Set up fail2ban on Debian 13 with nftables: the Debian defaults, systemd journal backend, sshd and recidive jails, incremental bans and how to verify bans.
Run a secure web server: understand every config change, start from proven defaults, patch regularly and keep learning as new threats and exploits appear.