
# Timeout การเชื่อมต่อที่ไม่ Active
ClientAliveInterval 300
ClientAliveCountMax 2
# เปลี่ยน Port (Optional — ลด Bot Scan แต่ไม่ใช่ Security จริง)
# Port 2222
# อนุญาตเฉพาะ User ที่กำหนด
AllowUsers deployer
# Restart SSH หลังแก้ config
sudo systemctl restart sshd
ขั้นที่ 5 — ตั้งค่า UFW Firewall
# ติดตั้ง UFW (มาใน Ubuntu แล้ว)
sudo apt install ufw -y
# ค่า default: block incoming, allow outgoing
sudo ufw default deny incoming
sudo ufw default allow outgoing
# อนุญาต SSH (ก่อนเปิด UFW เสมอ)
sudo ufw allow 22/tcp
# ถ้าเปลี่ยน SSH port: sudo ufw allow 2222/tcp
# อนุญาต Web (ถ้ารัน web server)
sudo ufw allow 80/tcp
sudo ufw allow 443/tcp
# เปิด UFW
sudo ufw enable
# ตรวจสอบ status
sudo ufw status verbose
UFW App Profiles
# ดู App profiles ที่มี
sudo ufw app list
# ใช้ profile แทน port
sudo ufw allow 'Nginx Full' # 80+443
sudo ufw allow 'OpenSSH' # 22
ขั้นที่ 6 — ติดตั้ง Fail2Ban
Fail2Ban ตรวจ Log และ Ban IP ที่พยายาม Login ผิดหลายครั้งโดยอัตโนมัติ
sudo apt install fail2ban -y
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
สร้าง Local Config (ไม่แก้ไฟล์หลัก)
sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local
sudo nano /etc/fail2ban/jail.local
แก้ไขส่วน [sshd]:
[sshd]
enabled = true
port = ssh
filter = sshd
logpath = /var/log/auth.log
maxretry = 3
bantime = 3600 # ban 1 ชั่วโมง
findtime = 600 # ใน 10 นาที
sudo systemctl restart fail2ban
# ดู banned IPs
sudo fail2ban-client status sshd
ขั้นที่ 7 — Automatic Security Updates
sudo apt install unattended-upgrades -y
sudo dpkg-reconfigure --priority=low unattended-upgrades
# เลือก Yes
ตั้งค่าให้ Auto-reboot เมื่อจำเป็น (Optional)
sudo nano /etc/apt/apt.conf.d/50unattended-upgrades
ค้นหาและ uncomment:
Unattended-Upgrade::Automatic-Reboot "true";
Unattended-Upgrade::Automatic-Reboot-Time "03:00";
ขั้นที่ 8 — ลบ Service ที่ไม่ใช้
# ดู Service ที่รันอยู่
sudo systemctl list-units --type=service --state=running
# ปิด Service ที่ไม่ต้องการ (ตัวอย่าง)
sudo systemctl disable --now snapd
sudo systemctl disable --now avahi-daemon
sudo systemctl disable --now cups
# ดู Port ที่เปิดอยู่
sudo ss -tlnp
ขั้นที่ 9 — ตั้งค่า sysctl Security Parameters
sudo nano /etc/sysctl.d/99-hardening.conf
# ป้องกัน IP Spoofing
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
# ปิด ICMP Redirects
net.ipv4.conf.all.accept_redirects = 0
net.ipv6.conf.all.accept_redirects = 0
net.ipv4.conf.all.send_redirects = 0
# ป้องกัน SYN Flood
net.ipv4.tcp_syncookies = 1
net.ipv4.tcp_max_syn_backlog = 2048
# ปิด Source Packet Routing
net.ipv4.conf.all.accept_source_route = 0
net.ipv6.conf.all.accept_source_route = 0
sudo sysctl -p /etc/sysctl.d/99-hardening.conf
ขั้นที่ 10 — ตรวจสอบด้วย Lynis
Lynis คือ Security Audit Tool ที่ตรวจ Server แล้วให้คะแนนพร้อมคำแนะนำ
sudo apt install lynis -y
sudo lynis audit system
Lynis จะให้ Hardening Index คะแนน 0–100 พร้อม Suggestion สำหรับแก้ไข เป้าหมายคือ ≥65 สำหรับ Production Server ทั่วไป
เป้าหมายหลังทำ Hardening: SSH Key only · Root login disabled · UFW active · Fail2Ban running · Auto security updates · Lynis score ≥65 — ครบ 6 ข้อนี้ VPS ของคุณปลอดภัยกว่า VPS ส่วนใหญ่ที่ไม่ได้ผ่านการ harden
Checklist Server Hardening สรุป
| รายการ | ความสำคัญ | ใช้เวลา |
|---|---|---|
| อัปเดต System | Critical | 2 นาที |
| สร้าง Non-root User | Critical | 2 นาที |
| SSH Key + Disable Password | Critical | 5 นาที |
| UFW Firewall | High | 5 นาที |
| Fail2Ban | High | 5 นาที |
| Unattended Upgrades | High | 2 นาที |
| sysctl Hardening | Medium | 5 นาที |
| Lynis Audit | Medium | 10 นาที |
ต้องการ VPS Linux สำหรับ Harden?
AsiaGB มี VPS Ubuntu/Debian พร้อม Full Root Access เริ่มต้น 500 บาท/เดือน รองรับ Hardening ได้ทุกขั้นตอน
ดู VPS Plans