Put Cloudflare in front of your website
Proxy your site through Cloudflare: change nameservers, choose what to proxy, use Full (strict) SSL, restore visitor IPs in nginx or Apache, lock the origin.
- Intermediate
- 25 min read
- Updated
Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13
On this page
Cloudflare's reverse proxy sits between your visitors and your server: it serves cached files from locations near the visitor, filters malicious traffic and hides your server's real address. This guide puts a site on a HyperDC server behind Cloudflare without breaking HTTPS, logs or access control. Replace example.com and 203.0.113.10 with your values.
Before you start
- A Cloudflare account and your site working on the server, ideally already with HTTPS.
- Access to the domain's nameserver setting: for a HyperDC domain, Domains › My Domains › Manage Domain › Nameservers.
- A list of your current DNS records (website, mail, verifications), so nothing is lost in the move.
Step 1: Add the site to Cloudflare
In the Cloudflare dashboard, add example.com. Cloudflare scans your existing records; compare them with your list and add anything missing, especially MX, SPF, DKIM and DMARC records.
Step 2: Choose what to proxy
| Record | Proxy status |
|---|---|
A @ and A or CNAME www (website) | Proxied |
MX and the mail server's A record (mail) | DNS only |
| Records for SSH, FTP, game servers, VPN | DNS only |
| TXT (SPF, DKIM, DMARC, verifications) | Not proxied (TXT records are never proxied) |
If mail is sent from the same IP address as the website, the MX record reveals the server's address. Where you can, send mail from another host or IP.
Step 3: Change the nameservers
Cloudflare shows two nameservers for your zone. Enter them at your registrar; for a HyperDC domain choose Use custom nameservers (enter below), enter both and select Change Nameservers. If DNSSEC was enabled at the old DNS host, remove the old DS record first.
Verify: dig NS example.com +short returns the Cloudflare nameservers, and the Cloudflare dashboard shows the zone as active.
Step 4: Set SSL/TLS to Full (strict)
In SSL/TLS › Overview, choose Full (strict). Your server needs a valid certificate for that:
- A public certificate (for example Let's Encrypt) keeps working, and the site also works without Cloudflare.
- A Cloudflare Origin CA certificate (in SSL/TLS › Origin Server) is trusted only by Cloudflare and can be valid for many years. Install it like any certificate; see install an SSL certificate.
Avoid Flexible: it sends traffic from Cloudflare to your server unencrypted, and if your server redirects HTTP to HTTPS, visitors end up in a redirect loop.
Step 5: Restore the visitor's IP address
Behind the proxy, every request comes from a Cloudflare address. Tell your web server to take the real address from the CF-Connecting-IP header, trusting only Cloudflare's ranges (listed on Cloudflare's IP ranges page).
nginx
Create /etc/nginx/conf.d/cloudflare-realip.conf with one set_real_ip_from line per Cloudflare range:
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
real_ip_header CF-Connecting-IP;Add every range from the list, including the IPv6 ranges, then sudo nginx -t and sudo systemctl reload nginx.
Apache
Enable the module and add the trusted ranges:
sudo a2enmod remoteipRemoteIPHeader CF-Connecting-IP
RemoteIPTrustedProxy 173.245.48.0/20
RemoteIPTrustedProxy 103.21.244.0/22Add every range from the list, use %a instead of %h in your LogFormat, then sudo apachectl configtest and sudo systemctl reload apache2.
Verify: after visiting the site, the newest line in the access log shows your own IP address, not a Cloudflare one. Cloudflare changes its ranges occasionally; review them from time to time.
Step 6: Allow web traffic only from Cloudflare
If attackers find your server's IP address, they can bypass the proxy. With UFW, allow ports 80 and 443 only from Cloudflare's ranges and remove the general rule:
for ip in $(curl -s https://www.cloudflare.com/ips-v4) $(curl -s https://www.cloudflare.com/ips-v6); do sudo ufw allow proto tcp from "$ip" to any port 80,443; done
sudo ufw delete allow 80,443/tcp
sudo ufw status numberedKeep SSH allowed as before. Re-run the loop when Cloudflare publishes new ranges.
Caching basics
Cloudflare caches static files (images, CSS, JavaScript) by default and respects your Cache-Control headers. HTML pages are not cached unless you add a cache rule. After a deployment, use Caching › Configuration › Purge Cache if visitors see old files.
Troubleshooting
Error 521 (web server is down). Your server refused Cloudflare's connection: the web server is stopped, or the firewall does not allow Cloudflare's ranges.
Error 522 or 524 (timeouts). The server did not answer in time; check its load and logs. See website 502, 503 and 504 errors.
Error 525 or 526 (SSL). The handshake with the server failed, or its certificate is invalid while the mode is Full (strict). Install a valid certificate or an Origin CA certificate.
Too many redirects. The SSL mode is Flexible while the server redirects to HTTPS. Switch to Full (strict).
Mail stopped working. The MX target is proxied. Set the mail record to DNS only.
Next steps
- Protection against floods: DDoS protection basics.
- Certificates on the origin: install an SSL certificate.
Frequently asked questions
Which records should be proxied?
Web records, such as the root and www, can be proxied (orange cloud). Mail, SSH, FTP and other non-HTTP services must stay DNS only, because the proxy only carries web traffic on its supported ports.
Which SSL/TLS mode should I use?
Full (strict). It encrypts traffic between Cloudflare and your server and checks the server's certificate. Flexible leaves that connection unencrypted and often causes redirect loops.
Why do my logs show Cloudflare addresses instead of visitors?
Requests reach your server from Cloudflare. Configure nginx real_ip or Apache mod_remoteip to read the visitor address from the CF-Connecting-IP header, trusting only Cloudflare's ranges.
Do I need to change my domain's registrar?
No. You only change the nameservers to the ones Cloudflare assigns. For a domain registered with HyperDC, do that under Manage Domain › Nameservers.
Does Cloudflare replace a firewall on my server?
No. It protects the proxied web traffic. Keep your server's firewall, and allow web ports only from Cloudflare's ranges so attackers cannot bypass the proxy.
Sources
- developers.cloudflare.com/fundamentals/manage-domains/add-site
- developers.cloudflare.com/dns/proxy-status
- developers.cloudflare.com/ssl/origin-configuration/ssl-modes
- developers.cloudflare.com/ssl/origin-configuration/origin-ca
- developers.cloudflare.com/support/troubleshooting/restoring-visitor…
- cloudflare.com/ips
- nginx.org/en/docs/http/ngx_http_realip_module.html
- httpd.apache.org/docs/2.4/mod/mod_remoteip.html