October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
Redmond desk6 min

How to Reduce a Linux Server’s Attack Surface Without Breaking Services

Inventory Linux listeners, narrow access to needed services, and make reversible changes so you can reduce exposure without disrupting workloads.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Reduce a Linux server’s attack surface in stages: inventory what is listening, identify who genuinely needs to reach each service, narrow network access, and disable only services you have confirmed are unused. Check application health and re-inventory after every change. The commands below use Ubuntu’s UFW and AppArmor where noted; other distributions may use different firewall and security tools.

What counts as an unnecessary open port?

A listening port is not automatically a problem. The key questions are whether a service needs to accept network connections and whether it is exposed to more people or networks than necessary. Ubuntu Security Team defines an unnecessarily open port as one exposed to an untrusted network without need, or one that belongs to a service no longer in use. See Ubuntu’s guidance on unnecessarily open ports.

Reducing exposure does not always mean stopping a service. If an application needs a service, keep it running but restrict its binding address or the sources allowed to connect. A firewall rule can limit reachability while leaving the service available to approved clients.

1. Establish a baseline before changing anything

Record the server’s current listeners, expected application endpoints, service status, monitoring checks, and a recovery route such as console access. This gives you a comparison point and a way to detect an outage caused by a change.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
HPE ProLiant DL380 Gen10 2U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
  • HPE ProLiant DL380 Gen10 2U Rack Server with Rail kit for Enterprise
  • Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
  • Memory: 256GB (8 x 32GB) DDR4 PC4-25600 3200MHz Unbuffered Memory
  • Storage: 7.68TB (4 x 1.92TB) Enterprise 2.5” SATA III 6Gb/s SSDs for Ultra Fast Storage
  • Hard drives and memory upgrades included separately, not installed, installation required.

On Ubuntu and many Linux systems, ss can show listening TCP and UDP sockets:

ss -utln

With root access, add process information to help identify the owner of each listener:

sudo ss -utlnp

Review both IPv4 and IPv6 addresses. A service bound to 0.0.0.0, [::], or a wildcard may accept connections on more interfaces than intended; a loopback address is appropriate when only processes on the same host should connect. The output normally reflects the shell’s network namespace, so deployments using network namespaces may need an inventory for each relevant namespace. Ubuntu explains these checks in its open-port guidance.

Rank #2
Quiet Rackmount Computer (3.8-4.6GHz AMD Ryzen 7 5700G CPU, 32GB RAM, 1TB SSD, W11 Pro) - 2U Rack Mount Server or Workstation Desktop PC for Home or Business
  • [CPU] AMD Ryzen 7 5700G Processor (8 Cores, 16 Threads, 3.8 GHz Base Clock Speed up to 4.6 GHz Max Boost Clock Speed) for Gaming and Content Creation with 7nm Leading Edge Technology | [STORAGE] 1TB PCIe NVMe M.2 SSD - Experience Hyper-Fast Bootup and Data Transfer thats up to 30x Faster Performance than a Traditional Hard Drive.
  • Graphics: Integrated AMD Radeon Graphics | [RAM] 32GB DDR4 RAM 3200 Gaming Memory for Seamless Multitasking from Multiple Web Pages to Playing Games Online Simultaneously | [OS] Windows 11 Pro x64
  • 2x 3.5" Drive Bays | 4x Expansion Slots | mATX Motherboard | ATX PSU
  • [BUY WITH CONFIDENCE] Empowered PCs are Assembled in the USA, Rigorously Stress-Tested Before Shipping, and Supported with Lifetime Technical and Diagnostic Support and 3-Year Limited Hardware Warranty.

2. Decide what each listener needs

Do not infer purpose from a port number alone. Match each listening socket to its owning process, workload, documented callers, and operational dependencies. For each service, write down the intended clients, protocol and port, and network interface or address it should use.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Host-local only: If callers are on the same server, prefer a loopback bind where the application supports it.
  • Private-network access: Bind to the required private interface when practical, and permit only the networks that need the service.
  • Public access: Keep public reachability only when the workload requires it; specify the required protocols and ports rather than opening broad ranges.
  • Unknown purpose or owner: Investigate before changing it. Check service configuration, application documentation, dependencies, monitoring, and logs.

Ubuntu recommends avoiding wildcard binds when a narrower address works. Binding and firewall configuration are related but separate controls: changing a bind address can affect which interfaces accept connections, while firewall rules govern which traffic the host allows.

3. Restrict reachability before disabling services

If a service is required, first reduce who can reach it. Ubuntu’s documented default firewall frontend is UFW, and it is initially disabled in the documented setup. UFW is an Ubuntu-oriented example, not a universal Linux firewall interface; other distributions may use a different firewall manager. Avoid mixing firewall-management tools unless you understand which ruleset is active. See Canonical’s Ubuntu firewall documentation.

Rank #3
HPE ProLiant DL360 Gen10 1U Rack Server Bundle with Dual Xeon 6130 2.10 GHz, 256GB DDR4 Memory, 7.68TB Enterprise SSD Storage, RAID, Dual Power, iLO, Rail Kit
  • HPE ProLiant DL360 Gen10 1U Rack Server with Rail kit for small business or Enterprise
  • Dual (2) Xeon Gold 6130 16-Core 2.10 GHz, 22MB, Up To 3.70 GHz Turbo
  • Memory: 256GB (8 x 32GB) DDR4 PC4-25600 3200MHz Unbuffered Memory
  • Storage: 7.68TB (4 x 1.92TB) Enterprise 2.5” SATA III 6Gb/s SSDs for Ultra Fast Storage
  • Hard drives and memory upgrades included separately, not installed, installation required.

On Ubuntu, inspect the current state with:

sudo ufw status verbose

Before enabling a firewall on a remote server, add the management and workload rules the machine needs. Use the actual SSH port configured on that server—not an assumed default—and allow application ports only where required. For example, to permit SSH from one known management address, substitute the real address and port:

sudo ufw allow proto tcp from <management-address> to any port <ssh-port>

Preview a proposed rule where appropriate:

sudo ufw --dry-run allow <service-or-port>

When possible, keep a second SSH session open or use console access while applying firewall changes. Verify the resulting rules with sudo ufw status verbose and test access from the intended client networks. UFW also supports numbered rule inspection, which helps when reviewing or removing an existing rule.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Disable only services confirmed to be unused

A service should be stopped or disabled only after you have established that the workload and other services do not depend on it. Ubuntu cautions that disabling a systemd unit does not guarantee it cannot be started as a dependency of another enabled unit. Review dependencies before acting, and avoid bulk commands that disable services or remove packages based only on a port list.

Rank #4
MT-VIKI Rack Mount KVM Console w/15.6" LCD Monitor, 8 Port HDMI KVM Switch, 1920x1080@60Hz 1U Integrated Monitor Keyboard, Fits 18.9" to 31.5" Deep Racks (480-800mm), Included 8 Cables
  • MT-VIKI 1568HL is all-in-one console to manage up to 8 computers. Features a 15.6" LCD monitor with 1920x1080@60Hz resolution. Combines monitor, keyboard, and touchpad into a single 1U rackmount drawer to save up to 85% of valuable cabinet space.
  • Adjustable Depth & 2 set Rack Rails: Includes two sets of Rack Rails. Short Rack Rails: Fit 18.9"–23.6" (480-600mm) deep network racks (Note: check cable clearance for depths under 600mm). Long Rack Rails: Fit 23.6"–31.5" (600-800mm) deep standard racks. Measure your rack depth before purchase to ensure a perfect fit.
  • External Monitor Support & Flexible Operation--Features an HDMI console output for connecting an external monitor, allowing convenient server access without opening the rack. Three Ways Switching: Support OSD menu, Hot-key or push button switching.This 8 port lcd kvm console provides 2-level password security (administrator and user), up to 8 authorized users and an administrator view and control the computers
  • Lightweight Aluminum & Steel Build: Upgraded with an aluminum interior for less weight and a rugged steel drawer shell for industrial durability. Features a built-in handle and lock for secure operation. Physical Dimensions: 18.9" x 23.6" x 1.77" (480mm x 600mm x 45mm).
  • Built for Professional Environments – Ideal for server rooms, data centers, industrial control systems, and security monitoring centers where multiple computers need centralized management or when technicians need direct access to connected systems without an external monitor.

For a systemd-managed service confirmed to be unnecessary, Ubuntu documents stopping it and disabling it from starting automatically:

sudo systemctl stop <service>
sudo systemctl disable <service>

Use the actual unit name. Check its state after the change and confirm it remains stopped; then check listeners, application health checks, logs, and monitoring. Keep a record of the original service and firewall settings so you can roll back if a caller or dependency was missed.

5. Keep the controls that protect services still in use

Apply security updates with your release and repositories in mind

Updates reduce exposure to known vulnerabilities in services that remain enabled. Canonical documents unattended-upgrades as included by default on Ubuntu Server and Desktop beginning with Ubuntu 18.04 LTS, with daily security updates in the documented default configuration. The documentation describes defaults of 24 hours for security updates and seven days for normal updates; release, local configuration, and automatic-reboot behavior can vary. Review update logs and validate applications as part of maintenance. Third-party repositories and PPAs need separate configuration if their packages are to be included. See Canonical’s Ubuntu security-updates documentation and security-features overview for release-specific details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Lenovo ThinkSystem SR630 Rack Server Bundle with Rail Kit, 2 x Intel Xeon Silver 4110, 128GB DDR4, 8TB SSD, RAID (Renewed)
  • Lenovo ThinkSystem SR630 is your reliable, easy to manage, and scalable 1U rack server, designed to excel at running a wide range of applications for small businesses up to large enterprises; rail kit is included for easy server installation
  • Get professional-grade performance with Dual (2) Intel Xeon Silver 4110 8-Core 2.10GHz 11MB processors, with up to 3.2GHz turbo
  • Speed, quality and reliability with 128GB DDR4 memory; Keep your data safe with software RAID
  • Increase application performance, manage information more efficiently and store plenty of data with 8TB (4 x 2TB) 6Gb/s SATA III Solid State Drives
  • Connectivity: VGA; 3 x USB 3.0; 1 x USB 2.0; Network: 4 x 1GbE ports standard; 1 x 1GbE dedicated management port; Hard drives and memory upgrades included separately NOT installed, installation required.

Use application confinement where supported

On Ubuntu, AppArmor is the default mandatory access-control mechanism. Its profiles restrict an application’s capabilities and permissions. Where a supported profile is available, use complain mode to observe and log policy violations while testing the real workload; move to enforce mode only after the profile permits required behavior. Inspect policy logs when adjusting confinement, and prefer local profile adjustments over casually editing package-managed files. Ubuntu’s AppArmor guide explains profile use, while its privilege-restriction documentation discusses AppArmor and SELinux. Use the mandatory-access-control system supported by the target distribution and operations team.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

6. Verify each change and recover safely

Make one controlled change at a time, then compare the result with your baseline. A port disappearing from the public network is not proof that the application still works for its intended clients, and a successful local health check does not prove remote access remains correctly scoped.

  1. Check the service state and listener inventory again with the relevant service manager and ss.
  2. Run the application’s health checks and test expected access from the relevant client network or networks.
  3. Review service and firewall logs, plus monitoring alerts, for denied traffic or new failures.
  4. If an expected caller is blocked, restore the last known-good rule or service state, then identify the missed dependency before trying a narrower change.

Keep changes reversible and retain console or other recovery access during remote firewall work. Do not close every port, disable every listener, or apply a broad hardening profile to production without workload review.

Which approach fits the risk?

Control What it changes Best fit Main check
Narrow the bind address Which interfaces a service listens on A service needed only on loopback or a specific network interface Confirm all intended callers can still reach that address.
Restrict with a host firewall Which sources can reach a listening service A required service that should accept connections only from selected clients or networks Preserve management and workload access; use the firewall manager appropriate to the distribution.
Stop and disable a service Whether a service runs and starts automatically A service confirmed unused and not required as another unit’s dependency Check dependencies, unit state, listeners, application health, and monitoring.
Constrain with an application profile What an application can access or do under mandatory access control A workload with a supported profile and a test path for policy changes Observe behavior before enforcement and inspect policy logs.

For Ubuntu fleets with compliance requirements, Canonical documents Ubuntu Security Guide for benchmark-oriented hardening and audit reporting in applicable Ubuntu Pro contexts. It is an optional compliance workflow, not a substitute for testing workload behavior; details are in the Ubuntu compliance documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.