Every 10-15 second hit my homepage url and load 2 or 3 times .
Almost 1200 hit perday.
Then I tried to block using range of ip throught WF firewall. Until now still hit but succesfully blocked.
After that.
I tried again add my site to Cloudflare. The hit just even more with various pattern. Then I blocked it again and remove my domain from Cloudflare.
Now I face another problems that most of the visitor comes from china, India, Turkey, taiwan, korea that never ever happen before. I am still watching the traffic and blocking it. Its painfull.
You should place button to clear all chache after domain removed. I cant find the button or anything option because domain has been removed.
Should I add again, and make the bot more worst? Than purge the cache?
I suggest your team to make change header original ip in low cost. Not entreprice only.
I doubt this has any relationship with CF. Your site is simply being crawled or attacked. You should get a PRO account for that domain to obscure the real IP of your server through the CDN. Even tho, if they have your IP by now, the attacks won’t get mitigated by CF.
If using WordPress and Wordfence, set Use the Cloudflare “CF-Connecting-IP” HTTP header to get a visitor IP. Only use if you’re using Cloudflare. in global options. Otherwise, you’ll have to search for information on X-Forwarded-For header to obtain the real IP adresses and not the Cloudflare proxy.
Thank you. Is this metode using wordfence also solve real ip isue in log server?
So we do not need to install mod Cloudflare on the server to get real visitor ip?
I have disabled Cloudflare until I got fix with this.