Back to articles
Technology Insight

Securing Your VPS: Deploying a Host-Based Intrusion Detection System (HIDS) with Wazuh and Cloudflare Tunnels

June 3, 2026

Introduction to Modern Host-Based Security

In today's hyper-connected digital landscape, Virtual Private Servers (VPS) are constant targets for automated bots, brute-force campaigns, and sophisticated cyber attacks. While network-level firewalls provide a critical first line of defense, they lack visibility into what happens inside the operating system. This is where a Host-Based Intrusion Detection System (HIDS) becomes indispensable.

By monitoring system logs, file integrity, running processes, and user activity, a HIDS acts as an internal security guard for your server. Among the open-source tools available, Wazuh stands out as a powerful, enterprise-grade security monitoring platform. However, deploying a centralized security tool often introduces a classic dilemma: how do you allow remote servers or agents to communicate with your security manager without exposing sensitive ports to the public internet? The answer lies in combining Wazuh with Cloudflare Tunnels.

Understanding the Core Components

What is Wazuh?

Wazuh is a free, open-source security monitoring platform that combines HIDS capabilities with Security Information and Event Management (SIEM) functionalities. It provides real-time threat detection, compliance auditing, file integrity monitoring (FIM), and active response capabilities across cloud, on-premise, and virtualized environments.

The Role of Cloudflare Tunnels

Traditionally, connecting remote agents to a central security manager required opening specific ports (like 1514 and 1515) on your firewall. This exposes your security infrastructure to potential exploits. Cloudflare Tunnels (part of Cloudflare One) solves this problem by creating a secure, outbound-only connection from your server to the Cloudflare network. Your agents connect through an encrypted tunnel, eliminating the need for open inbound public ports and effectively hiding your server's true IP address from attackers.

Architecture Overview

Before diving into the implementation, it is crucial to understand how these pieces fit together. The architecture relies on three primary layers:

  • The Monitored Host (Agent): The endpoint or VPS where the Wazuh agent is installed to gather logs and system metrics.
  • The Cloudflare Network: Acts as the secure proxy, routing traffic through an encrypted tunnel.
  • The Security Manager (Wazuh Server): The core infrastructure running the Wazuh manager, indexer, and dashboard, safely tucked behind the tunnel.
Security Best Practice: By minimizing the attack surface of your central monitoring server, you ensure that an attacker cannot compromise your security logs to hide their tracks during an active breach.

Step-by-Step Deployment Guide

Step 1: Preparing the VPS and Installing Wazuh

To begin, you need a clean VPS running a modern Linux distribution (such as Ubuntu 22.04 or 24.04 LTS) with at least 4GB of RAM to handle the indexing components comfortably. Update your system packages and execute the Wazuh installation script:

sudo apt update && sudo apt upgrade -y
curl -sO [https://packages.wazuh.com/4.x/wazuh-install.sh](https://packages.wazuh.com/4.x/wazuh-install.sh)
sudo bash wazuh-install.sh -a

This automated script handles the installation of the Wazuh indexer, manager, and dashboard. Once finished, record the generated admin credentials safely.

Step 2: Configuring Cloudflare Tunnels

Next, log into your Cloudflare dashboard and navigate to Zero Trust. Follow these steps to establish the tunnel:

  1. Navigate to Networks > Tunnels and click Create a Tunnel.
  2. Select cloudflared and give your tunnel a descriptive name (e.g., wazuh-secure-link).
  3. Run the environment-specific installation command provided by Cloudflare on your Wazuh manager VPS to install the cloudflared daemon.
  4. Configure the Public Hostname routes. You will need to route traffic for the Wazuh dashboard (HTTPS over port 443) and the agent communication ports.

For agent communication, ensure you configure the tunnel to route TCP traffic properly over port 1514 (for agent connection) and port 1515 (for enrollment), map them to your designated subdomains (e.g., wazuh-mgr.yourdomain.com).

Step 3: Deploying and Connecting Wazuh Agents

With the network infrastructure secured by Cloudflare, you can now deploy agents to your target hosts. In the Wazuh dashboard, navigate to the "Deploy new agent" wizard. Select your operating system and input your secure subdomain pointing to the Cloudflare Tunnel as the manager address:

WAZUH_MANAGER="wazuh-mgr.yourdomain.com" dpkg -i wazuh-agent_amd64.deb

Once installed, start the agent service. The agent will establish a secure handshake through the Cloudflare Tunnel without your backend server ever exposing a public IP port.

Optimizing and Utilizing Your HIDS

Once your architecture is operational, you can leverage Wazuh's extensive capabilities to harden your environment:

1. File Integrity Monitoring (FIM)

Configure Wazuh to monitor critical directories such as /etc, /bin, and /var/www. If an attacker modifies a configuration file or drops a web shell, Wazuh will flag the modification instantly, showing exactly what lines were altered.

2. Automated Active Response

Wazuh can actively mitigate threats. For example, if a remote IP triggers multiple SSH brute-force alerts within a short window, you can configure an active response script to automatically block that IP at the host's local firewall (iptables/UFW) for a specified duration.

Conclusion

Building a Host-Based Intrusion Detection System using Wazuh paired with Cloudflare Tunnels provides an outstanding balance of deep operational visibility and stringent network perimeter security. By ensuring your security manager remains hidden from the public internet, you mitigate structural vulnerabilities while gaining a powerful platform capable of identifying and neutralizing threats in real time. Implement this architecture today to elevate your organization's VPS security posture to an enterprise standard.

Securing Your VPS: Deploying a Host-Based Intrusion Detection System (HIDS) with Wazuh and Cloudflare Tunnels | DPTCloud