Tutorial Tutorial Tutorial Application Services Application Services Application Services ~24 phút ~24 min ~24 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Thiết lập nguồn riêng tư thông qua Cloudflare WAN Set up a private origin via Cloudflare WAN ការបង្កើតប្រភពឯកជនតាម Cloudflare WAN

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Thiết lập private origin via Cloudflare WAN» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Docs gốc chia khoảng 3 bước chính; bản tóm tắt dưới đây giúp bạn nắm khung trước khi làm theo từng lệnh.

Proxy public hostnames to private origins through a Cloudflare WAN IPsec tunnel.

ទាញយកប្រព័ន្ធប្រតិបត្តិការ WAN IPsec tunnel សម្រាប់ប្រព័ន្ធប្រតិបត្តិការ WAN

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Overview Overview Overview

Hướng dẫn này chỉ cách proxying public hostnames to origins on a private network. The private network is reachable through a Cloudflare WAN (formerly Magic WAN) IPsec tunnel. The CDN, WAF, Cache, and other proxied features apply to this traffic the same way they apply to traff…

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hướng dẫn này hướng dẫn bạn thông qua việc chuyển tên máy chủ công cộng sang nguồn gốc trên mạng riêng. Mạng riêng có thể truy cập thông qua Cloudflare WAN (trước đây là Magic WAN) IPsec tunnel. Các CDN, WAF, Cache, và các tính năng proxy khác áp dụng cho lưu lượng truy cập này theo cách tương tự như họ áp dụng cho lưu lượng truy cập dành cho nguồn gốc công cộng.
This guide walks you through proxying public hostnames to origins on a private network. The private network is reachable through a Cloudflare WAN (formerly Magic WAN) IPsec tunnel. The CDN, WAF, Cache, and other proxied features apply to this traffic the same way they apply to traffic destined for public origins.
វគ្គបណ្តុះបណ្តាលនេះដំណើរការអ្នកតាមរយៈការផ្លាស់ប្តូរប្រព័ន្ធប្រតិបត្តិការសាធារណៈទៅជាប្រភពនៅលើបណ្តាញឯកជន។ កុំព្យូទ័រអាចរកបានតាមរយៈ Cloudflare WAN (មុន Magic WAN) IPsec tunnel ។ ការ CDN, WAF, Cache, និងលក្ខណៈពិសេស proxy ផ្សេងទៀតត្រូវបានអនុវត្តទៅនឹងការដឹកជញ្ជូននេះដូចគ្នានឹងអនុវត្តទៅនឹងការដឹកជញ្ជូនដែលមានគោលបំណងសម្រាប់ប្រភពសាធារណៈ។
đóng cửa beta
Closed beta
ដំណឹង Beta
Tính năng này hiện đang trong phiên bản beta đóng. Để yêu cầu access, hãy liên hệ với nhóm tài khoản Cloudflare của bạn.
This feature is in closed beta. To request access, contact your Cloudflare account team.
វាត្រូវបានគេហទំព័រនេះនៅពេលបច្ចុប្បន្ន beta. ដើម្បីស្វែងរក access សូមទាក់ទងជាមួយក្រុមប្រឹក្សាភិបាលគណនីរបស់អ្នក Cloudflare ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Trước khi bạn bắt đầu Before you begin មុនពេលដែលអ្នកចាប់ផ្តើម

Phần «Before you begin» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Before you begin" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «មុនពេលដែលអ្នកចាប់ផ្តើម» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Hãy xác nhận những điều sau đây trước khi bạn bắt đầu:
Confirm the following before you start:
សូមអនុញ្ញាតឱ្យអ្នកបញ្ជាក់ដូចខាងក្រោមមុនពេលអ្នកចាប់ផ្តើម:
  • Active Cloudflare WAN subscription: Tính năng này yêu cầu đăng ký WAN Cloudflare trên tài khoản của bạn.
  • Access to private origins enabled on your account: Đây là quyền riêng biệt từ tiêu chuẩn có thẩm quyền DNS access. Liên hệ với nhóm tài khoản Cloudflare của bạn để yêu cầu access.
  • IPsec tunnels configured: Thiết lập hai đường hầm IPsec anycast cho sự dư thừa, mỗi đường hầm có điểm cuối anycast khác nhau Cloudflare. Nhắc đến Configure tunnel endpoints Hai cài đặt là quan trọng cho trường hợp sử dụng này:
  • Active Cloudflare WAN subscription: This capability requires a Cloudflare WAN subscription on your account.
  • Access to private origins enabled on your account: This is a separate entitlement from standard authoritative DNS access. Contact your Cloudflare account team to request access.
  • IPsec tunnels configured: Set up two anycast IPsec tunnels for redundancy, each with a different Cloudflare anycast endpoint. Refer to Configure tunnel endpoints. Two settings are important for this use case:
  • Active Cloudflare WAN subscription: សមត្ថភាពនេះត្រូវការការគណនី Cloudflare WAN នៅលើគណនីរបស់អ្នក។
  • Access to private origins enabled on your account: នេះគឺជាការអនុញ្ញាតដោយផ្ទាល់ពីការអនុញ្ញាតទូទៅ DNS access ។ សូមទាក់ទងជាមួយក្រុមប្រឹក្សាភិបាលគណនីរបស់អ្នក Cloudflare ដើម្បីស្វែងរក access ។
  • IPsec tunnels configured: បានបង្កើតទីផ្សារ IPsec ទាំងអស់ទាំងពីរសម្រាប់ការ redundancy, ទាំងអស់ជាមួយនឹង Cloudflare ដំណាក់កាលទាំងអស់។ សូមអរគុណ Configure tunnel endpoints ការផ្លាស់ប្តូរទាំងពីរគឺជាការសំខាន់សម្រាប់ការប្រើប្រាស់នេះ:
Leave Automatic return routing bị vô hiệu hóa. Nó không áp dụng cho mô hình lưu lượng truy cập nguồn gốc từ công cộng đến tư nhân, nơi các yêu cầu bắt nguồn từ Internet và đến nguồn gốc của bạn thông qua proxy ngược của Cloudflare. Giữ các cài đặt Health check mặc định (chọn reply, hướng bidirectional, tỷ lệ mid). Những mặc định này là cần thiết cho tunnel sức khỏe để theo dõi chính xác trong trường hợp sử dụng này.
Leave Automatic return routing disabled. It does not apply to the public-to-private origin traffic pattern, where requests originate on the Internet and reach your origin through Cloudflare's reverse proxy. Keep the default Health check settings (type reply, direction bidirectional, rate mid). These defaults are required for tunnel health to track correctly in this use case.
Leave Automatic return routing កាត់បន្ថយ វាត្រូវបានអនុវត្តសម្រាប់គំរូការដឹកជញ្ជូនប្រភពឯកជនទៅប្រភពសាធារណៈដែលទម្រង់មកពីអ៊ីនធឺណិតនិងទទួលបានការដឹកជញ្ជូនប្រភពរបស់អ្នកតាមរយៈការផ្លាស់ប្តូរ Cloudflare ។ រក្សាទុកការកំណត់ Health check ជាទូទៅ (ប្រភេទ reply, គោលបំណង bidirectional, កម្រិត mid) ។ នេះជាការចាំបាច់ដើម្បី tunnel សុខភាពដើម្បីរក្សាទុកយ៉ាងត្រឹមត្រូវនៅក្នុងការប្រើប្រាស់នេះ។
  • Static routes configured: Thêm hai tuyến đường tĩnh cho tiền tố riêng mà bạn muốn tiếp cận - một cho mỗi tunnel - với các ưu tiên khác nhau để lưu lượng truy cập không chuyển sang sao lưu tunnel nếu chính đi xuống. Ví dụ, đặt ưu tiên 100 trên tuyến đường thông qua tunnel chính của bạn và 101 trên tuyến đường thông qua sao lưu tunnel của bạn (số thấp hơn là ưu tiên cao hơn). Nhắc đến Configure routes
  • Cloudflare Source IP set to a private range: Cloudflare Nguồn IP là IP mà Cloudflare sử dụng khi gửi yêu cầu proxy vào mạng riêng của bạn. Nếu nó được để lại như một phạm vi công cộng, mạng của bạn không thể định tuyến lưu lượng truy cập trở lại thông qua tunnel và yêu cầu thời gian ra. Nhắc đến Configure Cloudflare source IPs
  • Static routes configured: Add two static routes for the private prefix you want to reach — one per tunnel — with different priorities so traffic fails over to the backup tunnel if the primary goes down. For example, set priority 100 on the route through your primary tunnel and 101 on the route through your backup tunnel (lower numbers are higher priority). Refer to Configure routes.
  • Cloudflare Source IP set to a private range: The Cloudflare Source IP is the IP that Cloudflare uses when sending proxied requests into your private network. If it is left as a public range, your network cannot route the return traffic back through the tunnel and requests time out. Refer to Configure Cloudflare source IPs.
  • Static routes configured: Add two static routes for the private prefix you want to reach — one per tunnel — with different priorities so traffic fails to the backup tunnel if the primary goes down. លក្ខណៈពិសេសរបស់អ្នកគឺ 100 នៅលើដំណើរការតាមដំណើរការ tunnel និង 101 នៅលើដំណើរការតាមដំណើរការតាមដំណើរការតាមដំណើរការតាមដំណើរការ tunnel ។ សូមអរគុណ Configure routes ។
  • Cloudflare Source IP set to a private range: ទិន្នន័យ Cloudflare ទិន្នន័យ IP គឺជាទិន្នន័យ IP ដែល Cloudflare ប្រើក្នុងការផ្ញើសំណួរ proxy ទៅលើបណ្តាញឯកជនរបស់អ្នក។ ប្រសិនបើវាត្រូវបានផ្ដល់ឱ្យជាតម្រូវការចែករំលែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចែកចាយចែកចែកចាយចែកចាយចែកចាយចាយចែកចាយចែកចាយចែកចាយចាយចែកចាយចែកចាយច សូមអរគុណ Configure Cloudflare source IPs

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

1.Điều Kiểm tra Cloudflare Nguồn IP Allocation 1. Verify your Cloudflare Source IP allocation 1 ។ សូមពិនិត្យមើល Cloudflare ទិន្នន័យ IP

Phần «Xác minh your Cloudflare Source IP allocation» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "1. Verify your Cloudflare Source IP allocation" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «1 ។ សូមពិនិត្យមើល Cloudflare ទិន្នន័យ IP» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Một cấu hình sai Cloudflare Nguồn IP là nguyên nhân phổ biến nhất của sự thất bại. Nếu Nguồn IP được để lại như là một phạm vi công cộng, mạng nơi nguồn của bạn sống không có đường trở lại và yêu cầu thời gian ra trước khi đến ứng dụng.
A misconfigured Cloudflare Source IP is the most common cause of failure. If the Source IP is left as a public range, the network where your origin lives has no return route and requests time out before reaching the application.
ទិន្នន័យដែលបានកែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រែប្រ ប្រសិនបើប្រភព IP ត្រូវបានបាត់បង់ជាតម្រូវការសាធារណៈបន្ទាប់មកប្រព័ន្ធផ្សព្វផ្សាយដែលអ្នកមានតម្រូវការរបស់អ្នកមិនមានផ្លូវដំណើរការមកវិញហើយគួរតែបញ្ចប់ពេលវេលាមុនពេលដែលអ្នកចូលទៅក្នុងកម្មវិធី។
Đi đến Configure Cloudflare source IPs và xác minh rằng Nguồn IP được đặt thành một phạm vi riêng tư, chẳng hạn như 100.64.0.0/12 (mặc định) hoặc /12 riêng tư khác mà bạn đã chọn.
Go to Configure Cloudflare source IPs and verify that the Source IP is set to a private range, such as 100.64.0.0/12 (the default) or another private /12 you have selected.
ចុច Configure Cloudflare source IPs ហើយធ្វើឱ្យប្រសិនបើប្រភព IP ត្រូវបានកំណត់ទៅជាតម្រូវការឯកជនដូចជា 100.64.0.0/12 (តម្រូវការទូទៅ) ឬ /12 ដែលអ្នកបានជ្រើស។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

2.Đối với Tạo bản ghi DNS với định tuyến mạng riêng 2. Create a DNS record with private network routing 2 ។ ការបង្កើតសៀវភៅ DNS ជាមួយនឹងការដំណើរការបណ្តាញឯកជន

Phần «Tạo DNS record với private network routing» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "2. Create a DNS record with private network routing" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «2 ។ ការបង្កើតសៀវភៅ DNS ជាមួយនឹងការដំណើរការបណ្តាញឯកជន» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Tạo bản ghi A hoặc AAAA chỉ đến địa chỉ riêng IP của nguồn gốc của bạn, với trạng thái proxy được bật và Use private network routing được bật. Điều này nói Cloudflare để gửi lưu lượng truy cập cho tên máy chủ thông qua Cloudflare WAN của bạn tunnel thay vì thông qua Internet công cộng.
Create an A or AAAA record that points to the private IP address of your origin, with proxy status enabled and Use private network routing turned on. This tells Cloudflare to send traffic for the hostname through your Cloudflare WAN tunnel instead of over the public Internet.
បានបង្កើតសៀវភៅ A ឬ AAAA ដែលបង្ហាញទៅ IP អាសយដ្ឋានឯកជនរបស់អ្នក, ជាមួយនឹងសកម្មភាព proxy និង Use private network routing បានបើក។ នេះបានបង្ហាញ Cloudflare ដើម្បីផ្ញើការដឹកជញ្ជូនសម្រាប់ឈ្មោះក្រុមហ៊ុនផ្គត់ផ្គង់តាមរយៈ Cloudflare WAN tunnel របស់អ្នកដោយផ្អែកលើអ៊ីនធឺណិត។
Đối với bảng điều khiển và các bước API, hãy tham khảo Private network routing.
For the dashboard and API steps, refer to Private network routing.
សម្រាប់ប្រព័ន្ធប្រតិបត្តិការនិងជំហាន API សូមមើល Private network routing ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

3 Cái Kiểm tra kết nối end-to-end 3. Verify end-to-end connectivity 3 ។ ការត្រួតពិនិត្យការតភ្ជាប់ end-to-end

Phần «Xác minh end-to-end connectivity» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "3. Verify end-to-end connectivity" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «3 ។ ការត្រួតពិនិត្យការតភ្ជាប់ end-to-end» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi bản ghi DNS được đặt, hãy xác nhận đường dẫn từ mạng Cloudflare thông qua tunnel của bạn đến nguồn gốc.
After the DNS record is in place, validate the path from the Cloudflare network through your tunnel to the origin.
បន្ទាប់ពីអត្ថបទ DNS បានមានទីតាំង, សូមអនុញ្ញាតឱ្យដំណើរការពីបណ្តាញ Cloudflare តាមរយៈអត្ថបទ tunnel របស់អ្នកទៅជាប្រភព។

Kiểm tra tunnel sức khỏe Check tunnel health ពិនិត្យឡើងវិញ tunnel សុខភាព

Phần «Check tunnel health» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Check tunnel health" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ពិនិត្យឡើងវិញ tunnel សុខភាព» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trong bảng điều khiển Cloudflare, xác nhận rằng IPsec của bạn tunnel là khỏe mạnh. Nhắc đến Check tunnel health on the dashboard
In the Cloudflare dashboard, confirm that your IPsec tunnel is healthy. Refer to Check tunnel health on the dashboard.
នៅលើប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមបញ្ជាក់ថា IPsec tunnel របស់អ្នកគឺមានប្រសិទ្ធិភាព។ សូមអរគុណ Check tunnel health on the dashboard

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Gửi yêu cầu từ một khách hàng bên ngoài Send a request from an external client សូមផ្ញើសំណួរពីអតិថិជនខាងក្រៅ

Phần «Send request từ external client» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Send a request from an external client" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «សូមផ្ញើសំណួរពីអតិថិជនខាងក្រៅ» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Từ một máy bên ngoài mạng riêng của bạn, hãy gửi yêu cầu HTTPS đến tên máy chủ được ủy quyền:
From a machine outside your private network, send an HTTPS request to the proxied hostname:
ពីកុំព្យូទ័រនៅខាងក្រៅនៃបណ្តាញឯកជនរបស់អ្នក, សូមផ្ញើការ HTTPS ទៅឈ្មោះក្រុមហ៊ុនផ្គត់ផ្គង់:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
curl -v https://<YOUR_DOMAIN>/
Một phản hồi thành công xác nhận rằng Cloudflare đã chấp nhận yêu cầu, áp dụng các tính năng proxy của bạn và đạt đến nguồn thông qua tunnel.
A successful response confirms that Cloudflare accepted the request, applied your proxied features, and reached the origin through the tunnel.
ការឆ្លើយតបល្អប្រសិនបើ Cloudflare បានទទួលស្គាល់សំណួររបស់អ្នកបានអនុវត្តលក្ខណៈពិសេស proxy របស់អ្នកហើយបានទទួលស្គាល់ប្រភពតាម tunnel ។

Xác nhận giao thông trên nguồn gốc Confirm traffic on the origin ការបញ្ជាក់ការដឹកជញ្ជូននៅលើដើម

Phần «Confirm traffic on origin» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Confirm traffic on the origin" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបញ្ជាក់ការដឹកជញ្ជូននៅលើដើម» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trên VM nguồn, hãy xác minh rằng các yêu cầu đến từ phạm vi Cloudflare Source IP. Ví dụ, để theo dõi lưu lượng truy cập đến từ 100.64.0.0/12 trên cổng 443:
On the origin VM, verify that requests are arriving from the Cloudflare Source IP range. For example, to watch for incoming traffic from 100.64.0.0/12 on port 443:
នៅលើកុំព្យូទ័រដើមសូមត្រួតពិនិត្យថាតើតម្រូវការកំពុងមកពីទំហំ Cloudflare Source IP ។ ឧទាហរណ៍, ដើម្បីមើលការដឹកជញ្ជូនចូលពី 100.64.0.0/12 នៅលើផែន 443:
Cửa sổ Terminal
Terminal window
បង្វិល Terminal
text
sudo tcpdump -n -i any 'src net 100.64.0.0/12 and dst port 443'
Thay thế 100.64.0.0/12 bằng phạm vi Nguồn IP được cấu hình cho tài khoản của bạn, và điều chỉnh cổng để phù hợp với người nghe ở nguồn của bạn.
Replace 100.64.0.0/12 with the Source IP range configured for your account, and adjust the port to match the listener on your origin.
សូមផ្លាស់ប្តូរ 100.64.0.0/12 ជាមួយនឹងប្រភេទ Source IP ដែលបានកំណត់សម្រាប់គណនីរបស់អ្នកហើយផ្លាស់ប្តូរប្រព័ន្ធផ្លាស់ប្តូរដើម្បីបំពេញតាមប្រព័ន្ធប្រតិបត្តិការរបស់អ្នក។

Điểm chung Pitfalls Common pitfalls ហ្វេសប៊ុក

Phần «Common pitfalls» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Common pitfalls" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ហ្វេសប៊ុក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Bằng cách này, bạn có thể xác định được thời gian kết nối của bạn từ các khách hàng.Bạn có thể xác định thời gian kết nối từ các khách hàng.Bạn có thể xác định thời gian kết nối từ các khách hàng.Bạn có thể xác định thời gian kết nối từ các khách hàng.Bạn có thể xác định thời gian kết nối từ các khách hàng.Bạn có thể xác định thời gian kết nối từ các khách hàng. Đặt nó vào Private /12. Mạng lưới nơi nguồn gốc của bạn sống không có đường trở lại cho phạm vi Cloudflare Nguồn IP. Thêm một tuyến đường gửi phạm vi đó trở lại thông qua tunnel. T58_3# hiển thị IKE thiết lập nhưng kiểm tra sức khỏe thất bại ICMP bị chặn trên đường hoặc kiểm tra sức khỏe được cấu hình sai. Cho phép ICMP giữa các điểm cuối tunnel và xác nhận hướng kiểm tra sức khỏe là hai chiều và nhập là câu trả lời. Traffic của Bồ Đào Nha cố gắng định tuyến qua Internet công cộng Bồ Đào Nha Chuyển đổi Use private network routing không được bật cho bản ghi DNS. Chỉnh sửa bản ghi và bật toggle. Bồ Tát
| Symptom | Cause and fix | | --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Connection timeouts from clients | Cloudflare Source IP is set to a public range. Set it to a private /12. | | Request times out, no response on the origin | The network where your origin lives has no return route for the Cloudflare Source IP range. Add a route that sends that range back through the tunnel. | | Tunnel shows IKE established but health checks fail | ICMP is blocked on the path or the health check is misconfigured. Allow ICMP between the tunnel endpoints and confirm the health check direction is bidirectional and type is reply. | | Traffic tries to route over the public Internet | The Use private network routing toggle is not turned on for the DNS record. Edit the record and turn the toggle on. |
| Symptom | Cause and fix | | --------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | Connection timeouts from clients | Cloudflare Source IP is set to a public range. Set it to a private /12. | | Request times out, no response on the origin | The network where your origin lives has no return route for the Cloudflare Source IP range. Add a route that sends that range back through the tunnel. | | Tunnel shows IKE established but health checks fail | ICMP is blocked on the path or the health check is misconfigured. Allow ICMP between the tunnel endpoints and confirm the health check direction is bidirectional and type is reply. | | Traffic tries to route over the public Internet | The Use private network routing toggle is not turned on for the DNS record. Edit the record and turn the toggle on. |

Bước tiếp theo Next steps ជំហានបន្ទាប់

Phần «Bước tiếp theo» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Next steps" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ជំហានបន្ទាប់» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"item":{"@id":"/directory/","name":"Directory"}},{"@type":"ListItem","position":2,"item":{"@id":"/dns/","name":"DNS"}},{"@type":"ListItem","position":3,"item":{"@id":"/dns/private-origins/","name":"Private origins (beta)"}},{"@type":"ListItem","position":4,"item":{"@id":"/dns/private-origins/set-up-via-cloudflare-wan/","name":"Set up a private origin via Cloudflare WAN"}}]}

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗