SSWConsulting / SSW.Website

Generator for ssw.com.au
https://www.ssw.com.au
Apache License 2.0
8 stars 8 forks source link

☁️FrontDoor to Cloudflare Part 2/2 - sswdory.com & ssw.com #2781

Closed amankumarrr closed 1 month ago

amankumarrr commented 4 months ago

@chrisschultzssw

As per my conversation with @wicksipedia @jeoffreyfischer, we have successfully migrated tfs365.com and ssw.com.au to Cloudflare, including all necessary redirects. With this milestone achieved, our next steps are to move the remaining domains to Cloudflare to enable the complete removal of the Front Door.

### Tasks
- [x] CDN - Move ssw.com and its aossicated redirects
- [x] CDN - Move sswdory.com. and its associated redirects
- [x] Decommission FrontDoor
Calinator444 commented 3 months ago

@wicksipedia

Is this a blocker for switching off the VM? The redirects for ssw.com.au are moved. However as far as I'm aware we haven't set a preferred URL on for sswdory.com

wicksipedia commented 3 months ago

@wicksipedia

Is this a blocker for switching off the VM? The redirects for ssw.com.au are moved. However as far as I'm aware we haven't set a preferred URL on for sswdory.com

no, it'll be a blocker for switching off frontdoor

amankumarrr commented 1 month ago

We've found some logs showing traffic still hitting our website through Front Door, despite having moved our server names to Cloudflare. We're unsure why this is happening and need to investigate further.

amankumarrr commented 1 month ago

All redirects are tested and seems to be working fine for both domains.

amankumarrr commented 1 month ago

We’ve noticed some traffic on FrontDoor that ideally shouldn’t be there. After investigating the logs, we plan to decommission it.

amankumarrr commented 1 month ago

I’ve developed a theory regarding the traffic showing up in the FrontDoor logs. It appears that most of the links are coming from China, and since Cloudflare is blocked in China, it seems the DNS requests are being routed to our FrontDoor, possibly via internal DNS.

I initially thought the traffic might be related to our CodeAuditor, but after investigating further, I found that the source country was China, while we run CodeAuditor from our pipeline, which shouldn’t originate from there. Additionally, I noticed a user agent that was already linked to a known user, confirming it wasn’t CodeAuditor.

Image

Figure: Logs from FrontDoor for the past 3 days

amankumarrr commented 1 month ago

✅Done - As per my conversation with @chrisschultzssw, Front Door has been decommissioned. This is confirmed in the email with the subject "Migrate domains from FrontDoor to Cloudflare Part 2/2."