- Compatible XF versions
- 2.3
Everything is available from within XenForo (you don't need to access Cloudflare to do anything) via the Cloudflare API. This allows you to grant admins permission to do certain things (e.g. block IP addresses in Cloudflare without giving them access to your Cloudflare account).
It simplifies/automates much of the configuration and usage of Cloudflare with XenForo.

It simplifies/automates much of the configuration and usage of Cloudflare with XenForo.
- Manage all Cloudflare options/settings for your region.
- Ability to clear Cloudflare cache .
- Cloudflare FirewallSupport
- You can automatically create firewall filters to block access to XenForo internal directories not intended to be accessed via a web browser (internal_data and src). You can also remove any firewall filters.
- Create/delete firewall user agent rules .
- Create/delete firewall IP address rules . Includes the ability to optionally expire rules in the future (e.g. maybe you want to block class C for 7 days or you want to force a challenge on a specific IP for 30 days).
- Manage country-level traffic blocking (including Tor exit nodes).
- Cloudflare AccessSupport
- You can automatically create an Access policy to only allow administrators access to the install URL and admin.php. You can also delete any existing access policies.
- Cloudflare Page RulesSupport
- You can automatically create a Page Rule that will instruct Cloudflare to cache XenForo CSS files (they are not normally cached because Cloudflare caches based on file extension and XenForo's CSS system has a .php extension).
- You can automatically create a Page Rule that will instruct Cloudflare to cache images served through XenForo's image proxy (similar to XenForo's CSS, Cloudflare typically doesn't cache it because the image proxy uses a .php extension).
- Supports both global API keys and API tokens. API tokens allow for minimal permissions required and are cross-domain scalable (you can use the same API token across multiple XenForo installations/domains without granting any unnecessary permissions).
- Moderators who are able to clean spam and view user IPs will have an additional option in the spam cleaner where they can temporarily ban the IP address(es) that the spammer has used in the last 30 days. The number of days of ban is an option you can set in the admin area (it defaults to 7 days).
- Ability to backup and restorecertain Cloudflare configurations (Application Access, Firewall Rules, Firewall IP Access Rules, Firewall User Agent Blocking, Page Rules).
- You can restore backups to another region (for example, if you have an extended configuration for one region, you can provide another region with the same configuration through a backup restore).
- Restoring a backup does not delete existing configurations (you can merge the configuration into an existing configuration).
- Cloudflare configuration is protected by the new Manage Cloudflare admin privilege.









