First, go to the domain list in the mybox panel – the “Domains” tab on the left, and then click the “Actions” button on the right side of the domain for which you want to activate protection and select “Configure Cloudflare” from the list. Similarly, you can also expand the domain details, then expand the “Cloudflare” item and click the “Configure” button there.
A window will appear asking you to confirm the changes. Click “Configure Domain”.
Information about the current activation status will appear in the domain settings list.
To complete the configuration, you need to change the delegation to the name servers we provided with the current operator where the domain is registered (where you pay for it).
After changing the delegation, the status will change within a maximum of 24 hours to “Awaiting Cloudflare Activation”. The status will be updated to Active within a maximum of 24 hours (it usually takes a few hours).
Table of Contents
How to Disable?
To disable “Cloudflare” protection, in the domain list, click the “Actions” button and select “Deactivate Cloudflare” from the list.
A prompt will appear asking you to confirm the changes by clicking the “Deactivate” button.
After confirmation, the domain will be removed from “Cloudflare” servers after 24 hours. To maintain service continuity, change the delegation to our name servers.
The “Cloudflare” protection status will be updated after 24 hours.
Explanation of Statuses
SSL Certificate
Ability to activate an SSL encrypted connection. The certificate is activated on the “Cloudflare” side, and the data encryption itself occurs between the internet user and “Cloudflare” servers. A requirement for the “Cloudflare” certificate to work is to have active protection for the main domain.
Protection Level
Five protection statuses are available: disabled, low, medium, high, I’m Under Attack. The levels are based on increasing the probability of a user being challenged to prove they are not a bot.
- Disabled – allows access to the site from any IP address.
- Low – people who notoriously try to access the site causing artificial traffic receive a captcha notification.
- Medium – optimal level for websites. People who relatively often cause artificial traffic on the site are also blocked by captcha.
- High – if the IP address of a person connecting to the site within the last 14 days was identified as unwanted, it is blocked by captcha.
- I’m Under Attack – if this option is selected, the site will require access to content to be confirmed via captcha. This option is recommended only when a DDoS attack is detected.
Cache Level
Three caching modes are available: standard, no Query String, ignore Query String. This option enables faster content delivery to the user via CDN. It provides load balancing, distributing content among 101 data centers, where data on the site is displayed from the closest server. All of this speeds up the website’s operation.
- Standard – delivers different content if the Query String has changed.
- Without Query String – delivers content from cache without Query String.
- Ignore Query String – delivers the same content regardless of the Query String.
Developer Mode
This mode disables caching and mechanisms responsible for HTML/CSS optimization, so the response received from the “Cloudflare” server is identical to that from our server. This option deactivates all additional “Cloudflare” mechanisms. It does not refresh the site cache.
Rocket Loader
Which means automatically reducing the number of network connections and ensuring that third-party content does not slow down your website’s presentation. This option may negatively affect sites based on AJAX scripts.
IPv6
Enables access to your site from IPv6 addresses.
IP Geolocation
Information about the IP geolocation of the client who connects to your site is added to the HTTP headers.
Email address protection – phrases on your site in the form of an email address are modified in such a way that they do not point to an actual email. They are then appropriately modified, e.g., the @ symbol is removed. Thanks to this solution, bots that scan websites do not use the contact form for spamming. Changes occur on the source code side of the page, e.g., HTML, so you don’t have to worry that the address will be distorted in the browser.