Hướng Dẫn Cloudflare Cho VPS Toàn Tập 2026 - CDN, SSL, WAF, DDoS Protection Miễn Phí
Bạn có VPS nhưng website vẫn chậm với user ở xa? Sợ DDoS làm sập server? Muốn có SSL miễn phí tự động gia hạn? Cloudflare là câu trả lời — và nó miễn phí. Bài viết này hướng dẫn toàn tập cách tích hợp Cloudflare với VPS: từ DNS, CDN, SSL Full Strict, WAF, Firewall Rules, đến Argo Tunnel và Workers. Tất cả đều có hướng dẫn từng bước cụ thể.
1. Cloudflare Là Gì? Tại Sao Cần Cho VPS?
Cloudflare là mạng lưới reverse proxy toàn cầu với hơn 300 datacenter. Khi bạn dùng Cloudflare:
- CDN miễn phí: File tĩnh (CSS, JS, ảnh) được cache tại datacenter gần user nhất → load nhanh hơn 2-5 lần
- DDoS Protection: Cloudflare hấp thụ DDoS attack (lên đến Tbps) trước khi nó tới VPS bạn
- SSL/TLS miễn phí: Tự động cấp và gia hạn SSL, hỗ trợ cả HTTP/2, HTTP/3
- WAF (Web Application Firewall): Chặn SQL injection, XSS, bot xấu theo ruleset OWASP
- Ẩn IP thật của VPS: User chỉ thấy IP của Cloudflare, không biết IP VPS của bạn
- DNS nhanh: Cloudflare DNS (1.1.1.1) nhanh nhất thế giới, propagate 1-2 phút
2. Setup Cloudflare Cho VPS — 3 Bước Cơ Bản
Bước 1: Thêm Domain Vào Cloudflare
- Đăng ký tài khoản miễn phí tại
cloudflare.com - Add Site → nhập domain của bạn → chọn Free plan
- Cloudflare quét DNS records hiện tại → xác nhận đúng hết
- Cloudflare cấp 2 nameserver mới (vd:
alice.ns.cloudflare.com) - Vào nhà đăng ký domain → đổi nameserver sang Cloudflare
- Đợi 5-30 phút để DNS propagate
Bước 2: Cấu Hình DNS Records
Sau khi domain active trên Cloudflare, cấu hình DNS:
| Type | Name | Content | Proxy |
|---|---|---|---|
| A | @ | IP VPS của bạn | 🟠 Proxied |
| A | www | IP VPS của bạn | 🟠 Proxied |
| CNAME | Domain | ⚪ DNS only |
Quan trọng: Bật proxy (mây cam) cho web traffic. Tắt proxy (mây xám) cho mail server, SSH, game server.
Bước 3: Cấu Hình SSL/TLS
Vào SSL/TLS → Overview → chọn Full (strict). Đây là chế độ an toàn nhất:
- Flexible: Cloudflare ↔ VPS qua HTTP (KHÔNG an toàn)
- Full: Cloudflare ↔ VPS qua HTTPS (chấp nhận self-signed cert)
- Full (strict): Cloudflare ↔ VPS qua HTTPS (bắt buộc cert hợp lệ từ CA) ✅
Cần có SSL trên VPS. Dùng Let's Encrypt (miễn phí): certbot --nginx -d yourdomain.com
3. Tối Ưu Cache — Tăng Tốc Website 2-5 Lần
3.1. Caching Rules
Cloudflare tự động cache file tĩnh. Để tối ưu thêm, vào Caching → Configuration:
- Caching Level: Standard (cache cả query string)
- Browser Cache TTL: 1 year
- Always Online: Bật — nếu VPS die, Cloudflare serve bản cache
3.2. Cache Rules (Custom)
Tạo rule để cache mạnh hơn cho static assets:
URI path matches: *.css, *.js, *.jpg, *.png, *.svg, *.woff2
→ Cache: Eligible for cache
→ Edge TTL: 30 days
→ Browser TTL: 1 year
Tạo rule KHÔNG cache cho admin page:
URI path contains: /wp-admin, /wp-login
→ Cache: Bypass cache
3.3. Auto Minify & Brotli
Speed → Optimization → bật Auto Minify cho CSS, JS, HTML. Bật Brotli (nén tốt hơn Gzip 15-20%). Test kỹ sau khi bật — một số theme/plugin có thể bị lỗi.
4. Bảo Mật VPS Với Cloudflare WAF & Firewall
4.1. WAF (Web Application Firewall)
Security → WAF → Managed Rules → bật Cloudflare Managed Ruleset (Free). Nó tự động chặn SQL injection, XSS, path traversal, bot xấu. Có thể tùy chỉnh mức độ: Low / Medium / High.
4.2. Firewall Rules (Custom Rules)
Tạo rule chặn theo IP, country, user agent:
Expression: (ip.geoip.country eq "CN") or (ip.geoip.country eq "RU")
Action: Block hoặc JS Challenge
Chặn bot crawl quá đà:
Expression: (cf.threat_score gt 30)
Action: JS Challenge
4.3. Rate Limiting
Security → Rate Limiting → tạo rule:
Path: /wp-login.php
Period: 10 seconds
Requests: 5
Action: Block (10 minutes)
Chỉ 5 lần thử login mỗi 10 giây → chặn brute force hoàn toàn.
4.4. Bot Fight Mode
Security → Bots → bật Bot Fight Mode — chặn bot xấu tự động. Nếu cần chặn cả bot SEO tools/AI crawler, dùng custom WAF rule.
5. Ẩn IP Thật Của VPS
Khi bật Cloudflare proxy, user không thấy IP thật. Nhưng IP vẫn có thể bị lộ qua:
- MX record: Email header lộ IP. Fix: dùng email service riêng (Google Workspace, Zoho)
- DNS history: Có thể tra DNS cũ. Fix: đổi IP VPS sau khi bật Cloudflare
- Direct IP access: Ai đó truy cập thẳng IP VPS. Fix: tạo default server block trong Nginx chỉ trả lời cho domain của bạn
Chặn direct IP access trên Nginx:
server {
listen 80 default_server;
server_name _;
return 444; # Drop connection
}
6. Tính Năng Nâng Cao (Free Plan)
6.1. Argo Tunnel / Cloudflare Tunnel
Kết nối VPS với Cloudflare qua tunnel an toàn — không cần mở port 80/443. Xem: Cài Cloudflare Tunnel trên VPS.
6.2. Cloudflare Workers (100K requests/ngày free)
Deploy JavaScript code chạy trên edge của Cloudflare. Ví dụ: redirect mobile user, A/B testing, custom header.
6.3. Transform Rules
Rewrite URL, thêm/sửa header. Ví dụ: thêm security header cho mọi response:
Rules → Transform Rules → Modify Response Header
Set: X-Content-Type-Options = nosniff
Set: X-Frame-Options = SAMEORIGIN
6.4. Page Rules (3 rules free)
Tạo cache rule đặc biệt cho URL pattern:
URL: yourdomain.com/wp-content/*
Cache Level: Cache Everything
Edge Cache TTL: 30 days
7. Cloudflare + VPS TrumVPS = Combo Hoàn Hảo
| Thành phần | Không có Cloudflare | Có Cloudflare |
|---|---|---|
| Tốc độ user quốc tế | Chậm (phụ thuộc vị trí VPS) | Nhanh (CDN 300+ datacenter) |
| DDoS protection | Không (VPS dễ sập) | Có (Cloudflare hấp thụ) |
| SSL | Phải tự cài + gia hạn | Tự động |
| Bandwidth tiết kiệm | 0% | 60-80% (Cloudflare cache) |
| Bot & spam | Vào thẳng VPS | Bị chặn ở Cloudflare |
| Ẩn IP | Không | Có |
| Chi phí | 0đ | 0đ (Free plan) |
Bắt Đầu Với VPS + Cloudflare Ngay
VPS TrumVPS 40K/tháng + Cloudflare Free = website nhanh, bảo mật, chống DDoS
🚀 Thuê VPS + Cài Cloudflare