4 min read Sep 26, 2026

First Steps After Your Unmanaged VPS Is Ready

A checklist for a brand-new Unmanaged VPS: find your IP and root password, log in over SSH, install updates, set the hostname and time zone, then secure the server.

FimuroHost Team

FimuroHost Team

Technical Writer

Share Article

Your new VPS is a clean server with nothing on it except the operating system you chose. The first 20 minutes are the most important: a fresh server with a password-only root login is scanned by automated bots within hours of going online.

Work through the steps below in order. Commands are shown for Ubuntu 24.04 / 22.04, Debian 12 and AlmaLinux / Rocky Linux 9.

Which VPS is this for? These steps are for an Unmanaged VPS, where you log in as root and look after the server yourself. On a Managed VPS we take care of the operating system and server software, and you manage your websites in StackCP instead.

Step 1: Find your IP address and login details

  1. Log in to your FimuroHost client area.
  2. Open Services and click your VPS.
  3. Note the IP address, the username (normally root on Linux) and the password.

The same details are in the welcome email sent when the VPS was created. Search your inbox (and spam folder) for it. If the password is not shown anywhere, open a support ticket and we will help you get access.

Step 2: Log in over SSH

On Windows 10/11, open Terminal or PowerShell. On macOS or Linux, open Terminal. Replace the example IP with yours:

ssh [email protected]

Type yes when asked to confirm the server's fingerprint, then paste the password. Nothing appears on screen while you type or paste a password; that is normal. For PuTTY and troubleshooting, see How to Connect to Your VPS as Root with SSH.

Step 3: Change the root password

The password in your welcome email has travelled by email, so replace it with a new, long one (a password manager helps):

passwd

Step 4: Install all updates

Images can be a few weeks old, so bring every package up to date before you install anything else.

Ubuntu and Debian

apt update
apt upgrade -y

AlmaLinux and Rocky Linux

dnf upgrade -y

If a new kernel was installed, reboot so it takes effect. To check whether a reboot is needed:

# Ubuntu / Debian: prints the file name if a reboot is required
ls /var/run/reboot-required

# AlmaLinux / Rocky
dnf needs-restarting -r

Then run reboot, wait a minute, and log in again.

Step 5: Set the hostname

The hostname is the server's own name. Use a sub-domain you control, such as server1.example.com. It matters if you plan to send email from the server or install a control panel.

hostnamectl set-hostname server1.example.com
hostnamectl

On Ubuntu and Debian, also add the name to /etc/hosts so the server can resolve itself. Open the file with nano /etc/hosts and add a line like:

127.0.1.1   server1.example.com   server1

Tip: if the hostname changes back after a reboot, cloud-init is resetting it. Add preserve_hostname: true to /etc/cloud/cloud.cfg and set the hostname again.

Later, create an A record for server1.example.com pointing at your VPS IP. See How to Point Your Domain to Your VPS.

Step 6: Set the time zone

Logs, cron jobs and scheduled backups all use the server time zone. For Bangladesh:

timedatectl set-timezone Asia/Dhaka
timedatectl

Check that System clock synchronized says yes. Many administrators prefer to keep servers on UTC and convert times when reading logs; either choice is fine, just be consistent. List all zones with timedatectl list-timezones.

Step 7: Install a few handy tools

# Ubuntu / Debian
apt install -y curl wget nano htop unzip

# AlmaLinux / Rocky (htop comes from the EPEL repository)
dnf install -y epel-release
dnf install -y curl wget nano htop unzip

Step 8: Secure the server

Do these next, in this order:

  1. Create a sudo user and disable root login
  2. Switch to SSH key login
  3. Turn on a firewall
  4. Install Fail2ban
  5. Enable automatic security updates
  6. Plan your backups

Common problems

  • Connection timed out right after ordering: the VPS may still be building. Wait five minutes and try again. Check the service shows as Active in your client area.
  • Permission denied: the password was mistyped. Copy it carefully without leading or trailing spaces, or type it by hand.
  • WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED: you connected to this IP before (for example before a reinstall). Remove the old entry with ssh-keygen -R 203.0.113.10 and connect again.

Need help?

If something about the VPS itself is not working (it won't start, you can't reach it, or you need console access, an upgrade or a reinstall), open a support ticket from your client area or message us on WhatsApp at 01818160926. Include your VPS IP address and what you have already tried so we can help faster.

Categories

FimuroHost Team

Written by

FimuroHost Team

Technical Writer