Skip to content
DnsLister Forum

Where domain hunters compare notes

Random ~15-60s complete request drops on Hostinger VPS *only* when traffic comes in via Cloudflare — origin confirmed healthy, seems like a Hostinger-network-to-Cloudflare-edge issue

Running a KVM VPS on Hostinger, Ubuntu + Docker/Traefik, multiple sites/services behind it, DNS/proxy through Cloudflare (orange-clouded). Several subdomains/services all affected identically.

Symptom: Requests that come in through Cloudflare intermittently just vanish — client hangs until timeout or gets a 522, a few times per hour under normal traffic, more often under sustained testing.

The key finding — this points at the network path into Hostinger, not my app/origin, and not Cloudflare's dispatch logic in the abstract:

I ran two client-side test loops at the same time, same laptop, hitting the same hostnames every 1-2s: – Loop A: normal request through Cloudflare – Loop B: request to the exact same hostname, but sent directly to the VPS's public IP (bypassing Cloudflare's proxy entirely, via curl --resolve) — same TLS SNI/Host header, so the origin serves it identically

Every single time Loop A hangs/fails, Loop B succeeds in parallel against the same VPS, in under 1 second, no errors. Worst case so far: a ~60 second stretch where 4 consecutive Cloudflare-path requests failed back-to-back across different subdomains, while the direct-to-VPS loop completed 20+ clean requests during that exact window.

I also ran continuous packet capture and full access logging on the VPS itself. During every failure window: either zero packets of any kind arrive at the VPS from any Cloudflare IP for that request (it just never shows up), or an already-open, idle Cloudflare→VPS connection sits silent for 10-60+ seconds before the request is finally written to it — and the VPS answers in single-digit milliseconds the moment it actually receives something.

So: the VPS itself is up, responsive, and reachable by literally anyone else on the internet (or via direct IP) the entire time. The only path that ever fails is traffic arriving specifically via Cloudflare's edge network into this Hostinger VPS. That strongly suggests something on the network path/peering between Cloudflare and Hostinger's infrastructure for this VPS — not app config, not my client, not my home network/ISP (checked and ruled that out separately too).

And Cloudflare's own edge-side data backs this up independently:

Pulled Cloudflare's per-request edge analytics for a confirmed 522 window. Every 522 shows a TCP handshake duration of 0ms and TLS handshake duration of 0ms — meaning Cloudflare's edge sent a SYN toward the VPS's IP and never got a SYN+ACK back, timing out at Cloudflare's ~19s TCP-handshake timeout. This happened from two different Cloudflare edge locations within the same few minutes, so it's not one PoP having a bad day — SYNs from Cloudflare's network just weren't reaching the VPS. My own origin-side packet capture during that exact window independently shows zero SYNs arriving from any Cloudflare IP, while a direct (non-Cloudflare) connection to the same VPS at the same moment worked instantly. The very next requests right after recovery show brand-new TCP+TLS handshakes completing normally (tens of ms), confirming the origin itself was fine throughout — it just wasn't receiving the packets.

So both sides agree independently: Cloudflare tried to connect, the VPS never saw it arrive, and the VPS answers fine the instant a connection actually gets through. That points at something on the hosting side — a firewall, rate-limit, or DDoS-mitigation layer — intermittently dropping inbound traffic from Cloudflare's IP ranges before it reaches the VPS.

Question for the sub: anyone else running a Hostinger VPS behind Cloudflare seeing this — intermittent total silence/timeouts specifically on the Cloudflare-facing path, while the VPS is reachable fine directly? Curious if this is isolated to my instance/datacenter, or something others have hit recently. Would also love to hear from anyone who's gotten Hostinger support to acknowledge or fix something like this, and what they said.

Source: r/Hostinger · by /u/tweeto

Leave a Reply

Your email address will not be published. Required fields are marked *