ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
aaPanel / BaoTa

aaPanel Security Hardening Guide: Change Panel Port and Security Entrance, Authorized IPs, SSH Protection and Closing Unused Ports

6 steps 12 min read 5 views 0
On this page

aaPanel (BaoTa) makes server management easy, but the panel is also a favourite target for attackers: a default port, a weak password or an outdated version can all lead to a compromise. This guide collects practical aaPanel security settings — changing the panel port and security entrance, restricting authorized IPs, hardening SSH, updating promptly and closing unused ports — for Debian/Ubuntu and CentOS/Rocky/AlmaLinux servers running aaPanel / BaoTa.

When changing ports, IP restrictions or SSH settings, keep your current SSH session open and verify the new settings from a second window before disconnecting. If you lock yourself out, use the VNC console in the client area (log in → My Products & Services → select the server → Manage).

Step 1: Change the aaPanel port

Choose an unused high port (for example 23456) and open it in the firewall first. Check that it is free:

ss -tlnp | grep 23456

Open the new port on Debian / Ubuntu:

ufw allow 23456/tcp

Open the new port on CentOS / Rocky / AlmaLinux:

firewall-cmd --permanent --add-port=23456/tcp && firewall-cmd --reload

Then change "Panel port" under the panel's Settings and save. Alternatively, run bt over SSH and choose the "change panel port" item (menu numbers differ between versions, so read the menu). Log in on the new port to confirm it works.

Step 2: Use a strong security entrance and password

The security entrance is the path after the panel address; only people who know the full path can see the login page. In Settings, change it to a long random string (12+ mixed letters and digits), change the panel username and use a password of 16+ characters. If possible, enable the built-in two-factor authentication (Google Authenticator) and panel SSL so the panel is served over HTTPS and credentials cannot be sniffed. You can view the current entrance details at any time:

bt default

Step 3: Restrict aaPanel to authorized IPs

If your office or home connection has a static IP, fill in "Authorized IP" in the panel Settings so only those addresses can reach the panel and everything else is rejected. This is one of the most effective protections against brute-force attacks on the panel.

If your IP changes and you lock yourself out, run bt over SSH and choose the "cancel IP access restriction" menu item, then set the restriction again.

Step 4: Harden SSH — new port, key login and Fail2ban

Generate a key on your local computer and copy it to the server (Windows 10/11 PowerShell includes ssh-keygen too):

ssh-keygen -t ed25519
ssh-copy-id [email protected]

After confirming key-based login works, edit /etc/ssh/sshd_config and set the following (port 22022 as an example — open it in the firewall first):

Port 22022
PermitRootLogin prohibit-password
PasswordAuthentication no
MaxAuthTries 3

Check the syntax and restart SSH (the service is named ssh on Debian / Ubuntu and sshd on CentOS / Rocky / AlmaLinux):

sshd -t && systemctl restart ssh
sshd -t && systemctl restart sshd

With SELinux enabled on Rocky / AlmaLinux, allow the new port first: semanage port -a -t ssh_port_t -p tcp 22022. On Ubuntu 22.10 and later with socket activation, also run systemctl daemon-reload && systemctl restart ssh.socket after changing the port.

Finally, install Fail2ban to ban IPs that keep failing to log in:

apt install -y fail2ban
dnf install -y epel-release && dnf install -y fail2ban

Create /etc/fail2ban/jail.local with the following content, then run systemctl enable --now fail2ban:

[sshd]
enabled = true
port = 22022
maxretry = 5
bantime = 3600

The panel's "Security" menu can also change the SSH port and disable password login with the same effect.

Step 5: Keep the OS and aaPanel up to date

Vulnerabilities in the panel and system packages are fixed regularly, so update often. Click update whenever the panel home page shows a new version, and update the OS:

apt update && apt upgrade -y
dnf update -y

Install only the plugins and software you actually need, and stop or uninstall unused ones (such as phpMyAdmin or FTP) to reduce the attack surface.

Step 6: Close ports you do not need

List the ports currently listening and confirm each one is required:

ss -tlnp

Usually only 80, 443, your SSH port and the panel port need to be public. Database ports such as MySQL 3306 or Redis 6379 should never be open to the internet. After changing the panel and SSH ports, remove the old firewall rules:

ufw delete allow 8888/tcp
ufw delete allow 22/tcp
firewall-cmd --permanent --remove-port=8888/tcp && firewall-cmd --reload

You can also manage allowed ports from the panel's "Security" menu and delete rules you no longer need.

FAQ

The panel will not open after changing its port.

The new port is most likely not open in the system firewall. Open it via SSH or the VNC console, or change the port back from the bt menu.

SSH refuses me after disabling password login.

Your key is not set up correctly. Log in via the VNC console, temporarily set PasswordAuthentication back to yes, restart SSH, upload your public key again and then disable passwords.

Does the panel need to run all the time?

If you rarely use it, stop it with /etc/init.d/bt stop when idle and start it when needed. Your websites keep running and the risk drops further.

If you run into problems or suspect the server has been compromised, submit a ticket to IMIDC 24/7 technical support and we will help you investigate.

Was this answer helpful?

Related Tutorials