Skip to content

Strato VPS Host

Server Details

Property Value
Provider Strato VPS
Public IP 217.154.228.231
OS Debian 13 (Trixie)
Admin User admin
SSH Access VPN-only (10.0.0.1 via strato-host tunnel)

Installed Software

Software Version Purpose
Docker CE 27+ Container runtime
Docker Compose v2 Container orchestration
WireGuard Latest VPN tunnels
UFW Latest Host firewall
KVM/libvirt Latest VM hypervisor
fail2ban Latest Intrusion prevention

Directory Structure

/home/admin/
├── docker/
│   ├── control-center/        # Control Center (new, active)
│   │   ├── app/               # FastAPI application
│   │   ├── data/              # rules.json, audit.jsonl
│   │   ├── Dockerfile
│   │   └── docker-compose.yml
│   ├── vm-firewall/           # Old Control Center (backup)
│   ├── infrastructure/
│   │   ├── traefik/
│   │   │   ├── traefik.yml           # Static config
│   │   │   ├── dynamic/
│   │   │   │   ├── middlewares.yml    # BasicAuth, IP whitelist
│   │   │   │   └── vm-services.yml   # VM routes (managed by CC)
│   │   │   ├── acme.json             # Let's Encrypt certs
│   │   │   └── docker-compose.yml
│   │   ├── pihole/
│   │   │   └── docker-compose.yml
│   │   └── fail2ban-dashboard/
│   │       └── docker-compose.yml
│   └── .env                   # Shared environment variables

WireGuard Configuration

Server-side configs are at /etc/wireguard/:

Config File Interface Listen Port
strato-host.conf strato-host 51820
strato-vm.conf strato-vm 51821
openclaw-ai.conf openclaw-ai 51822

All interfaces are managed by wg-quick and enabled at boot via systemd:

sudo systemctl enable wg-quick@strato-host
sudo systemctl enable wg-quick@strato-vm
sudo systemctl enable wg-quick@openclaw-ai

UFW Rules

sudo ufw status
# Status: active
# 80/tcp        ALLOW   Anywhere
# 443/tcp       ALLOW   Anywhere
# 51820/udp     ALLOW   Anywhere
# 51821/udp     ALLOW   Anywhere
# 51822/udp     ALLOW   Anywhere

SSH (port 22) is allowed only from VPN subnets via UFW rules or AllowedIPs.

Mail Port Forwarding (DNAT)

Mail ports are forwarded from the host to the KVM VM using persistent DNAT rules in /etc/ufw/before.rules:

Port Protocol Service Destination
25 TCP SMTP 192.168.10.10:25
143 TCP IMAP 192.168.10.10:143
587 TCP SMTP Submission 192.168.10.10:587
993 TCP IMAPS 192.168.10.10:993

The rules consist of two parts in /etc/ufw/before.rules:

  1. *nat table — DNAT rules that redirect incoming traffic to the VM
  2. *filter table (ufw-before-forward chain) — FORWARD rules that allow the DNATed traffic through

Fail2ban jails (postfix and dovecot) are active on the host to protect against brute-force attacks on mail services.

SSH Configuration

Key hardening measures in /etc/ssh/sshd_config:

  • PasswordAuthentication no
  • PermitRootLogin no
  • PubkeyAuthentication yes
  • ListenAddress 10.0.0.1 (VPN only)

Connecting

# Connect via VPN
sudo wg-quick up vpn_host

# SSH to host
ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key admin@10.0.0.1