When websites in Pakistan deploy Cloudflare’s reverse proxy to protect against volumetric DDoS attacks and accelerate static assets, web server administrators immediately face an unintended operational crisis: Every visitor appears to originate from Cloudflare’s edge IP addresses.
In cPanel EasyApache 4, this reverse proxy masking leads to catastrophic side effects:
- False-Positive Security Bans: Security modules such as ModSecurity, Imunify360, and cPHulk observe hundreds of requests originating from a single IP (a Cloudflare edge node) and blacklist it, inadvertently disconnecting thousands of legitimate Pakistani visitors.
- Corrupted Access Logs: Apache
access_logfiles and AWStats record Cloudflare data centers rather than local visitor locations across Karachi, Lahore, and Islamabad. - Application Logic Failures: Geo-location modules, currency switchers, and fraud detection systems in WooCommerce or Laravel fail because
$_SERVER['REMOTE_ADDR']contains proxy addresses.
The definitive solution is properly configuring Apache’s mod_remoteip module.
1. How Apache mod_remoteip Restores Client Visibility
When a Pakistani visitor connects to your site via Cloudflare, Cloudflare forwards the original visitor’s real IP address in custom HTTP request headers, primarily CF-Connecting-IP and X-Forwarded-For.
Without mod_remoteip, Apache parses the TCP socket connection address directly, reading Cloudflare’s edge node IP. With mod_remoteip enabled and configured with Cloudflare’s trusted IP ranges, Apache transparently replaces the socket address with the value supplied in CF-Connecting-IP.
[Pakistani Visitor: 103.151.44.120]
│
▼
[Cloudflare Edge Node: 172.68.22.45] ──(HTTP Header: CF-Connecting-IP: 103.151.44.120)──►
│
▼
[cPanel Apache Server with mod_remoteip]
- Validates 172.68.22.45 is in RemoteIPTrustedProxyList
- Overwrites %h / REMOTE_ADDR with 103.151.44.120
│
▼
[ModSecurity, cPHulk, PHP & Access Logs see REAL Client IP: 103.151.44.120]
To run enterprise web clusters with high connection volumes, dedicated bare-metal servers eliminate CPU hypervisor limits. Explore our robust Dedicated Servers and localized Dedicated Servers in Pakistan deployed with redundant gigabit uplinks.
2. Enabling mod_remoteip in EasyApache 4
Verify that mod_remoteip is installed and compiled into your EasyApache 4 build:
# Check if mod_remoteip is loaded in Apache
httpd -M | grep -i remoteip
If it does not appear in the output, install it via the package manager:
# On AlmaLinux / CloudLinux / Rocky Linux
dnf install -y ea-apache24-mod_remoteip
# Verify module loading
httpd -M | grep remoteip
Output:
remoteip_module (shared)
3. Configuring Trusted Proxy CIDRs in cPanel
To prevent spoofing (where an attacker crafts an arbitrary CF-Connecting-IP header directly to bypass firewall rules), Apache must only trust proxy headers originating from verified Cloudflare IP blocks.
Step 1: Create an Automated Cloudflare IP Sync Script
Create /usr/local/bin/update_cloudflare_ips.sh:
#!/bin/bash
# Script to fetch current Cloudflare IP ranges and rebuild Apache trusted list
CLOUDFLARE_FILE="/etc/apache2/conf.d/cloudflare_ips.txt"
TMP_FILE="/tmp/cf_ips.tmp"
# Fetch IPv4 and IPv6 blocks from Cloudflare's official API
curl -s -f https://www.cloudflare.com/ips-v4 > "$TMP_FILE"
echo "" >> "$TMP_FILE"
curl -s -f https://www.cloudflare.com/ips-v6 >> "$TMP_FILE"
if [ -s "$TMP_FILE" ]; then
mv "$TMP_FILE" "$CLOUDFLARE_FILE"
chmod 0644 "$CLOUDFLARE_FILE"
echo "[$(date)] Cloudflare IP ranges successfully updated."
# Gracefully reload Apache to apply changes
systemctl reload httpd
else
echo "[$(date)] Failed to fetch Cloudflare IP ranges!" >&2
rm -f "$TMP_FILE"
exit 1
fi
Make it executable and execute it:
chmod +x /usr/local/bin/update_cloudflare_ips.sh
/usr/local/bin/update_cloudflare_ips.sh
Add a monthly cron job in /etc/cron.monthly/update_cf_ips:
ln -s /usr/local/bin/update_cloudflare_ips.sh /etc/cron.monthly/update_cf_ips
Step 2: Inject Global Apache Pre-VirtualHost Directive
In cPanel & WHM, custom global Apache directives must be placed in the include directories to survive automatic cPanel updates.
Edit /etc/apache2/conf.d/includes/pre_virtualhost_global.conf:
<IfModule remoteip_module>
# Header passed by Cloudflare containing visitor real IP
RemoteIPHeader CF-Connecting-IP
# Path to verified Cloudflare CIDR blocks
RemoteIPTrustedProxyList /etc/apache2/conf.d/cloudflare_ips.txt
</IfModule>
4. Updating Apache LogFormat to Record Real IPs
By default, Apache logs client hostnames or IPs using %h. Under mod_remoteip, %h continues to log the proxy IP, whereas %a records the authenticated client IP resolved by mod_remoteip.
Updating LogFormat via WHM:
- Log into WHM as
root. - Navigate to: Home » Service Configuration » Apache Configuration » Global Configuration.
- Locate LogFormat (combined).
- Replace the initial
%hwith%a:%a %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\" - Click Save and Rebuild Configuration and Restart Apache.
5. Testing and Verifying Real IP Resolution
Create a temporary diagnostic PHP script in your domain’s public_html:
<?php
// ip_test.php
header('Content-Type: text/plain');
echo "REMOTE_ADDR: " . $_SERVER['REMOTE_ADDR'] . "\n";
echo "HTTP_CF_CONNECTING_IP: " . ($_SERVER['HTTP_CF_CONNECTING_IP'] ?? 'Not Set') . "\n";
echo "HTTP_X_FORWARDED_FOR: " . ($_SERVER['HTTP_X_FORWARDED_FOR'] ?? 'Not Set') . "\n";
?>
Query the URL through your browser:
REMOTE_ADDR: 103.151.44.120 <-- Successfully restored!
HTTP_CF_CONNECTING_IP: 103.151.44.120
HTTP_X_FORWARDED_FOR: 103.151.44.120, 172.68.22.45
When REMOTE_ADDR matches HTTP_CF_CONNECTING_IP, ModSecurity, cPHulk, and application rate limiters function correctly without risking widespread service blackouts. Remember to delete ip_test.php once verified.
For further cPanel security tuning and brute-force mitigation, read our deep architectural guides on cPanel cPHulk Brute Force SQLite Backend Tuning and cPanel PHP-FPM Status Page & Slowlog Deep Tuning. If you require scalable cloud architecture, explore our Cloud VPS hosting solutions.
Deploy Bare-Metal Dedicated Servers in Pakistan
Eliminate reverse proxy bottlenecks, hypervisor latency, and resource contention. Nextgen delivers AMD EPYC bare-metal compute housed in high-security Tier-3 Pakistani datacenters.
