Complete Guide: DNS Migration to Cloudflare & High Availability Website with Two ISPs
![]() |
| Cloudflare DNS migration and high availability network diagram with two ISPs |
Migrasi DNS ke Cloudflare & High Availability Website dengan Dua ISP
Gw baru aja ngerancang arsitektur ini buat salah satu project, dan jujur, ini salah satu setup yang paling menarik yang pernah gw kerjain. Bayangin: website jalan di XAMPP lokal, aksesnya pake dua ISP buat high availability, dan DNS-nya pindah ke Cloudflare. Keren kan?
Tapi ya, ada aja tantangannya. Mulai dari migrasi DNS yang ribet, sampe gimana caranya bikin website tetep akses meskipun salah satu ISP mati. Gw bakal ceritain semuanya di sini—dari awal sampe akhir—dengan bahasa yang (semoga) gak bikin lo pusing.
Kenapa Pindah ke Cloudflare?
Jadi gini, Cloudflare tuh kayak swiss army knife-nya dunia internet. Selain DNS management yang cepet, mereka juga punya fitur keamanan, CDN, dan yang paling penting buat kasus ini: Cloudflare Tunnel.
Dengan Cloudflare Tunnel, server lokal lo gak perlu dibuka ke publik lewat port 80/443. Jadi lebih aman dari serangan DDoS atau percobaan hacking. Dan yang bikin gw suka, mereka punya free tier yang udah cukup buat kebutuhan website skala kecil-menengah.
Langkah 1: Inventarisasi DNS Sebelum Migrasi
Ini adalah langkah yang paling sering dilewati, tapi justru paling krusial. Sebelum lo ganti nameserver ke Cloudflare, lo harus tahu persis apa aja record DNS yang ada di provider lo sekarang.
Gw biasanya bikin tabel kayak gini:
| Type | Name | Value | TTL |
|---|---|---|---|
| A | @ | 123.45.67.89 | 3600 |
| A | www | 123.45.67.89 | 3600 |
| MX | @ | mail.domain.com | 3600 |
| TXT | @ | v=spf1 include:... -all | 3600 |
Record yang perlu diinventarisasi:
- A Record — IP publik server (bisa lebih dari satu untuk Round Robin)
- MX Record — buat email
- TXT Record — SPF, DKIM, DMARC, Google verification, dll
- CNAME Record — subdomain kayak mail., ftp., cpanel., dll
- AAAA Record — IPv6 (kalau ada)
- SRV Record — kalau ada layanan khusus
- ACME / Let's Encrypt Validation — buat renewal sertifikat
Gw selalu backup semua record ini sebelum ngapa-ngapain. Simpan di file teks atau spreadsheet. Percaya deh, lo bakal berterima kasih sama diri lo sendiri nanti kalau ada yang salah.
Langkah 2: Scan DNS dengan Cloudflare
Cloudflare punya fitur yang ngescan DNS lo secara otomatis pas lo nambahin domain. Tapi jangan langsung percaya 100% sama hasil scan-nya. Gw selalu bandingkan manual antara record yang udah di-backup sama hasil scan Cloudflare.
Kadang ada record yang gak ke-scan, terutama record TXT buat verifikasi atau record yang jarang dipakai. Jadi lebih baik cek ulang, daripada nanti website atau email lo bermasalah.
Langkah 3: Ganti Nameserver ke Cloudflare
Setelah semua record aman dan udah di-copy ke Cloudflare, barulah lo ganti nameserver di registrar domain. Proses ini biasanya makan waktu 24-48 jam buat propagasi penuh, tapi seringnya sih lebih cepet.
Tips dari gw: lakukan di waktu sepi, misalnya tengah malem atau akhir pekan. Biar kalau ada masalah, lo punya waktu buat fix sebelum traffic ramai.
Masalah: Dua A Record Gak Otomatis Jadi Failover
Nah, ini yang sering bikin orang salah paham. Banyak yang ngira kalau punya dua A record (dua IP dari dua ISP berbeda) itu otomatis jadi failover. Padahal gak.
Yang terjadi adalah DNS Round Robin: browser akan milih salah satu IP secara acak atau bergantian. Kalau satu ISP mati, browser tetep bisa aja milih IP yang mati, dan website gak kebuka. Gak ada mekanisme health check yang ngecek apakah IP tersebut bener-bener nyala atau nggak.
Jadi kalau lo pengen true failover, lo butuh solusi tambahan.
Solusi: Cloudflare Tunnel + MikroTik WAN Failover
Setelah mikir-mikir dan nyoba beberapa opsi, gw nemu kombinasi yang menurut gw paling optimal dan hemat buat setup XAMPP lokal:
Cloudflare → Cloudflare Tunnel → MikroTik → XAMPP
Gini cara kerjanya:
1. Cloudflare Tunnel
Cloudflare Tunnel (sebelumnya namanya Argo Tunnel) bikin koneksi outbound dari server lokal lo ke Cloudflare. Artinya, server lo gak perlu diekspos ke internet lewat port 80/443. Tunnel ini yang ngehubungin request dari user ke server lokal lo.
Yang bikin ini cocok adalah: tunnel bekerja via koneksi outbound, jadi gak peduli IP publik lo berubah atau pake ISP mana. Selama ada koneksi internet, tunnel bakal nyambung.
2. MikroTik WAN Failover
Di sisi jaringan, MikroTik bertugas buat memindahkan koneksi keluar dari ISP utama ke ISP cadangan kalau ISP utama bermasalah. Fitur ini disebut WAN Failover atau Load Balancing with Failover.
Caranya: MikroTik punya dua interface WAN (misal ether1 buat ISP1 dan ether2 buat ISP2). MikroTik akan nge-ping gateway atau IP tertentu secara berkala. Kalau gateway ISP1 gak respons, MikroTik otomatis pindah ke ISP2.
Ini yang bikin tunnel tetap nyambung meskipun salah satu ISP mati.
3. XAMPP di Belakang
Server XAMPP jalan normal di lokal, gak perlu konfigurasi aneh-aneh. Yang penting server punya akses internet buat nyambung ke Cloudflare Tunnel.
Proses Failover-nya Kayak Gini
- User akses website → DNS Cloudflare → Cloudflare Tunnel.
- Cloudflare Tunnel di server lokal nyambung keluar via ISP utama (lewat MikroTik).
- Kalau ISP utama mati, MikroTik switch ke ISP cadangan.
- Cloudflare Tunnel reconnect otomatis lewat ISP cadangan.
- Website tetap bisa diakses, cuma ada jeda beberapa detik pas tunnel reconnect.
Jeda ini wajar terjadi, karena butuh waktu buat tunnel ngebangun koneksi baru lewat jalur yang berbeda. Tapi setidaknya website gak down total.
Alternatif: Cloudflare Load Balancer
Cloudflare punya fitur Load Balancer yang bisa ngecek health endpoint dan otomatis ngarahin traffic ke IP yang sehat. Tapi ini layanan berbayar dan gak terlalu cocok buat server lokal yang gak punya IP publik static.
Kalau lo pake Load Balancer, lo tetap butuh IP publik yang bisa diakses dari luar, dan itu agak ribet kalau server di belakang NAT atau ISP gak kasih IP publik static.
Pengalaman Pribadi Gw
Gw sendiri udah nyoba setup ini di salah satu project. Awalnya pake dua A record dengan harapan failover otomatis, tapi ternyata gak jalan. Pas ISP utama mati, website kadang bisa diakses, kadang enggak—tergantung DNS cache dan Round Robin.
Setelah pindah ke Cloudflare Tunnel + MikroTik WAN Failover, masalahnya selesai. Website tetep akses meskipun ISP utama down, dan yang penting: server gak perlu diekspos langsung ke internet.
Emang sih ada biaya tambahan buat MikroTik dan konfigurasi awal yang agak rumit. Tapi buat gw, ini investasi jangka panjang yang worth it, terutama kalau website-nya udah mulai banyak pengunjung.
Catatan Penting
- Cloudflare Tunnel free tier cukup buat kebutuhan basic, tapi ada batasan bandwidth dan jumlah request.
- MikroTik WAN Failover butuh konfigurasi yang tepat biar gak flapping (bolak-balik pindah ISP).
- Pastikan server lokal punya koneksi internet stabil. Kalau dua ISP mati, ya gak ada yang bisa nolong.
- Jangan lupa monitoring—pakai Uptime Robot atau ping monitor buat ngecek apakah website masih akses.
- Backup konfigurasi MikroTik sebelum ngapa-ngapain. Satu kesalahan bisa bikin jaringan berantakan.
Kesimpulan
Migrasi DNS ke Cloudflare + Cloudflare Tunnel + MikroTik WAN Failover adalah kombinasi yang powerful buat ngejalanin website lokal dengan high availability. Gak perlu IP publik static, gak perlu expose server langsung, dan website tetep akses meskipun salah satu ISP mati.
Tentu aja ada trade-off: biaya (MikroTik, time, effort) dan kompleksitas konfigurasi. Tapi kalau lo serius pengen website yang stabil dan aman, setup ini layak banget dipertimbangkan.
Jujur, gw masih belajar juga sih. Jaringan itu luas banget dan selalu ada yang baru. Tapi setidaknya, dengan setup ini, gw udah punya fondasi yang kuat buat ngejalanin project-project ke depan.
Pertanyaan Buat Lo
Gimana? Lo pernah nyoba setup serupa? Atau punya pengalaman lain soal high availability dan Cloudflare? Share di kolom komentar ya, siapa tau bisa saling belajar.
Dan ingat: gak ada sistem yang 100% uptime, tapi kita bisa berusaha buat mendekatinya. Happy tinkering!
DNS Migration to Cloudflare & High Availability Website with Two ISPs
I just finished designing this architecture for one of my projects, and honestly, it's one of the most interesting setups I've ever worked on. Picture this: a website running on local XAMPP, accessed through two ISPs for high availability, and DNS migrated to Cloudflare. Pretty cool, right?
But of course, there were challenges. From the tricky DNS migration to figuring out how to keep the website accessible even when one ISP goes down. I'll walk you through everything—from start to finish—in a way that (hopefully) won't make your head spin.
Why Move to Cloudflare?
Here's the thing: Cloudflare is like the swiss army knife of the internet. Aside from fast DNS management, they offer security features, CDN, and most importantly for this case: Cloudflare Tunnel.
With Cloudflare Tunnel, your local server doesn't need to be exposed to the public via ports 80/443. That means better protection against DDoS attacks and hacking attempts. And what I love about it is that their free tier is already sufficient for small to medium-scale websites.
Step 1: Inventory Your DNS Records Before Migration
This is the step that's most often skipped, but it's absolutely critical. Before you change your nameservers to Cloudflare, you need to know exactly what DNS records exist with your current provider.
I usually create a table like this:
| Type | Name | Value | TTL |
|---|---|---|---|
| A | @ | 123.45.67.89 | 3600 |
| A | www | 123.45.67.89 | 3600 |
| MX | @ | mail.domain.com | 3600 |
| TXT | @ | v=spf1 include:... -all | 3600 |
Records you need to inventory:
- A Records — public IP of the server (could be multiple for Round Robin)
- MX Records — for email
- TXT Records — SPF, DKIM, DMARC, Google verification, etc.
- CNAME Records — subdomains like mail., ftp., cpanel., etc.
- AAAA Records — IPv6 (if you have it)
- SRV Records — for specialized services
- ACME / Let's Encrypt Validation — for certificate renewal
I always back up all these records before doing anything else. Save them in a text file or spreadsheet. Trust me, you'll thank yourself later if something goes wrong.
Step 2: Scan DNS with Cloudflare
Cloudflare has a feature that automatically scans your DNS when you add your domain. But don't trust the scan results 100%. I always manually compare the backed-up records with what Cloudflare finds.
Sometimes records don't get scanned, especially TXT records for verification or rarely used records. So it's better to double-check, rather than ending up with a broken website or email later.
Step 3: Change Nameservers to Cloudflare
Once all records are safe and copied to Cloudflare, it's time to change the nameservers at your domain registrar. This process usually takes 24-48 hours for full propagation, though it's often faster.
My tip: do it during off-peak hours, like late at night or on weekends. That way, if something goes wrong, you have time to fix it before traffic picks up.
The Problem: Two A Records Don't Automatically Mean Failover
This is where a lot of people get confused. Many assume that having two A records (two IPs from two different ISPs) automatically provides failover. But it doesn't.
What actually happens is DNS Round Robin: the browser will randomly or alternately pick one of the IPs. If one ISP is down, the browser might still pick the dead IP, and the website won't load. There's no health check mechanism to verify if an IP is actually alive.
So if you want true failover, you need an additional solution.
The Solution: Cloudflare Tunnel + MikroTik WAN Failover
After thinking it through and trying a few options, I found a combination that I think is the most optimal and cost-effective for a local XAMPP setup:
Cloudflare → Cloudflare Tunnel → MikroTik → XAMPP
Here's how it works:
1. Cloudflare Tunnel
Cloudflare Tunnel (formerly known as Argo Tunnel) creates an outbound connection from your local server to Cloudflare. This means your server doesn't need to be exposed to the internet via ports 80/443. The tunnel handles the connection between user requests and your local server.
What makes this perfect is that the tunnel works via an outbound connection, so it doesn't care if your public IP changes or which ISP you're using. As long as there's an internet connection, the tunnel will stay connected.
2. MikroTik WAN Failover
On the network side, MikroTik handles switching outgoing traffic from the primary ISP to the backup ISP if the primary goes down. This feature is called WAN Failover or Load Balancing with Failover.
How it works: MikroTik has two WAN interfaces (e.g., ether1 for ISP1 and ether2 for ISP2). It periodically pings the gateway or specific IPs. If the primary ISP's gateway doesn't respond, MikroTik automatically switches to ISP2.
This is what keeps the tunnel connected even when one ISP fails.
3. XAMPP Behind It All
The XAMPP server runs normally locally—no weird configurations needed. The important thing is that the server has internet access to connect to Cloudflare Tunnel.
Failover Process Flow:
- User accesses the website → DNS Cloudflare → Cloudflare Tunnel.
- Cloudflare Tunnel on the local server goes out through the primary ISP (via MikroTik).
- If the primary ISP goes down, MikroTik switches to the backup ISP.
- Cloudflare Tunnel automatically reconnects via the backup ISP.
- The website remains accessible, with just a few seconds of downtime while the tunnel reconnects.
This downtime is normal—the tunnel needs a moment to establish a new connection through a different path. But at least the website doesn't go completely offline.
Alternative: Cloudflare Load Balancer
Cloudflare offers a Load Balancer feature that can check endpoint health and automatically route traffic to healthy IPs. However, this is a paid service and isn't very suitable for local servers without static public IPs.
If you use Load Balancer, you still need a public IP that's accessible from outside, which gets complicated if your server is behind NAT or your ISP doesn't provide static IPs.
My Personal Experience
I actually tried this setup on one of my projects. Initially, I used two A records hoping for automatic failover, but it didn't work. When the primary ISP went down, the website would sometimes load and sometimes not—depending on DNS cache and Round Robin behavior.
After switching to Cloudflare Tunnel + MikroTik WAN Failover, the problem was solved. The website stayed accessible even when the primary ISP was down, and more importantly: the server didn't need to be directly exposed to the internet.
Sure, there's the added cost of MikroTik hardware and some initial configuration complexity. But for me, this is a long-term investment worth making, especially if your website is starting to attract more visitors.
Important Notes
- Cloudflare Tunnel's free tier is sufficient for basic needs, but there are bandwidth and request limits.
- MikroTik WAN Failover requires precise configuration to avoid flapping (constantly switching between ISPs).
- Make sure your local server has stable internet access. If both ISPs go down, nothing can save you.
- Don't forget monitoring—use Uptime Robot or ping monitors to check if the website is still accessible.
- Back up your MikroTik configuration before making changes. One mistake can break your entire network.
Conclusion
DNS migration to Cloudflare + Cloudflare Tunnel + MikroTik WAN Failover is a powerful combination for running a local website with high availability. No need for static public IPs, no need to expose the server directly, and the website stays accessible even when one ISP goes down.
Of course, there are trade-offs: cost (MikroTik hardware, time, effort) and configuration complexity. But if you're serious about a stable and secure website, this setup is well worth considering.
Honestly, I'm still learning too. Networking is a vast field, and there's always something new. But at least with this setup, I have a solid foundation for future projects.
Question for You
Have you tried a similar setup? Or do you have other experiences with high availability and Cloudflare? Share them in the comments—maybe we can learn from each other.
And remember: no system has 100% uptime, but we can do our best to get close. Happy tinkering!
Terima kasih sudah mampir! Jika kamu menikmati konten ini dan ingin menunjukkan dukunganmu, bagaimana kalau mentraktirku secangkir kopi? 😊 Ini adalah gestur kecil yang sangat membantu untuk menjaga semangatku agar terus membuat konten-konten keren. Tidak ada paksaan, tapi secangkir kopi darimu pasti akan membuat hariku jadi sedikit lebih cerah. ☕️
Thank you for stopping by! If you enjoy the content and would like to show your support, how about treating me to a cup of coffee? �� It’s a small gesture that helps keep me motivated to continue creating awesome content. No pressure, but your coffee would definitely make my day a little brighter. ☕️ Buy Me Coffee

Post a Comment for "Complete Guide: DNS Migration to Cloudflare & High Availability Website with Two ISPs"
Post a Comment
You are welcome to share your ideas with us in comments!