Skip to content

Cookie settings

Choose which kinds of cookies you allow. You can change your choice at any time via Cookie settings at the bottom of every page. Privacy statement

Necessary

Always on

Needed to log in, keep your cart and remember your choices. These are always on.

Which cookies?
  • weboke_sessie, weboke_klant, weboke_remember: your session and staying logged in
  • weboke_basket: your cart
  • wkBtwIncl: showing prices with or without VAT
  • wok_cookies: your cookie choice, 12 months

Measures which ad leads to a visit or order, so we do not pay for ads that do nothing.

Which cookies?
  • Google Ads via Google Tag Manager (_gcl_au, _gcl_aw), up to 90 days
  • OpenAI Ads, ads in ChatGPT
  • wok_aff: which partner referred you to us (affiliate programme), 60 days

4.6

Country and language

Each country has its own site, with prices and VAT for that country.

View

Securing your VPS: the first five minutes

A new server on the internet is scanned within minutes by bots trying passwords. These steps keep you well ahead of them. Run them as root.

1. Update everything and enable automatic updates

  • Ubuntu and Debian: apt update && apt upgrade -y, then apt install -y unattended-upgrades and dpkg-reconfigure -plow unattended-upgrades.
  • AlmaLinux and Rocky Linux: dnf upgrade -y, then dnf install -y dnf-automatic and systemctl enable --now dnf-automatic-install.timer.

2. Log in with a key, passwords off

First put your SSH key on the server (see Logging in to your VPS with SSH) and test that logging in with the key works. Then set in /etc/ssh/sshd_config:

PasswordAuthentication no

and restart SSH with systemctl restart ssh (AlmaLinux and Rocky: systemctl restart sshd). Keep your current session open until you have checked in a second window that you can still get in.

3. A firewall

  • Ubuntu and Debian: apt install -y ufw, then ufw allow OpenSSH, optionally ufw allow 80,443/tcp for a website, and ufw enable.
  • AlmaLinux and Rocky Linux: firewalld is already there. For example firewall-cmd --permanent --add-service=http --add-service=https and firewall-cmd --reload.

Always keep SSH (port 22) open, or you will lock yourself out.

4. Fail2ban against guessing

apt install -y fail2ban or dnf install -y epel-release && dnf install -y fail2ban, then systemctl enable --now fail2ban. By default it blocks IP addresses that try wrong passwords too often.

5. A snapshot as a safety net

The Snapshots tab in the VPS screen

Take a snapshot in your VPS screen before making big changes. If something goes wrong, roll back in one click. See Snapshots and backups of your VPS.

Keep the qemu-guest-agent

The qemu-guest-agent program is installed by default. It lets you set a new root password from the VPS screen and shows disk usage. Do not remove it.

Was this article helpful?

← Back to VPS hosting

One moment…

Set up your domains

For each domain, arrange the nameservers, the link to your hosting and who becomes the owner.

Loading your domains…