apt update && apt upgrade -y
useradd -m -s /bin/bash admin && usermod -aG sudo admin
ufw default deny incoming && ufw allow 2222/tcp 80/tcp 443/tcp && ufw enable
apt install fail2ban -y && systemctl enable --now fail2ban
Sysctl hardening: add tcp_syncookies, rp_filter, randomize_va_space to
/etc/sysctl.d/99-security.conf and apply: sysctl --system