Complemento Cloudflare para WP Cerber
The Cloudflare add-on for WP Cerber synchronizes selected WP Cerber IP decisions with Cloudflare IP Access Rules. When enabled, it can create and remove Cloudflare rules for WP Cerber lockouts and for entries in the Allowed and Blocked IP Access Lists. Because Cloudflare applies these rules before a request reaches your WordPress server, the add-on can reduce the traffic your server receives from addresses WP Cerber has already decided to block.
The add-on works with Cloudflare IP Access Rules, not Cloudflare Custom Rules.
Important: The add-on creates user-level Cloudflare IP Access Rules. Each rule applies to all Cloudflare zones owned by the Cloudflare user whose credentials you configure, not just to the WordPress website where the add-on is installed. Keep this scope in mind if the same Cloudflare user owns several websites.
Requirements
Before installing the add-on, make sure your website meets the following requirements:
- WP Cerber 9.8.3 or newer
- PHP 7.4 or newer
- A free or paid Cloudflare account
- The website hostname is proxied through Cloudflare, not set to DNS only
- WP Cerber’s Load security engine setting is set to Standard mode
- WP Cerber’s My site is behind a reverse proxy setting is enabled when the website is served through the Cloudflare proxy
Cloudflare IP Access Rules can act on requests before they reach the origin server only if Cloudflare actually proxies the website’s HTTP and HTTPS traffic. A DNS-only record does not send web traffic through Cloudflare.
On the WordPress side, the reverse proxy setting is just as important. WP Cerber can make reliable IP-based security decisions only if it correctly detects the original visitor IP address. Enable My site is behind a reverse proxy only when the website really is behind Cloudflare or another trusted reverse proxy.
Cloudflare and HTTPS
When your website is proxied through Cloudflare, Cloudflare sits between visitors and your origin server and terminates visitor TLS connections at its edge, which means your website traffic is processed by Cloudflare infrastructure.
The connection between Cloudflare and your origin server can still be encrypted. Cloudflare supports encrypted origin connections and recommends Full (strict) mode when possible.
If your website has privacy, data-processing, or TLS requirements, review the corresponding Cloudflare configuration before enabling the add-on.
Install the add-on
The Cloudflare add-on is a standard WordPress plugin. It is distributed through the WP Cerber website, not the wordpress.org plugin repository.
- Download the add-on: https://downloads.wpcerber.com/plugin/wp-cerber-cloudflare-addon.zip
- Log in to your WordPress admin dashboard.
- Go to Plugins → Add New Plugin.
- Click Upload Plugin.
- Select the downloaded ZIP archive.
- Click Install Now.
- Click Activate Plugin.
After activation, open WP Cerber → Add-ons → Cloudflare. All synchronization options are disabled by default.
Configure Cloudflare credentials
In the Cloudflare credentials section, enter:
- the email address of your Cloudflare account
- the Global API Key for that account
You can find the Global API Key in the Cloudflare dashboard under My Profile → API Tokens, in the API Keys section.
Version 2.5 authenticates with the account email address and the Global API Key. Cloudflare API Tokens are not supported by this version of the add-on. Treat the Global API Key as a sensitive credential, because it grants broader access than a narrowly scoped API Token.
When you save the add-on settings, WP Cerber verifies the credentials by creating and deleting a temporary Cloudflare IP Access Rule. If Cloudflare rejects the request, the add-on reports the failure in the WordPress admin area.
Syncing WP Cerber lockouts
Without the add-on, WP Cerber enforces its lockouts on the WordPress server. Enable Sync locked out IP addresses to have supported lockouts enforced at Cloudflare as well.
When WP Cerber locks out an address and the lockout qualifies for synchronization, the add-on creates a Cloudflare Block rule, so further requests from that address can be stopped at Cloudflare before they reach your WordPress server. When WP Cerber lifts the lockout, the add-on removes the corresponding rule.
Some lockouts are not synchronized
By design, the add-on does not mirror every WP Cerber lockout as it occurs. No Cloudflare rule is created when:
- the request belongs to a logged-in user
- the lockout is triggered by certain erroneous requests, such as repeated 404 requests
- the login attempt limit is reached for the first time, in cases where WP Cerber treats the first lockout differently
- the request is identified as Googlebot from the googlebot.com domain
- Cloudflare cannot represent the locked-out address or network as an IP Access Rule target
These exclusions apply only to the Cloudflare copy of the lockout. The lockout itself remains active in WP Cerber.
Subnet lockouts
Version 2.5 supports subnet lockouts. If Block subnet – Always block entire subnet Class C of intruders IP is enabled in WP Cerber, the add-on creates the rule for the subnet WP Cerber has locked out rather than only for the individual address that triggered the lockout. With the current WP Cerber subnet mode, this normally results in a /24 Cloudflare rule.
The rule is created only if Cloudflare supports that network size. If it does not, the lockout remains active in WP Cerber without a Cloudflare counterpart.
Earlier versions of the add-on did not synchronize subnet lockouts and required the Block subnet option to be disabled. Version 2.5 removes that restriction.
Syncing IP Access Lists
Turn on Enable IP Access List syncing to synchronize supported changes in the WP Cerber Allowed and Blocked IP Access Lists with Cloudflare IP Access Rules.
Synchronization runs in one direction only: WP Cerber → Cloudflare. Changes you make directly to IP Access Rules in the Cloudflare dashboard are not sent back to WP Cerber.
Blocked IP Access List
A supported entry added to the WP Cerber Blocked IP Access List becomes a Cloudflare Block rule. For example, if you add 192.168.1.0/24 to the list, the add-on can create a matching Cloudflare rule that blocks requests from that network before they reach your WordPress server.
Allowed IP Access List
A supported entry added to the WP Cerber Allowed IP Access List becomes a Cloudflare Allow rule, so use this list with care. Cloudflare documents that an IP Access Rule with the Allow action can bypass other Cloudflare security checks for that address, including Custom Rules, Rate Limiting Rules, WAF Managed Rules, and some other security features.
For that reason, add an address to the Allowed IP Access List only if you trust it and understand the effect of a Cloudflare Allow rule.
Supported IP addresses and networks
WP Cerber accepts more IP address and network formats than Cloudflare IP Access Rules do.
If an entry is valid in WP Cerber but Cloudflare cannot represent it, the add-on does not create a Cloudflare rule for it. The entry stays in your IP Access List exactly as it is, and nothing is rewritten or removed to make it fit Cloudflare.
| Entry in a WP Cerber IP Access List | Synced to Cloudflare |
|---|---|
A single IPv4 address, for example 192.168.1.1 |
Yes |
A single IPv6 address, for example 2001:db8::1 |
Yes |
An IPv4 network with prefix length /16 or /24, for example 192.168.1.0/24 |
Yes |
An IPv6 network with prefix length /32, /48, or /64, for example 2001:db8::/48 |
Yes |
An IPv4 network with another prefix length, for example 10.0.0.0/8 |
No |
| A range written as a first and last IP address | No |
WP Cerber wildcard notation is converted to CIDR notation automatically when Cloudflare supports the resulting network:
192.168.1.*becomes192.168.1.0/24192.168.*.*becomes192.168.0.0/16
Enabling IP Access List synchronization on an existing website
Turning on IP Access List synchronization does not trigger a bulk sync of entries already in the Access Lists. Only additions and removals made after you enable it are synchronized, as they occur.
To mirror an existing entry right away, remove it from the WP Cerber IP Access List and add it again. Be careful with entries that affect your own access to the website.
The one-time rebuild that runs when you update from an add-on version earlier than 2.5 works differently. It reads the current Access Lists and can recreate Cloudflare rules for entries that already exist at the time of the update.
Other add-on settings
Verbose rule notes
Enable Verbose rule notes to include additional WP Cerber information in Cloudflare rule notes. For IP Access List rules, the add-on can add the entry comment. For lockout rules, it can add the lockout reason.
Verbose notes can make Cloudflare rules easier to identify and search, but the information they contain is then stored by Cloudflare. Leave this option disabled if your Access List comments or lockout reasons contain anything you do not want stored there.
Delete Cloudflare rules on deactivation
When Delete Cloudflare rules on deactivation is enabled, deactivating the Cloudflare add-on removes the Cloudflare rules recorded by the add-on. The same cleanup also runs when WP Cerber itself is deactivated.
If a Cloudflare deletion fails, it is not retried during that deactivation. The add-on then no longer tracks that rule, so remove it manually in Cloudflare. After using deactivation to clear the rule set, check the IP Access Rules in your Cloudflare account to confirm that the expected rules are gone.
Reactivating the plugins does not automatically recreate the rules removed during deactivation. From that point on, synchronization is event-driven.
Enable diagnostic logging
Turn on Enable diagnostic logging before investigating a synchronization problem. While this option is enabled, the add-on records synchronization activity and Cloudflare failures in the WP Cerber Diagnostic Log, which you can open from WP Cerber → Tools → Diagnostic Log. When the option is disabled, the add-on writes nothing to that log.
Troubleshooting
Cloudflare credentials are rejected
Check that:
- you entered the Cloudflare account email address
- you entered the Global API Key, not an API Token
- the credentials belong to the Cloudflare user whose zones you intend the add-on to affect
Then save the settings again to rerun the credential check.
A WP Cerber entry does not appear in Cloudflare
Work through the following steps:
- Make sure the relevant synchronization option is enabled.
- Confirm that Cloudflare supports the address or network format.
- If the entry was added before you enabled synchronization, remember that existing entries are not synchronized in bulk.
- Look for a Cloudflare error in the WordPress admin notices.
- Enable diagnostic logging and review WP Cerber → Tools → Diagnostic Log.
Nothing happens after updating from an older version
The one-time rebuild starts with the next relevant WP Cerber IP event, not necessarily at the moment you update the plugin. Also confirm that the Cloudflare email address and Global API Key are saved.
To trigger a relevant event yourself, add an IP Access List entry and then remove it. Choose an address that will not affect your own access to WordPress or to other Cloudflare zones.
The Cloudflare rule set looks incomplete after an update
A large rebuild can span multiple requests, and while it is in progress, Cloudflare rule IDs and the number of visible rules may change.
Enable diagnostic logging and check the Diagnostic Log for rejected Cloudflare operations or unsupported targets.
Recovering from an accidental block
A Cloudflare Block rule can prevent your current IP address from reaching WordPress at all. If you accidentally block yourself, you have two practical ways to recover.
Use another Internet connection
Switch to a device or connection with a different public IP address, such as a mobile device on cellular data instead of your Wi-Fi network. Then log in to WordPress and remove the lockout or IP Access List entry that caused the block.
This is the preferred option when you need to restore normal WordPress access immediately.
Remove the Cloudflare rule manually
Log in to Cloudflare, open Security → Security rules → IP Access rules, find the rule for your IP address, and remove it. To find out your current public IP address, use What is my IP address.
Removing the Cloudflare rule lets your requests reach the WordPress server again, but it does not remove the corresponding WP Cerber lockout or IP Access List entry. WP Cerber continues to enforce its own state until that state expires or you change it in WordPress.
The add-on does not detect a rule you remove manually and continues to treat it as existing until the corresponding lockout is lifted or the IP Access List entry is removed in WordPress. At that point, the add-on clears its record of the rule, and if the same address is added again later, a new Cloudflare rule is created as usual.
Delete all Cloudflare rules created by the add-on
To remove the rules currently recorded by the add-on:
- Open WP Cerber → Add-ons → Cloudflare.
- Enable Delete Cloudflare rules on deactivation.
- Save the settings.
- Go to the WordPress Plugins page.
- Deactivate the Cloudflare for WP Cerber Security plugin.
- Check your Cloudflare IP Access Rules to confirm that the expected rules were removed.
- Reactivate the add-on only if you still want to use it.
Keep in mind that individual Cloudflare deletions can fail, so deactivation does not guarantee that every remote rule is removed.
Support
If you run into a synchronization problem, turn on Enable diagnostic logging, reproduce the issue, and then check WP Cerber → Tools → Diagnostic Log.
WP Cerber Professional customers can use the support helpdesk at https://my.wpcerber.com. Support for the free version is available through the WP Cerber community at https://talk.wpcerber.com.
Cloudflare references
The Cloudflare documentation covers the following topics in more detail:
- Behavior and scope of IP Access Rules: https://developers.cloudflare.com/waf/tools/ip-access-rules/
- Proxy status and the difference between proxied and DNS-only hostnames: https://developers.cloudflare.com/dns/proxy-status/
- Full (strict) TLS mode: https://developers.cloudflare.com/ssl/origin-configuration/ssl-modes/full-strict/
Have any questions?
If you have a question regarding WordPress security or WP Cerber, leave them in the comments section below or get them answered here: G2.COM/WPCerber.