Cloud & Server Management

Cloudflare Setup

We set up Cloudflare in front of your site with caching, firewall and bot rules tuned to your traffic, and lock down your origin server so the protection can’t simply be bypassed.

What Cloudflare does for your site

Cloudflare sits between visitors and your server. When the proxy is on, visitors connect to Cloudflare’s network, which can serve cached content from a nearby location, filter malicious requests and absorb attack traffic before it reaches you. It also provides DNS, SSL at the edge and tools for handling bots.

Turning it on takes minutes. Getting it right takes more thought: which pages can be cached, which rules block attacks without blocking customers, and how to make sure attackers cannot go around Cloudflare straight to your server’s IP.

Who benefits

  • E-commerce stores that see traffic spikes during sales and bot activity on checkout or login.
  • Content and coaching sites serving images and video to visitors across different countries.
  • SaaS products whose API or login endpoints attract credential-stuffing attempts.
  • Businesses whose server IP is unreachable from some networks, where proxying through Cloudflare restores access.
  • Anyone who has had a site slowed or knocked offline by unwanted traffic.

What’s included

  • Zone setup and a full check that every DNS record was imported correctly.
  • Proxy enabled on the right records, with mail and other non-web records left DNS-only.
  • SSL mode set to Full (strict) with a valid origin certificate.
  • Cache rules for static assets, with dynamic, logged-in and cart pages excluded.
  • WAF managed rules and custom rules for your sensitive paths, such as admin and login.
  • Rate limiting and bot settings suited to your traffic.
  • Origin lockdown: the server firewall accepts web traffic only from Cloudflare’s IP ranges.
  • Real visitor IPs restored in your server logs and application.

How we set it up

  1. Review your site’s traffic patterns, dynamic pages and existing DNS.
  2. Add the zone, verify every record and switch nameservers during a quiet period.
  3. Configure SSL, caching and security rules, starting conservatively.
  4. Test logins, checkout, forms, APIs and webhooks through the proxy.
  5. Lock the origin firewall to Cloudflare and confirm the site still works end to end.
  6. Review firewall events after launch and adjust rules that block real visitors.

Tools and integrations

Alongside Cloudflare itself, we configure your origin: Nginx or Apache to trust Cloudflare’s forwarded IP header, UFW or cloud firewall rules for the origin lockdown, and origin certificates or Let’s Encrypt for encryption between Cloudflare and your server. Where you already use a cloud provider’s load balancer or CDN, we check how Cloudflare fits so you are not caching or filtering twice.

What affects timeline and cost

A single website is quick to onboard. More time is needed for many domains, complex caching of dynamic content, APIs and webhooks from third parties that must not be blocked, or several origin servers. Cloudflare has a free plan and paid plans; which features you need determines which plan fits.

If you need Cloudflare features beyond the basics, such as load balancing across origins, image optimisation or Zero Trust access for internal tools, we scope those separately and explain what each adds before you decide.

Deciding what to cache

Caching is where Cloudflare delivers most of its speed benefit, and also where most problems start. We work through your site’s pages and decide explicitly how each type should be handled:

ContentTypical handlingReason
Images, CSS, JavaScript, fontsCached at the edge for a long timeRarely changes; biggest speed gain
Public pages such as blog postsCached briefly or with careful rulesSpeeds up browsing while allowing updates
Cart, checkout and account pagesNever cachedContains personal or session-specific data
Admin and login areasNever cached, extra WAF rulesSensitive and frequently targeted
APIs and webhooksBypassed, with rate limits where suitableResponses are dynamic; partners must not be blocked

After launch we check cache hit rates and the firewall event log. If real visitors are being challenged or blocked, or content is not caching as expected, we adjust the rules. A setup that is reviewed once after real traffic arrives is far more reliable than one configured blind and never revisited.

Common mistakes

  • Trusting the automatic DNS import, which can miss records or import none at all.
  • Proxying the mail server hostname, which breaks email.
  • Using Flexible SSL, leaving traffic to the origin unencrypted and often causing redirect loops.
  • Caching everything, including pages with personal data.
  • Leaving the origin IP open, so attackers skip Cloudflare entirely.

Related: DNS Management, Firewall Configuration and Website Security. See Cloud & Server Management, the cloud and server guide, or contact us.

Frequently asked questions

Is the free Cloudflare plan enough?

For many small sites, yes. Paid plans add more WAF rules, image optimisation and other features. We recommend a plan only if you need what it adds.

Will Cloudflare break my website?

It can if caching or security rules are too aggressive. We start conservatively and test logins, carts, forms and APIs before tightening.

Do I need to move my domain to Cloudflare?

You change nameservers to Cloudflare; the domain registration can stay with your current registrar.

Does Cloudflare replace server security?

No. It filters web traffic, but the server still needs hardening, patching and a firewall. The two work together.

Can Cloudflare help if my server is unreachable from some networks?

Often, yes. Because visitors connect to Cloudflare rather than your server directly, proxying can restore access where a route to your server’s IP is unreliable from certain networks or regions.

Talk to us about cloudflare setup

CDN, WAF, caching rules and DDoS protection sitting in front of your site.

Let's talk

Have something you need built, hosted or fixed?

Tell us what you are trying to do. If we are not the right people for it, we will say so.