Skip to content

NetworkingCDN & proxy

Put Cloudflare in front of your website

Proxy your site through Cloudflare: change nameservers, choose what to proxy, use Full (strict) SSL, restore visitor IPs in nginx or Apache, lock the origin.

  • Intermediate
  • 25 min read
  • Updated

Tested on: Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, Debian 12, Debian 13

This guide is not available in your language yet, so it is shown in English.

On this page
  1. Before you start
  2. Step 1: Add the site to Cloudflare
  3. Step 2: Choose what to proxy
  4. Step 3: Change the nameservers
  5. Step 4: Set SSL/TLS to Full (strict)
  6. Step 5: Restore the visitor's IP address
  7. Step 6: Allow web traffic only from Cloudflare
  8. Caching basics
  9. Troubleshooting
  10. Next steps

Cloudflare's reverse proxy sits between your visitors and your server: it serves cached files from locations near the visitor, filters malicious traffic and hides your server's real address. This guide puts a site on a HyperDC server behind Cloudflare without breaking HTTPS, logs or access control. Replace example.com and 203.0.113.10 with your values.

Before you start

  • A Cloudflare account and your site working on the server, ideally already with HTTPS.
  • Access to the domain's nameserver setting: for a HyperDC domain, Domains › My Domains › Manage Domain › Nameservers.
  • A list of your current DNS records (website, mail, verifications), so nothing is lost in the move.

Step 1: Add the site to Cloudflare

In the Cloudflare dashboard, add example.com. Cloudflare scans your existing records; compare them with your list and add anything missing, especially MX, SPF, DKIM and DMARC records.

Step 2: Choose what to proxy

RecordProxy status
A @ and A or CNAME www (website)Proxied
MX and the mail server's A record (mail)DNS only
Records for SSH, FTP, game servers, VPNDNS only
TXT (SPF, DKIM, DMARC, verifications)Not proxied (TXT records are never proxied)

If mail is sent from the same IP address as the website, the MX record reveals the server's address. Where you can, send mail from another host or IP.

Step 3: Change the nameservers

Cloudflare shows two nameservers for your zone. Enter them at your registrar; for a HyperDC domain choose Use custom nameservers (enter below), enter both and select Change Nameservers. If DNSSEC was enabled at the old DNS host, remove the old DS record first.

Verify: dig NS example.com +short returns the Cloudflare nameservers, and the Cloudflare dashboard shows the zone as active.

Step 4: Set SSL/TLS to Full (strict)

In SSL/TLS › Overview, choose Full (strict). Your server needs a valid certificate for that:

  • A public certificate (for example Let's Encrypt) keeps working, and the site also works without Cloudflare.
  • A Cloudflare Origin CA certificate (in SSL/TLS › Origin Server) is trusted only by Cloudflare and can be valid for many years. Install it like any certificate; see install an SSL certificate.

Avoid Flexible: it sends traffic from Cloudflare to your server unencrypted, and if your server redirects HTTP to HTTPS, visitors end up in a redirect loop.

Step 5: Restore the visitor's IP address

Behind the proxy, every request comes from a Cloudflare address. Tell your web server to take the real address from the CF-Connecting-IP header, trusting only Cloudflare's ranges (listed on Cloudflare's IP ranges page).

nginx

Create /etc/nginx/conf.d/cloudflare-realip.conf with one set_real_ip_from line per Cloudflare range:

Nginx
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 103.21.244.0/22;
real_ip_header CF-Connecting-IP;

Add every range from the list, including the IPv6 ranges, then sudo nginx -t and sudo systemctl reload nginx.

Apache

Enable the module and add the trusted ranges:

Bash
sudo a2enmod remoteip
Apache
RemoteIPHeader CF-Connecting-IP
RemoteIPTrustedProxy 173.245.48.0/20
RemoteIPTrustedProxy 103.21.244.0/22

Add every range from the list, use %a instead of %h in your LogFormat, then sudo apachectl configtest and sudo systemctl reload apache2.

Verify: after visiting the site, the newest line in the access log shows your own IP address, not a Cloudflare one. Cloudflare changes its ranges occasionally; review them from time to time.

Step 6: Allow web traffic only from Cloudflare

If attackers find your server's IP address, they can bypass the proxy. With UFW, allow ports 80 and 443 only from Cloudflare's ranges and remove the general rule:

Bash
for ip in $(curl -s https://www.cloudflare.com/ips-v4) $(curl -s https://www.cloudflare.com/ips-v6); do sudo ufw allow proto tcp from "$ip" to any port 80,443; done
sudo ufw delete allow 80,443/tcp
sudo ufw status numbered

Keep SSH allowed as before. Re-run the loop when Cloudflare publishes new ranges.

Caching basics

Cloudflare caches static files (images, CSS, JavaScript) by default and respects your Cache-Control headers. HTML pages are not cached unless you add a cache rule. After a deployment, use Caching › Configuration › Purge Cache if visitors see old files.

Troubleshooting

Error 521 (web server is down). Your server refused Cloudflare's connection: the web server is stopped, or the firewall does not allow Cloudflare's ranges.

Error 522 or 524 (timeouts). The server did not answer in time; check its load and logs. See website 502, 503 and 504 errors.

Error 525 or 526 (SSL). The handshake with the server failed, or its certificate is invalid while the mode is Full (strict). Install a valid certificate or an Origin CA certificate.

Too many redirects. The SSL mode is Flexible while the server redirects to HTTPS. Switch to Full (strict).

Mail stopped working. The MX target is proxied. Set the mail record to DNS only.

Next steps

Frequently asked questions

Which records should be proxied?

Web records, such as the root and www, can be proxied (orange cloud). Mail, SSH, FTP and other non-HTTP services must stay DNS only, because the proxy only carries web traffic on its supported ports.

Which SSL/TLS mode should I use?

Full (strict). It encrypts traffic between Cloudflare and your server and checks the server's certificate. Flexible leaves that connection unencrypted and often causes redirect loops.

Why do my logs show Cloudflare addresses instead of visitors?

Requests reach your server from Cloudflare. Configure nginx real_ip or Apache mod_remoteip to read the visitor address from the CF-Connecting-IP header, trusting only Cloudflare's ranges.

Do I need to change my domain's registrar?

No. You only change the nameservers to the ones Cloudflare assigns. For a domain registered with HyperDC, do that under Manage Domain › Nameservers.

Does Cloudflare replace a firewall on my server?

No. It protects the proxied web traffic. Keep your server's firewall, and allow web ports only from Cloudflare's ranges so attackers cannot bypass the proxy.

Sources

Generer passord

Please confirm