OpenLiteSpeed + Cloudflare configuration
Budget: €8 – €30 EUR
Hello,
I would like to have a good DDoS Protection for my website, and I would like to configure OpenLiteSpeed DDoS Protection (https://docs.litespeedtech.com/lsws/cp/cpanel/antiddos/) + Cloudflare. At the moment I am using Cloudflare in front of the real IP address of my VPS.
In particularly I would like to set ReCAPTCHA https://openlitespeed.org/kb/recaptcha-with-openlitespeed/ but I have some issues with it, as well as with "Per Client Throttling" settings.
Configuration:
Use Client IP in Header is in Trusted IP Only
Allowed List contains Cloudflare IPs
LS reCAPTCHA Max Tries is on 10, but why when someone visit the page for the first time my website and reload the page, it will have 403 Forbidden error even if it is the first try with Captcha?
Also I can't use Per Client Throttling, because if I use it, it will not block the Visitor IPs, but Cloudflare IPs, resulting in my website being offline for everyone. I don't really understand where the issue is.
While we get the real visitors IPs it looks like ReCAPTCHA is blocking Cloudflare IPs, because everyone will be blocked even if they performed the Captcha or even if you reload the page for the first time without performing the captcha, it will redirect you instantly to 403 error page instead of letting you try until 10 times.
Also, in our VPS, we blocked connections with iptables on port 80 and 443 every IPs except Cloudflare IPs, so if someone know our real IP behind Cloudflare, they can't attack us because only Cloudflare IPs are allowed.
I would like to have a good DDoS Protection for my website, and I would like to configure OpenLiteSpeed DDoS Protection (https://docs.litespeedtech.com/lsws/cp/cpanel/antiddos/) + Cloudflare. At the moment I am using Cloudflare in front of the real IP address of my VPS.
In particularly I would like to set ReCAPTCHA https://openlitespeed.org/kb/recaptcha-with-openlitespeed/ but I have some issues with it, as well as with "Per Client Throttling" settings.
Configuration:
Use Client IP in Header is in Trusted IP Only
Allowed List contains Cloudflare IPs
LS reCAPTCHA Max Tries is on 10, but why when someone visit the page for the first time my website and reload the page, it will have 403 Forbidden error even if it is the first try with Captcha?
Also I can't use Per Client Throttling, because if I use it, it will not block the Visitor IPs, but Cloudflare IPs, resulting in my website being offline for everyone. I don't really understand where the issue is.
While we get the real visitors IPs it looks like ReCAPTCHA is blocking Cloudflare IPs, because everyone will be blocked even if they performed the Captcha or even if you reload the page for the first time without performing the captcha, it will redirect you instantly to 403 error page instead of letting you try until 10 times.
Also, in our VPS, we blocked connections with iptables on port 80 and 443 every IPs except Cloudflare IPs, so if someone know our real IP behind Cloudflare, they can't attack us because only Cloudflare IPs are allowed.