cPanel Apache mod_remoteip Cloudflare Trusted Proxy in Pakistan (2026)

Restore real visitor client IPs behind Cloudflare on cPanel Apache servers in Pakistan. Configure mod_remoteip, automated CIDR syncing, LogFormat %a, and security WAF unblocking.

cPanel Apache mod_remoteip Cloudflare Trusted Proxy in Pakistan (2026)

When websites in Pakistan deploy Cloudflare’s reverse proxy to protect against volumetric DDoS attacks and accelerate static assets, web server administrators immediately face an unintended operational crisis: Every visitor appears to originate from Cloudflare’s edge IP addresses.

In cPanel EasyApache 4, this reverse proxy masking leads to catastrophic side effects:

  1. False-Positive Security Bans: Security modules such as ModSecurity, Imunify360, and cPHulk observe hundreds of requests originating from a single IP (a Cloudflare edge node) and blacklist it, inadvertently disconnecting thousands of legitimate Pakistani visitors.
  2. Corrupted Access Logs: Apache access_log files and AWStats record Cloudflare data centers rather than local visitor locations across Karachi, Lahore, and Islamabad.
  3. Application Logic Failures: Geo-location modules, currency switchers, and fraud detection systems in WooCommerce or Laravel fail because $_SERVER['REMOTE_ADDR'] contains proxy addresses.

The definitive solution is properly configuring Apache’s mod_remoteip module.


1. How Apache mod_remoteip Restores Client Visibility

When a Pakistani visitor connects to your site via Cloudflare, Cloudflare forwards the original visitor’s real IP address in custom HTTP request headers, primarily CF-Connecting-IP and X-Forwarded-For.

Without mod_remoteip, Apache parses the TCP socket connection address directly, reading Cloudflare’s edge node IP. With mod_remoteip enabled and configured with Cloudflare’s trusted IP ranges, Apache transparently replaces the socket address with the value supplied in CF-Connecting-IP.

[Pakistani Visitor: 103.151.44.120]
                 │
                 ▼
[Cloudflare Edge Node: 172.68.22.45] ──(HTTP Header: CF-Connecting-IP: 103.151.44.120)──►
                 │
                 ▼
[cPanel Apache Server with mod_remoteip]
  - Validates 172.68.22.45 is in RemoteIPTrustedProxyList
  - Overwrites %h / REMOTE_ADDR with 103.151.44.120
                 │
                 ▼
[ModSecurity, cPHulk, PHP & Access Logs see REAL Client IP: 103.151.44.120]

To run enterprise web clusters with high connection volumes, dedicated bare-metal servers eliminate CPU hypervisor limits. Explore our robust Dedicated Servers and localized Dedicated Servers in Pakistan deployed with redundant gigabit uplinks.


2. Enabling mod_remoteip in EasyApache 4

Verify that mod_remoteip is installed and compiled into your EasyApache 4 build:

# Check if mod_remoteip is loaded in Apache
httpd -M | grep -i remoteip

If it does not appear in the output, install it via the package manager:

# On AlmaLinux / CloudLinux / Rocky Linux
dnf install -y ea-apache24-mod_remoteip

# Verify module loading
httpd -M | grep remoteip

Output:

 remoteip_module (shared)

3. Configuring Trusted Proxy CIDRs in cPanel

To prevent spoofing (where an attacker crafts an arbitrary CF-Connecting-IP header directly to bypass firewall rules), Apache must only trust proxy headers originating from verified Cloudflare IP blocks.

Step 1: Create an Automated Cloudflare IP Sync Script

Create /usr/local/bin/update_cloudflare_ips.sh:

#!/bin/bash
# Script to fetch current Cloudflare IP ranges and rebuild Apache trusted list
CLOUDFLARE_FILE="/etc/apache2/conf.d/cloudflare_ips.txt"
TMP_FILE="/tmp/cf_ips.tmp"

# Fetch IPv4 and IPv6 blocks from Cloudflare's official API
curl -s -f https://www.cloudflare.com/ips-v4 > "$TMP_FILE"
echo "" >> "$TMP_FILE"
curl -s -f https://www.cloudflare.com/ips-v6 >> "$TMP_FILE"

if [ -s "$TMP_FILE" ]; then
    mv "$TMP_FILE" "$CLOUDFLARE_FILE"
    chmod 0644 "$CLOUDFLARE_FILE"
    echo "[$(date)] Cloudflare IP ranges successfully updated."
    # Gracefully reload Apache to apply changes
    systemctl reload httpd
else
    echo "[$(date)] Failed to fetch Cloudflare IP ranges!" >&2
    rm -f "$TMP_FILE"
    exit 1
fi

Make it executable and execute it:

chmod +x /usr/local/bin/update_cloudflare_ips.sh
/usr/local/bin/update_cloudflare_ips.sh

Add a monthly cron job in /etc/cron.monthly/update_cf_ips:

ln -s /usr/local/bin/update_cloudflare_ips.sh /etc/cron.monthly/update_cf_ips

Step 2: Inject Global Apache Pre-VirtualHost Directive

In cPanel & WHM, custom global Apache directives must be placed in the include directories to survive automatic cPanel updates.

Edit /etc/apache2/conf.d/includes/pre_virtualhost_global.conf:

<IfModule remoteip_module>
    # Header passed by Cloudflare containing visitor real IP
    RemoteIPHeader CF-Connecting-IP
    
    # Path to verified Cloudflare CIDR blocks
    RemoteIPTrustedProxyList /etc/apache2/conf.d/cloudflare_ips.txt
</IfModule>

4. Updating Apache LogFormat to Record Real IPs

By default, Apache logs client hostnames or IPs using %h. Under mod_remoteip, %h continues to log the proxy IP, whereas %a records the authenticated client IP resolved by mod_remoteip.

Updating LogFormat via WHM:

  1. Log into WHM as root.
  2. Navigate to: Home » Service Configuration » Apache Configuration » Global Configuration.
  3. Locate LogFormat (combined).
  4. Replace the initial %h with %a:
    %a %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"
  5. Click Save and Rebuild Configuration and Restart Apache.

5. Testing and Verifying Real IP Resolution

Create a temporary diagnostic PHP script in your domain’s public_html:

<?php
// ip_test.php
header('Content-Type: text/plain');
echo "REMOTE_ADDR:          " . $_SERVER['REMOTE_ADDR'] . "\n";
echo "HTTP_CF_CONNECTING_IP: " . ($_SERVER['HTTP_CF_CONNECTING_IP'] ?? 'Not Set') . "\n";
echo "HTTP_X_FORWARDED_FOR:  " . ($_SERVER['HTTP_X_FORWARDED_FOR'] ?? 'Not Set') . "\n";
?>

Query the URL through your browser:

REMOTE_ADDR:          103.151.44.120  <-- Successfully restored!
HTTP_CF_CONNECTING_IP: 103.151.44.120
HTTP_X_FORWARDED_FOR:  103.151.44.120, 172.68.22.45

When REMOTE_ADDR matches HTTP_CF_CONNECTING_IP, ModSecurity, cPHulk, and application rate limiters function correctly without risking widespread service blackouts. Remember to delete ip_test.php once verified.

For further cPanel security tuning and brute-force mitigation, read our deep architectural guides on cPanel cPHulk Brute Force SQLite Backend Tuning and cPanel PHP-FPM Status Page & Slowlog Deep Tuning. If you require scalable cloud architecture, explore our Cloud VPS hosting solutions.


ENTERPRISE CLOUD ARCHITECTURE

Deploy Bare-Metal Dedicated Servers in Pakistan

Eliminate reverse proxy bottlenecks, hypervisor latency, and resource contention. Nextgen delivers AMD EPYC bare-metal compute housed in high-security Tier-3 Pakistani datacenters.