Domain-migration to Cloudflare, how to get the most (secure) out of it?

What is the name of the domain?

What is the error number?

There is no error, I have a question :slight_smile:

What is the error message?

There is no error, I have a question :slight_smile:

What is the issue you’re encountering

Recently switched to Cloudflare with my domain that points to my WAN IP. opnSense is acting as my firewall, where HAproxy serves a LE certificate and routes related traffic to my Nextcloud-VM. Again, it’s working fine and I just wanted to hear your insights on how to get the most out of Cloudflare’s eco-system.

What steps have you taken to resolve the issue?

As of now, I’ve disabled proxying on Cloudflare, because on my road-warrior clients (that are syncing contacts and calendar), I get an error 520. That’s understood, because until now I took care of those HTTP->HTTPS forwards locally in my home-lab. I would assume that I need to disable HAproxy, and furthermore any nginx configurations that are 301-related?

Is it possible to completely get rid of my local HAproxy and let Cloudflare do all the work (I’m on the “free” plan)?
Also that it provides a SSL cert like HAproxy now (it’s an LE cert that is automatically managed by the ACME client on opnSense)?

I’ve also read about cloudflared, do I need to set it up or are the “out of the box” functionalities just fine?

Thanks for your time!

1 Like

Most likely if all you’re getting out of that is firewall. The cloudflare WAF is probably much more full featured.

Yes, you can use Universal SSL between visitors and Cloudflare and a self-signed cloudflare cert on your origin between the origin and cloudflare in order to ensure end to end encryption.

Usually oob is fine, you may want to ensure all your DNS records were imported. Beyond that, you can tune the WAF to ensure optimal protection for your site.

Good morning, sir!

Many thanks for your insights. Based on that, I’ve finalized my setup - everything works as intended (w/o cloudflared), utilizing CFs’ cert management and WAF works like a charm.

Have a great day!

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.