• Home
  • Get help
  • Ask a question
Last post 6 hours 11 min ago
Posts last week 141
Average response time last week 4 hours 42 min
All time posts 67824
All time tickets 10480
All time avg. posts per day 21

Helpdesk is open from Monday through Friday CET

Please create an (free) account to post any question in the support area.
Please check the development versions area. Look at the changelog, maybe your specific problem has been resolved already!
All tickets are private and they cannot be viewed by anyone. We have made public only a few tickets that we found helpful, after removing private information from them.

#7055 – Question about Security and Cloudflare

Posted in ‘sh404SEF’
This is a public ticket. Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.
Wednesday, 08 April 2020 10:55 UTC
TheSDHotel
Hello,
Cloudflare suggests this: 

"If you are using services like .htaccess, firewalls or server mods to manage access to your site from visitors, it is vitally important to make sure requests from Cloudflare’s IP ranges are not being blocked or limited in any way. The number one cause of site offline issues in our support channel is something blocking or restricting requests from our IPs, so please take the time to make sure that all of Cloudflare’s IPs are whitelisted on your server."

I've already taken care of adding the Cloudflare IPs to htaccess whitelist.

Since sh404sef has a Security tab with a Whitelist field, do I need to add the Cloudflare IPs there as well?

What is that Whitelist section for, and what does it allow to those IPs compared to not listing any IP there?

Thanks!
Wednesday, 08 April 2020 11:05 UTC
wb_weeblr
Hi

The IP whitelist will allow any request coming from that IP or IP range. The IP blacklist will block any IP or IP range listed.

If you do not block any IP using the blacklist, then there's no need to whitelist any IP.

They work both in tandem so that you can for instance, block 123.456.123.* but then unblock 123.456.123.001.

Again, if no IP is balcklisted you don't need to whitelist anything.

The only security feature that could affect you is anti-flood: if you enabled that then you probably want to disable it because there's no way to exclude cloudflare or anyone else from it. Anti-flood will prevent too many requests from the same IP in a given period of time.
If you have cloudflare, they'll probably protect your from that anyway, at least to some extent.

Best regards

Yannick Gaultier
weeblr.com
@weeblr
 
Wednesday, 08 April 2020 11:08 UTC
TheSDHotel
Perfect, thanks a lot!
Wednesday, 08 April 2020 11:14 UTC
wb_weeblr
Hi

You're welcome! Closing this ticket now, feel free to open a new one as needed. If you do so, please mention this ticket number in the new one.

If you created any superadmin account for us, be sure to delete or block it now to avoid unnecessary risk in the future.

Best regards

Yannick Gaultier
weeblr.com
@weeblr
 
This ticket is closed, therefore read-only. You can no longer reply to it. If you need to provide more information, please open a new ticket and mention this ticket's number.