LUCKVM / CLOUD INFRASTRUCTURE

Explore LuckVM

Home Global Acceleration Domains Support News Company

How to Set Up Cloudflare for Your VPS in 2026: Complete CDN & Security Guide

Cloudflare for VPS: CDN, SSL, WAF and DDoS setup guideCloudflare protects and accelerates VPS-hosted websites in 8 simple steps.
TL;DR: Sign up to Cloudflare free plan, change your domain's nameservers, wait for propagation, switch SSL mode to Full (strict), install a Cloudflare Origin Certificate on your VPS, enable WAF managed rules, then toggle the DNS orange cloud on. Do not use Flexible SSL, and never orange-cloud MX/SSH/SRV records.

1. Why Add Cloudflare to Your VPS

If you host a site on a VPS, your origin IP is public knowledge the moment you point an A record at it. Any attacker who finds that IP can:

  • Launch Layer 3/4 DDoS attacks directly at your server, bypassing any CDN.
  • Crawl your site from thousands of IPs and exhaust your CPU.
  • See the real geographic location of your server from any IP lookup tool.

Cloudflare's free plan solves all of that and more. In front of your VPS, you get a 300+ city Anycast network, free SSL termination, a managed web application firewall, bot management, DDoS mitigation, automatic static caching, HTTP/3 (QUIC), Brotli compression, and a global DNS that typically answers in under 20 ms. Nothing else at that price point comes close.

Request path comparison: direct vs Cloudflare proxiedFigure 1. Without Cloudflare every visitor hits your VPS directly (TTFB 400–1800 ms, origin exposed). With Cloudflare proxied, cached assets are served from the nearest edge PoP (TTFB 20–80 ms), and only cache misses reach the origin.

2. What Cloudflare Can and Cannot Do

Before jumping in, it is important to set expectations.

Cloudflare does Cloudflare does NOT
Proxy HTTP/HTTPS on ports 80/443 (plus 8080/8443/2052/2082/2086/2095) Proxy SSH (22), FTP (21), SMTP (25/465/587), MySQL (3306) or any custom TCP port
Absorb Layer 3/4 and most Layer 7 DDoS at the edge Protect your origin if attackers already know your real IP and hit it directly
Terminate TLS and issue free Universal SSL certs Replace a valid certificate on your origin (you still need one)
Cache static assets at the edge Magically speed up uncached dynamic PHP/Node responses
Important: Cloudflare is not "set and forget". If you turn on the orange cloud before SSL works on your origin you will lock yourself out with a redirect loop. We will avoid that below.

3. Step 1 β€” Add Your Site to Cloudflare

  1. Sign up at dash.cloudflare.com/sign-up with email and password.
  2. Click Add Site and enter your root domain (e.g. example.com, not www.example.com).
  3. Choose the Free plan ($0/month). It includes everything in this guide. Upgrade to Pro ($20/month) only if you need the WAF ML model or image resizing.
  4. Cloudflare will scan your existing DNS records automatically. Review them but do not trust the scan blindly β€” any missing A/AAAA/MX/TXT record will cause mail or subdomains to break.

4. Step 2 β€” Change Nameservers at Your Registrar

Cloudflare will give you two nameservers that look like something.ns.cloudflare.com and something-else.ns.cloudflare.com. Log in to the registrar where you bought the domain (Namecheap, Cloudflare Registrar, Porkbun, Name.com, GoDaddy, etc.) and replace the existing nameservers with Cloudflare's.

Pro tip: DNS propagation typically takes 1–4 hours but can take up to 24 hours. Wait until the Cloudflare dashboard shows "Great, your site is active" before moving to the SSL step.
DNS records: which ones to orange-cloud vs grey-cloudFigure 3. Only A, AAAA and CNAME records pointing to HTTP(S) websites get the orange cloud. MX, TXT (SPF/DKIM/DMARC), SRV and any non-HTTP service must stay grey (DNS only).

5. Step 3 β€” Set SSL/TLS to Full (Strict)

Go to SSL/TLS in the Cloudflare dashboard. You will see four options.

Cloudflare four SSL modes comparison: Off, Flexible, Full, Full StrictFigure 2. The four SSL/TLS modes. "Full (strict)" is the only mode that gives real end-to-end encryption without redirect loops.

Set the mode to Full for now. We will upgrade to Full (strict) once the origin certificate is installed in Step 4. Never choose Flexible — it creates an infinite HTTP→HTTPS→HTTP loop when your origin already redirects to HTTPS, and it sends plaintext traffic from Cloudflare to your VPS.

Never use Flexible SSL on production. It is the single most common cause of "too many redirects" errors after switching to Cloudflare. If you currently have Flexible on, switch to Full immediately.

6. Step 4 β€” Install a Cloudflare Origin Certificate on Your VPS

"Full (strict)" mode requires that the certificate your VPS presents to Cloudflare is either (a) a valid public certificate from Let's Encrypt, or (b) a Cloudflare-issued Origin CA certificate. The Origin CA option is easier because it lasts 15 years and auto-renewal is not required.

  1. In Cloudflare, go to SSL/TLS β†’ Origin Server β†’ Create Certificate.
  2. Let Cloudflare generate a private key and CSR, keep default hostnames, set validity to 15 years.
  3. Copy the "Origin Certificate" (PEM block) and save it on your VPS as /etc/ssl/certs/cloudflare.pem.
  4. Copy the "Private key" and save it as /etc/ssl/private/cloudflare.key (chmod 600).

Then configure Nginx on your VPS to use this certificate for traffic coming from Cloudflare, alongside your Let's Encrypt certificate (which is still used for direct visitors and for health checks):

# /etc/nginx/sites-available/example.com
server {
    listen 443 ssl http2;
    server_name example.com www.example.com;

    ssl_certificate     /etc/ssl/certs/cloudflare.pem;
    ssl_certificate_key /etc/ssl/private/cloudflare.key;

    # Optional: Authenticated Origin Pulls (recommended for production)
    # ssl_client_certificate /etc/ssl/certs/cloudflare-origin-pull-ca.pem;
    # ssl_verify_client on;

    root /var/www/example.com;
    index index.html index.php;

    location / { try_files $uri $uri/ /index.php?$args; }
    location ~ \.php$ { include snippets/fastcgi-php.conf; fastcgi_pass unix:/run/php/php8.2-fpm.sock; }
}

Then reload Nginx: sudo nginx -t && sudo systemctl reload nginx.

Now return to Cloudflare and switch SSL to Full (strict). Your site should continue to load, but this time with genuine end-to-end encryption.

7. Step 5 β€” Enable WAF and Security Rules

Navigate to Security β†’ WAF. Under "Managed rules", enable:

  • Cloudflare Free Managed Ruleset (blocks known CVEs, SQLi, XSS)

Under "Custom rules", create these five free rules:

  1. Block high-risk countries (if you do not serve them): (ip.geoip.country in {"RU" "CN" "KP"}) β†’ Block
  2. Challenge suspicious user-agents: (http.user_agent contains "curl" or http.user_agent contains "python-requests") β†’ Managed Challenge
  3. Protect wp-admin: (http.request.uri.path contains "/wp-admin") and not (ip.src in $my_home_ip) β†’ Block
  4. Rate limit login: (http.request.uri.path eq "/wp-login.php") β†’ Rate limit to 5 req/min per IP
  5. Block XML-RPC: (http.request.uri.path eq "/xmlrpc.php") β†’ Block

Then go to Security β†’ DDoS and set all rules to "High". Under Security β†’ Bots, enable Bot Fight Mode (free).

8. Step 6 β€” Cache & Performance Tuning

Go to Caching β†’ Configuration and set Cache Level to "Standard" (default). Under Rules β†’ Page Rules add one rule that caches static assets aggressively:

URL: *example.com/wp-content/uploads/**
Setting: Cache Level β†’ Cache Everything
Setting: Edge Cache TTL β†’ 1 month
Setting: Browser Cache TTL β†’ 1 month

Under Speed β†’ Optimization, enable:

  • Auto Minify (JS, CSS, HTML)
  • Brotli compression
  • Early Hints
  • HTTP/3 (under Network)
  • 0-RTT Connection Resumption

Leave Rocket Loader, Mirage and Polish off initially β€” they can break some themes; enable them one by one and test.

Performance before vs after Cloudflare: TTFB, bandwidth, origin requests, CPUFigure 4. Typical performance impact after Cloudflare is enabled: TTFB drops ~10x for cached assets, origin bandwidth falls by ~65%, and your VPS CPU usage decreases substantially.

9. Step 7 β€” Enable the Orange Cloud (Carefully)

Go back to DNS β†’ Records. Toggle the orange cloud on for:

  • The root A record (example.com)
  • The www CNAME or A record
  • Any other HTTP(S) subdomains (app, blog, shop)

Leave MX, TXT, DKIM, DMARC, SRV, PTR, SSH CNAMEs, and any database/FTP/gaming records as grey cloud (DNS only). Cloudflare does not proxy those protocols, and orange-clouding them will break those services.

Do not enable orange cloud before Step 4. If your origin does not serve HTTPS with a valid cert when you flip the switch, every visitor will see Error 526 or a redirect loop.

10. Step 8 β€” Verify It Actually Works

After flipping the cloud, verify from a terminal:

# Check that DNS now returns Cloudflare IPs
dig +short example.com
# Should return two IPs from Cloudflare ranges, NOT your VPS IP

# Verify response headers include Cloudflare
curl -I https://example.com
# Expect to see:
#   server: cloudflare
#   cf-ray: 89ab12cd...
#   cf-cache-status: DYNAMIC (or HIT for cached assets)

Finally, open your site in a browser, check that the padlock is present, and visit example.com/cdn-cgi/trace β€” you should see a page showing Cloudflare PoP, IP, TLS version and your visitor country. If that page loads, Cloudflare is definitely in front.

Eight-step Cloudflare setup timeline and warningsFigure 5. The eight-step rollout. Do not skip ahead: propagation, SSL and origin cert must be in place before orange-clouding.

Optional hardening: lock your VPS to Cloudflare only

Once everything works, the best way to prevent anyone from bypassing Cloudflare is to add a UFW rule that only allows Cloudflare IP ranges on ports 80/443:

# Allow Cloudflare IPv4 ranges on 80/443
for ip in $(curl -s https://www.cloudflare.com/ips-v4); do
  sudo ufw allow proto tcp from $ip to any port 80,443
done
# Allow Cloudflare IPv6 ranges
for ip in $(curl -s https://www.cloudflare.com/ips-v6); do
  sudo ufw allow proto tcp from $ip to any port 80,443
done
# Block direct access to 80/443 from any other source
sudo ufw deny 80/tcp
sudo ufw deny 443/tcp
sudo ufw reload

If you do this, also enable Authenticated Origin Pulls (Step 4 Nginx snippet) so only Cloudflare's valid client certificate can connect β€” blocking anyone who spoofs the Host header to hit your IP.

Run your first Cloudflare-protected site on LuckVM

LuckVM VPS plans start at $8.80/month with NVMe SSD, 1 Gbps uplink and native support for Cloudflare Origin CA. Hong Kong, Los Angeles, Singapore, Tokyo and Frankfurt locations.

See LuckVM VPS Plans β†’

Frequently Asked Questions

Will Cloudflare slow down my site?No. Because of Anycast routing, the nearest PoP is almost always closer to your visitors than your origin server. Cached assets are served 5–15Γ— faster. Only completely uncacheable dynamic requests add ~5 ms of extra hop.
Can I use Cloudflare with a self-signed certificate?Yes, but only in "Full" mode β€” not "Full (strict)". We recommend using the free Origin CA certificate instead; it lasts 15 years.
Why is my mail broken after switching to Cloudflare?You almost certainly orange-clouded your MX record or mail subdomain. MX records must stay on grey cloud, and you should create a separate mail A record (grey) that points directly to your mail server.
Is Cloudflare free enough for a production site?Absolutely. The Free plan includes SSL, WAF, DDoS, bot fight mode, DNS, CDN and up to 100 custom WAF rules. Pro is only needed for advanced image optimization or enterprise-grade SLA.
Can Cloudflare hide my origin IP if it is already leaked?No. If the IP has been used elsewhere, attackers can find it via historical DNS, mail headers or certificate transparency logs. After setting up Cloudflare, consider requesting a new IP from your host or rotating to a new VPS.
Do I still need HTTPS on my origin if Cloudflare handles SSL?Yes, even in "Full" mode. The only secure configuration is end-to-end TLS with "Full (strict)" and an origin certificate.
Why do I see Error 521 "Web server is down"?Cloudflare cannot reach your origin. Check that Nginx is running, that port 443 is open, and (if you locked UFW) that you added the latest Cloudflare IP ranges.
Should I enable Cloudflare for SSH/FTP?No. Cloudflare does not proxy those protocols. Use your server IP or a grey-cloud DNS subdomain for SSH.

Related services

Compare the related LuckVM product plans, network options and resources. Final availability and pricing are subject to the order page. Domain Name Registration | Buy & Search Cheap Domains