The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Protect a Vultr server by installing an SSH public key during deployment, allowing only the inbound ports its actual role needs, and keeping YouTube’s stream key private. The right firewall rules depend on whether Vultr runs the encoder, a relay, or another service: a computer that sends RTMPS directly to YouTube does not, by that fact alone, need a public inbound RTMP port.
This guide uses Ubuntu with UFW for the host-firewall examples. Vultr Cloud Compute can run other operating systems and firewall tools, so do not apply UFW commands to a different system. First identify what runs on the instance and keep Vultr console access available as a recovery path.
Decide what the Vultr server actually does
Before opening ports, name the operating system, the software running on the instance, and the machine that encodes the video. Vultr’s OBS-on-Ubuntu guide is an example deployment, not a requirement that every YouTube stream be encoded on a server (Vultr’s OBS and Ubuntu guide).
| Topology | Typical network direction | Firewall implication |
|---|---|---|
| A local computer encodes and sends directly to YouTube | Inbound SSH to Vultr for administration; outbound RTMPS from the encoder to YouTube | No public inbound RTMP port is needed on Vultr merely because the stream is for YouTube. |
| Vultr runs the encoder | Inbound SSH for administration; outbound RTMPS from the instance to YouTube | Allow only the inbound services the instance actually provides. YouTube’s outbound connection does not establish a need for an inbound RTMP listener. |
| Vultr runs an RTMP relay, ingest service, or control panel | Depends on the relay or application and its clients | Identify the software’s required listener ports and intended client addresses before writing rules. There is no universal port list for every setup. |
Keep two connections distinct: SSH is inbound administrative access to the Vultr host. YouTube RTMPS is generally an outbound connection from the encoder to YouTube. YouTube’s RTMPS setup guidance does not say to expose an inbound RTMP service on your server.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Install and test an SSH key
An SSH key pair has a private key, which stays on your workstation or secure key store, and a public key, which you install on the server. Vultr documents generating a key on the workstation, selecting its public key during deployment, and connecting with SSH while specifying the private key (Vultr’s SSH connection guide, updated 26 May 2026).
- Create a key pair on your workstation. Use your operating system’s trusted SSH-key tool. Protect the private key with appropriate file permissions and, where supported, a passphrase. Do not send or publish the private key.
- Add the public key during Vultr deployment. Select or provide the public key as part of the instance setup, then note the server’s address and the account name supplied for your image.
- Connect using the matching private key. A typical OpenSSH pattern is
ssh -i /path/to/private_key username@SERVER_IP. Replace the path, account name, and address with your actual values; do not paste a private-key value into a command or article. - Test a second login before changing access rules. Keep your existing administrative session open while confirming the key-based connection works. Do not close your recovery path until the new one is verified.
Important for existing instances: Vultr warns that adding an SSH key through its console after deployment can reinstall the instance and cause data loss. Do not use that operation casually on a running server. Back up required data and follow Vultr’s documented recovery or reinstallation process if you need to recover access.
Allow only the inbound ports the architecture needs
For Ubuntu, UFW is one host-level firewall option. Vultr’s firewall quickstart demonstrates allowing SSH before enabling UFW and using a default-deny incoming policy (Vultr’s firewall quickstart, updated 21 November 2023). Start by inspecting the active state and existing rules:
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
sudo ufw status verbose
Confirm the SSH port your server actually uses. If it is the usual port 22, the following example permits it before setting the default policies. If you have changed SSH to another port, allow that port instead; do not enable UFW while the actual SSH port is blocked.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemssudo ufw allow 22/tcp
sudo ufw default deny incoming
sudo ufw default allow outgoing
sudo ufw enable
sudo ufw status verbose
Adapt this order to existing rules and your recovery channel. Have a second SSH session or Vultr console access ready before enabling or tightening the firewall. Vultr’s troubleshooting guidance notes that UFW changes can interrupt remote access and describes console recovery if SSH is lost (Vultr firewall troubleshooting).
- Allow HTTP or HTTPS only if the instance actually serves a web site, control panel, or other web service on those ports.
- Allow a streaming or relay port only if the selected software listens for inbound clients on it, and restrict the allowed source addresses when practical.
- Do not add inbound RTMP just because your encoder sends a stream to YouTube. That is a separate network direction.
- Check the installed system’s firewall tooling before using commands: Vultr documents different tools across operating systems, including firewalld, IPFW, pf, nftables, and Windows Firewall. UFW commands here are specifically for Ubuntu.
A host firewall and a provider/network firewall are separate control points: one is configured on the operating system; the other, if used, is configured outside it. The cited Vultr guidance here covers operating-system firewall behavior, so verify the settings and recovery behavior in your own Vultr account before relying on a provider-level rule.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Restrict SSH to trusted addresses when practical
A rule that permits SSH from any source is easier to use when your public IP changes, but it exposes the SSH service to connection attempts from everywhere. If you have a stable, known public IP and your workflow allows it, Vultr recommends restricting SSH to trusted IP addresses (Vultr’s UFW guide for Ubuntu). For example, replace the broad SSH allowance with a source-specific rule such as:
sudo ufw allow from YOUR_TRUSTED_PUBLIC_IP to any port 22 proto tcp
Use your real public source address and actual SSH port. A residential address that changes, a mobile connection, or travel can make a strict allowlist block your next login. Before removing any broader rule, test from the permitted address and confirm console recovery is available.
Should you change SSH’s port?
Changing the default port can reduce automated connection attempts, but it is not a substitute for key authentication, updates, source restrictions, or a least-exposure firewall. Vultr’s SSH production-practices guidance treats a port change as one measure rather than a complete security control (Vultr SSH production practices). If you change it, allow the new TCP port in the firewall before restarting SSH, test a new connection on that port, and only then remove the old allowance.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Send the YouTube stream over RTMPS and protect its key
YouTube describes RTMPS as RTMP secured with TLS/SSL and directs creators to copy the RTMPS URL and stream key from Live Control Room into an RTMPS-capable encoder (YouTube Help: Encrypt your stream using RTMPS). Use the exact endpoint and key shown for your stream; do not substitute an inbound port on Vultr for YouTube’s destination.
- In YouTube Live Control Room, retrieve the RTMPS URL and the stream key for the intended live stream.
- Enter those values in the encoder’s RTMPS server and stream-key fields, following that encoder’s own instructions.
- If SSL troubleshooting requires it, YouTube says port 443 can be specified. This is an outbound encoder-to-YouTube connection setting, not a reason by itself to open inbound port 443 on Vultr.
- Test before the scheduled stream and monitor stream health. YouTube recommends RTMPS and pre-event testing; stream quality still depends on encoder configuration and available upload capacity (YouTube RTMPS guidance; YouTube encoder guidance).
Treat the stream key like a password. YouTube says stream keys are like a stream’s “password and address” (YouTube Help: Manage live stream settings). Keep it out of screenshots, public configuration files, source repositories, and logs that others can read. If you suspect it was exposed, reset it in Live Control Room and update the encoder with the replacement key.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Troubleshoot the common lockouts and connection failures
| Symptom | Likely cause | What to check or do |
|---|---|---|
| SSH stopped working after enabling UFW | The active SSH port was not allowed, or the source-IP rule does not match your current address. | Use Vultr console access to inspect sudo ufw status verbose and add the correct SSH allowance. Test a fresh SSH session before closing console access. |
| SSH works at home but not while travelling | A trusted-IP rule permits only the previous network’s public address. | Use the recovery console, update the allowlist for your current trusted address, and test before removing any temporary access rule. |
| Encoder cannot connect to YouTube | The encoder may be using the wrong endpoint or key, lack RTMPS support, or have an outbound connectivity issue. | Recheck the RTMPS URL and key in Live Control Room and the encoder settings. If SSL troubleshooting calls for it, try YouTube’s port 443 guidance; this does not imply opening a public inbound listener. |
| Stream fails after a key was shared or logged | The stream credential may have been exposed. | Reset the stream key in YouTube Live Control Room and replace the saved key in the encoder. |
| Stream connects but quality is poor or unstable | Firewall hardening does not ensure encoding quality or enough upload capacity. | Review the encoder configuration and available upload capacity, test before going live, and monitor YouTube stream health. |
Or let it run in the cloud
If your goal is to keep a pre-recorded YouTube stream running 24/7, StreamNeo is a separate option from hardening a Vultr server: upload a recording or build a playlist, add your YouTube stream key once, and go live. It loops uploaded videos from the cloud, so no computer or home connection has to stay on. It is for YouTube and uploaded video, not a live camera feed.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
- Each slot streams the uploaded file as made, up to 4K 60fps, at one flat price per slot without re-encoding or quality tiers.
- Automatic recovery if YouTube drops the stream; each slot includes 10 GB storage, pooled across active slots.
- The first day is free with no card, one free day per account; billing options range from a day to a year and can be cancelled any time.
Monthly: $9.99 per month. See StreamNeo or its pricing page for plan details. Start the free first day with StreamNeo.
Frequently Asked Questions
Does a YouTube stream require an inbound RTMP port on my Vultr server?
Not when the encoder sends RTMPS directly to YouTube. An inbound streaming port is relevant only if your chosen server software actually listens for an incoming relay or ingest connection.
Can I use these UFW commands on Windows or another Linux distribution?
No. The commands shown are for Ubuntu with UFW; other operating systems use different firewall tools and procedures.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

