Start typing to search across invoices, services, domains, tickets, and more...
aaPanel (BaoTa) makes server management easy, but the panel is also a favourite target for attackers: a default port, a weak password or an outdated version can all lead to a compromise. This guide collects practical aaPanel security settings — changing the panel port and security entrance, restricting authorized IPs, hardening SSH, updating promptly and closing unused ports — for Debian/Ubuntu and CentOS/Rocky/AlmaLinux servers running aaPanel / BaoTa.
Choose an unused high port (for example 23456) and open it in the firewall first. Check that it is free:
ss -tlnp | grep 23456
Open the new port on Debian / Ubuntu:
ufw allow 23456/tcp
Open the new port on CentOS / Rocky / AlmaLinux:
firewall-cmd --permanent --add-port=23456/tcp && firewall-cmd --reload
Then change "Panel port" under the panel's Settings and save. Alternatively, run bt over SSH and choose the "change panel port" item (menu numbers differ between versions, so read the menu). Log in on the new port to confirm it works.
The security entrance is the path after the panel address; only people who know the full path can see the login page. In Settings, change it to a long random string (12+ mixed letters and digits), change the panel username and use a password of 16+ characters. If possible, enable the built-in two-factor authentication (Google Authenticator) and panel SSL so the panel is served over HTTPS and credentials cannot be sniffed. You can view the current entrance details at any time:
bt default
If your office or home connection has a static IP, fill in "Authorized IP" in the panel Settings so only those addresses can reach the panel and everything else is rejected. This is one of the most effective protections against brute-force attacks on the panel.
bt over SSH and choose the "cancel IP access restriction" menu item, then set the restriction again.Generate a key on your local computer and copy it to the server (Windows 10/11 PowerShell includes ssh-keygen too):
ssh-keygen -t ed25519
ssh-copy-id [email protected]
After confirming key-based login works, edit /etc/ssh/sshd_config and set the following (port 22022 as an example — open it in the firewall first):
Port 22022
PermitRootLogin prohibit-password
PasswordAuthentication no
MaxAuthTries 3
Check the syntax and restart SSH (the service is named ssh on Debian / Ubuntu and sshd on CentOS / Rocky / AlmaLinux):
sshd -t && systemctl restart ssh
sshd -t && systemctl restart sshd
With SELinux enabled on Rocky / AlmaLinux, allow the new port first: semanage port -a -t ssh_port_t -p tcp 22022. On Ubuntu 22.10 and later with socket activation, also run systemctl daemon-reload && systemctl restart ssh.socket after changing the port.
Finally, install Fail2ban to ban IPs that keep failing to log in:
apt install -y fail2ban
dnf install -y epel-release && dnf install -y fail2ban
Create /etc/fail2ban/jail.local with the following content, then run systemctl enable --now fail2ban:
[sshd]
enabled = true
port = 22022
maxretry = 5
bantime = 3600
The panel's "Security" menu can also change the SSH port and disable password login with the same effect.
Vulnerabilities in the panel and system packages are fixed regularly, so update often. Click update whenever the panel home page shows a new version, and update the OS:
apt update && apt upgrade -y
dnf update -y
Install only the plugins and software you actually need, and stop or uninstall unused ones (such as phpMyAdmin or FTP) to reduce the attack surface.
List the ports currently listening and confirm each one is required:
ss -tlnp
Usually only 80, 443, your SSH port and the panel port need to be public. Database ports such as MySQL 3306 or Redis 6379 should never be open to the internet. After changing the panel and SSH ports, remove the old firewall rules:
ufw delete allow 8888/tcp
ufw delete allow 22/tcp
firewall-cmd --permanent --remove-port=8888/tcp && firewall-cmd --reload
You can also manage allowed ports from the panel's "Security" menu and delete rules you no longer need.
The new port is most likely not open in the system firewall. Open it via SSH or the VNC console, or change the port back from the bt menu.
Your key is not set up correctly. Log in via the VNC console, temporarily set PasswordAuthentication back to yes, restart SSH, upload your public key again and then disable passwords.
If you rarely use it, stop it with /etc/init.d/bt stop when idle and start it when needed. Your websites keep running and the risk drops further.
If you run into problems or suspect the server has been compromised, submit a ticket to IMIDC 24/7 technical support and we will help you investigate.