How to Troubleshoot Joomla Behind Cloudflare or Another CDN

Establish whether the problem exists at the origin

Record the failing public URL and symptom, then compare it with an origin request using a safe provider-supported method when available. If the origin is correct but the public CDN response is wrong, focus on edge caching, redirects, TLS, firewall, or CDN transformations instead of changing Joomla blindly.

Inspect response and cache-status headers

Use browser developer tools or an HTTP diagnostic to inspect the final response. With Cloudflare, CF-Cache-Status can indicate states such as HIT, MISS, BYPASS, or other cache outcomes. Other CDNs provide their own headers. Record these values with the failing request so later tests are comparable.

Check cookies and private responses before forcing cache

Cloudflare documents that Set-Cookie and cache-control directives can affect whether a response is cached or bypassed. Joomla login, account, cart, and other personalized workflows often use cookies. Do not solve a low cache-hit rate by forcing shared caching onto responses that contain user-specific state.

Purge the edge after relevant Joomla changes

Clearing Joomla cache does not clear Cloudflare or another independent CDN. When a stale public response is confirmed at the edge, purge the affected URL or appropriate CDN cache scope and request the page again. Avoid repeated full-cache purges when one URL or rule is responsible.

Review redirects, HTTPS, and the visitor protocol

A CDN can terminate TLS and forward requests to the origin using settings that differ from the visitor connection. Check the provider's SSL/TLS mode, origin certificate, redirect rules, Joomla live-site assumptions, and web-server redirects. Redirect loops often come from two layers each trying to enforce the same scheme.

Review firewall and security events

If Joomla works at the origin but legitimate public requests receive access errors, inspect CDN security events, WAF rules, bot controls, rate limits, and IP restrictions. Also ensure the origin accepts the provider's proxy traffic. Change only the rule shown to affect the request rather than broadly disabling protection.

Retest both guest and authenticated workflows

After correcting the CDN rule, test public articles, static assets, login and logout, forms, account pages, and any transactional routes. Keep edge caching on the content that is safe to share and bypass it where Joomla needs per-user or per-request processing.


Need More Help with Joomla?

Still having trouble? Open a support ticket with QuantaCade Support and we'll be happy to help where we can.

Support priority is given to QuantaCade products, services, and customers. However, we're also happy to assist fellow Joomla users with general Joomla questions and troubleshooting when possible.

QuantaCade is an independent Joomla extension developer and is not official Joomla support. Some issues involving third-party extensions, hosting environments, server configurations, or other systems outside our development control may be beyond what we're able to resolve.

Open a Support Ticket