🔶

Cloudflare Error

Cloudflare Error 522: Connection Timed Out

Cloudflare's connection attempt to your origin server timed out — the server is reachable at the network level but not responding in time.

What This Error Means

A 522 is distinct from a 521: instead of an immediate refusal, Cloudflare's connection attempt to the origin simply never completed within the timeout window. The origin server may be up but overloaded, network routing between Cloudflare and the origin may be degraded, or a firewall may be silently dropping (not rejecting) Cloudflare's packets.

Why It Occurs

The most common cause is the origin server being overwhelmed (high CPU/load) and too slow to accept new connections. A second common cause is a firewall configured to silently drop packets from unrecognized IPs rather than actively rejecting them — a dropped SYN packet times out instead of returning an immediate refusal.

Symptoms

  • ⚠ Error 522 shown intermittently or consistently under load
  • ⚠ Origin server responds fine to direct requests when load is low
  • ⚠ Correlates with traffic spikes

Common Causes

  • • Origin server CPU/load is too high to accept new connections in time
  • • A firewall on the origin silently drops (rather than rejects) traffic from Cloudflare IP ranges
  • • Network-level packet loss or routing issues between Cloudflare's edge and the origin
  • • The origin's connection queue (backlog) is full during a traffic spike

How to Fix It

  1. Check origin server load at the time of the timeout: `top` or `uptime` for load average, and compare against CPU core count
  2. Confirm the origin's firewall explicitly ALLOWS (not silently drops) Cloudflare's published IP ranges — a DROP rule causes exactly this symptom, while a REJECT rule would produce a 521 instead
  3. Check for connection queue exhaustion — a very high `Recv-Q` in `ss -tn` output on the origin during load spikes indicates the backlog is full
  4. If load-related, address the root cause (scale the origin, add caching, optimize slow queries) rather than only increasing timeouts
  5. Temporarily test with Cloudflare in "DNS only" (grey-clouded) mode to determine if the issue is genuinely Cloudflare-to-origin connectivity or exists regardless
CommandPurpose
ss -tnCheck for connection queue exhaustion (high Recv-Q values)
uptimeCheck system load average
Advertisement

Verification

  • ✓ Monitor origin response times during a subsequent traffic spike to confirm it stays within Cloudflare's connection timeout window
  • ✓ Confirm 522 rate drops in Cloudflare's own analytics after the fix

Prevention

  • → Add caching (Cloudflare or origin-level) to reduce the load that reaches the origin during traffic spikes
  • → Set up origin load/CPU alerting well before it reaches the point of causing timeouts

Related