Configuring DDoS-Guard for a Bitrix Store: Avoiding Pitfalls
After connecting DDoS-Guard to a 1C-Bitrix store, clients from other regions suddenly see Moscow as the delivery city, and the 1C exchange stops working. SSL redirects loop, statistics show all visitors from a single IP, and the composite cache becomes unstable. A typical picture we see from new clients. In the last half-year alone, 18 companies approached us with these symptoms. Without correct configuration of X-Forwarded-For and X-Forwarded-Proto headers, geolocation accuracy drops to 100%, and 1C exchange errors cost an average of ₽25,000 per month. Over several years, we've performed more than 50 DDoS-Guard integrations with Bitrix — and we know every bottleneck. Let's break down how to configure this stack correctly so everything works without surprises. If you've encountered similar issues, get a consultation — we'll help configure DDoS-Guard in 1–2 weeks.
How to Correctly Determine the Real Client IP Behind DDoS-Guard
DDoS-Guard sends the client IP in the X-Forwarded-For header. Unlike Cloudflare (which sends a single IP via CF-Connecting-IP), X-Forwarded-For can contain a chain: client, proxy1, proxy2. The real IP is the first in the list.
- Edit
/bitrix/php_interface/dbconn.php.
- Add this code before the kernel initialization:
if (isset($_SERVER['HTTP_X_FORWARDED_FOR'])) {
$ips = array_map('trim', explode(',', $_SERVER['HTTP_X_FORWARDED_FOR']));
$_SERVER['REMOTE_ADDR'] = $ips[0];
}
- Block direct access to your server — allow only DDoS-Guard IP ranges in the firewall. The current ranges are published in DDoS-Guard documentation and via a DNS query to
_origin.ddos-guard.net. — DDoS-Guard Documentation
- Verify that the
X-Forwarded-For header is not spoofed.
Why Infinite SSL Redirects Occur After Connecting DDoS-Guard
DDoS-Guard terminates SSL on its end and can connect to the origin server via HTTP (Flexible SSL) or HTTPS (Full SSL).
With Flexible SSL, Bitrix doesn't know the client came via HTTPS. DDoS-Guard sends the X-Forwarded-Proto: https header, but Bitrix doesn't check it by default. Add this to dbconn.php:
if (isset($_SERVER['HTTP_X_FORWARDED_PROTO'])
&& $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https') {
$_SERVER['HTTPS'] = 'on';
}
Without this setting: infinite redirect loop when 'Redirect to HTTPS' is enabled in the admin panel, mixed content on pages, forms submitted over HTTP.
Caching: Differences from Cloudflare
DDoS-Guard caches static files (JS, CSS, images) automatically. HTML is not cached by default — unlike Cloudflare, where you must explicitly disable cache for PHP.
This simplifies integration: Bitrix's composite cache works normally, no double caching occurs. Compared to Cloudflare, DDoS-Guard does not require manual Page Rules for HTML caching, saving about 2–3 hours of configuration. However, DDoS-Guard caches static files aggressively, and after updating JS/CSS files, users may receive old versions.
Solutions:
-
File versioning — Bitrix automatically adds
?v=timestamp to files if using \Bitrix\Main\Page\Asset. Check that custom templates do the same.
-
Purge cache via DDoS-Guard API — after deployment, call the API to clear cache for specific resources or the entire domain.
Proactive Protection and Web Application Firewall
DDoS-Guard filters L3/L4 attacks (SYN-flood, UDP-flood) and some L7 attacks (HTTP-flood). However, DDoS-Guard's WAF rules are less granular than Cloudflare's. The Bitrix proactive filter remains an important line of defense.
A typical issue: under a strong attack, DDoS-Guard enables a JavaScript Challenge — a verification page that filters out bots. If 1C (HTTP data exchange) or payment system callbacks access the site, they won't pass the JS Challenge. Exclude the IP addresses of your 1C server and payment gateways in DDoS-Guard settings (Whitelist IP).
Additional Filtering Details
For fine-tuning WAF rules, refer to DDoS-Guard documentation. We also recommend enabling web analytics in Bitrix to monitor attacks.
Statistics Module and Geolocation
The statistic module determines geolocation by IP. If REMOTE_ADDR is not overridden, all visitors will be geolocated to DDoS-Guard's IP (Moscow or Rostov-on-Don). After correctly configuring the headers, geolocation works normally.
The sale module uses geolocation to automatically determine the delivery city. Without IP correction, a dealer from Brest will see 'Moscow' in the city field during checkout. In our experience, this leads to delivery errors in 30% of orders — after configuration, city accuracy reaches 95%.
Monitoring and Debugging
After connecting DDoS-Guard, add these checks:
| Check |
How to Perform |
| Composite works |
Check X-Bitrix-Composite: Cache header in response |
| 1C exchange |
Run an exchange, ensure /bitrix/admin/1c_exchange.php is accessible |
| Payment system callbacks |
Place a test order, check payment status |
| Real IP in logs |
In Apache/Nginx access.log, the client IP should appear, not DDoS-Guard. Configure RemoteIPHeader X-Forwarded-For in Apache or set_real_ip_from + real_ip_header in Nginx |
| SSL correct |
Open the site, check $_SERVER['HTTPS'] — should be on |
What Our Work Includes
Turnkey: audit of current configuration, setup of real IP detection, SSL, firewall, exclusion of 1C and payment system IPs, testing, documentation, administrator training. Experience: 5+ years, 80+ Bitrix projects. We guarantee stable operation after integration.
Timeline
| Stage |
Duration |
| DNS pointing + basic setup |
2–3 hours |
| IP, SSL, firewall |
3–4 hours |
| Testing all modules |
2–3 days |
| Setting exceptions (1C, payment) |
1 day |
| Stabilization and monitoring |
3–5 days |
| Total |
1–2 weeks |
Need help? Contact us to discuss your project.
CommerceML: Why Standard Exchange Is Both a Lifesaver and a Trap
Standard exchange via CommerceML 2.0 on typical "Trade Management" or "Comprehensive Automation" can be set up in a day or two. Products, prices, stock, orders—all via XML files on a schedule. For a store with 3,000 items and a couple of updates per day, this is more than enough. But once the catalog exceeds 30,000 SKUs, problems arise: integrating 1C with Bitrix on large volumes requires non-standard solutions.
Why does CommerceML slow down with catalogs over 100,000 items?
bitrix_1c_exchange.php generates XML on the Bitrix side, and 1C retrieves and parses it. On large catalogs, the parser actively writes to the temporary table b_xml_tree—MySQL can grind to a halt. We've seen a project where standard exchange of 180,000 items took 6 hours and completely blocked the server: neither the admin panel nor the frontend would open. The solution is incremental exchange. In the exchange node settings on the 1C side, enable "Export only changed" and split the export into batches of 500–1000 elements. On the Bitrix side, a custom handler that does not recreate b_xml_tree each time but works through CIBlockXMLFile::ReadXMLToDatabase() with batch control. A catalog of 200,000 SKUs updates in 8–12 minutes.
Another pitfall is EXTERNAL_ID. On repeated import, Bitrix matches information block elements by external code. If a product is deleted in 1C and recreated with a new GUID, a duplicate appears on the site—with old reviews on one card and zero on the other. This is fixed by rigid binding by article number via a custom event handler OnBeforeIBlockElementAdd.
How to avoid duplicates during repeated import?
We bind products not by GUID but by article number. Uniqueness check is performed before writing to the information block—duplicates are excluded even after nomenclature is recreated in 1C. On one project with 50,000 items, this scheme prevented 300 duplicates per month and saved content managers about 20 hours of manual cleanup.
Custom 1C Configurations: When CommerceML Falls Short
"We have a standard configuration"—says every second client, and then we open the database and see 200 custom processing routines, renamed attributes, and custom sales documents. CommerceML works with a fixed XML structure. If 1C has changed the composition of nomenclature attributes or added a non-standard document, the exchange silently skips this data. Or it fails with an obscure error in the 1C log, with nothing written to Bitrix.
In such cases, we implement custom export. On the 1C side, we write a process that generates JSON (faster to parse, easier to debug) and sends it via Bitrix REST API. Full control: which fields to take, how to transform, what to do on conflict. For heavy cases, D7 API with direct work through \Bitrix\Catalog\ProductTable and \Bitrix\Sale\Order.
| Criterion |
CommerceML (Standard) |
Custom REST (JSON) |
| Speed on 100,000+ SKUs |
Low (full XML) |
High (incremental JSON) |
| Schema flexibility |
Fixed |
Arbitrary |
| Expansion capability |
Limited |
Unlimited |
| Ease of debugging |
1C log |
HTTP request logs, Postman |
What are the key steps to set up 1C integration?
Custom REST is justified when:
- Non-standard nomenclature attributes;
- Multiple price types (retail, wholesale, dealer, promotional, regional, currency)—standard exchange sends only one type;
- Multi-warehouse with different stock levels and need to select a warehouse on the site.
Prices, Stock, and Multi-Warehouse
Standard exchange can transfer one price type. In reality, there may be 15: each with its own buyer group and priority. Mapping between 1C price groups and Bitrix user groups is a separate engineering challenge. Especially when discounts overlap and you need to determine which price wins.
Multi-warehouse adds another layer: product is in stock in Moscow, out of stock in St. Petersburg, and "on order" in Novosibirsk. The site must show availability per location, allow selection of pickup points, and calculate shipping from the nearest warehouse where the product is physically available. The standard Bitrix warehouse module (catalog.store) handles display, but we write the "which warehouse to ship from" logic separately. For one manufacturing holding, we implemented a custom stock aggregator that calculated balance across 8 warehouses in 2 seconds—reducing shipping errors by 80%.
Orders and Document Flow
An order from the site goes to 1C, a sales document is created, goods are reserved. Statuses come back. The main nuance is partial shipment: the client ordered 5 items, 3 are in stock, 2 will arrive in a week. 1C creates two sales documents. Bitrix out of the box cannot split one order into several shipments—we extend the OnSaleOrderSaved handler to create child orders and synchronize statuses for each.
Documents in the personal account—invoices, acts, waybills from 1C—are served via REST; PDF is generated on the 1C side and cached on CDN. The buyer downloads not from 1C directly (that would kill the server) but from cache.
Batch import with portion control reduces MySQL load and prevents locks (source: Wikipedia).
Monitoring: Not "Set and Forget"
Exchange can silently break: the script ran, no errors in log, but 200 products didn't update due to invalid UTF-8 in the name. Or 1C changed the date format in an update—all prices came in as zero.
Minimum set we install on every project:
- Telegram alert if exchange time increases 3+ times from average.
- Stock discrepancy check: script compares
b_catalog_product.QUANTITY with what 1C provides, and alerts when delta exceeds 5%.
- Dashboard: last sync, number of processed items, queue, errors.
For high-load projects, we add async queues on Redis or RabbitMQ. Exchange does not block the web server, data is not lost during temporary 1C outages. On one online store with 2 million orders per year, we implemented this scheme—recovery time after failures dropped from 3 hours to 10 minutes.
Linking with Bitrix24 for Document Flow Automation
If besides the site there is a corporate portal on Bitrix24, we link it too. Counterparties from CRM go to 1C, invoices from 1C appear in deal cards. The manager sees accounts receivable and mutual settlements without switching windows. Deal closed—documents generated automatically.
Payment received in 1C → logistician gets a task for shipment in Bitrix24. Goods shipped → manager sees notification. Automatic tasks based on events from 1C—via Bitrix24 REST API webhooks. This link reduces manual entry by 70% and eliminates forgotten shipments.
How We Set Up Integration: Step-by-Step Process
-
Audit of 1C Configuration. Review the structure of directories, documents, attributes. Identify custom modifications. Assess data volume (number of SKUs, orders, warehouses).
-
Design Exchange Schema. Agree on data set: products, prices, stock, orders, documents. Determine sync interval and mechanism—CommerceML or custom REST.
-
Configure Standard Exchange. Set up CommerceML, batch mode, binding by article. Verify data transfer correctness on a test catalog.
-
Extended Integration. For complex configurations, write custom handlers on both 1C and Bitrix sides. Incorporate multi-warehouse, multiple prices, partial shipment.
-
Monitoring and Warranty. Set up alerts, dashboard, documentation. Train operators. After launch, warranty support.
Typical exchange settings for a catalog of 50,000 SKUs
Batch mode: 500 elements per step. Binding by article. Sync period: every 15 minutes. Use Bitrix agents with tagged caching. On 1C side, JSON generation processing instead of XML to speed up.
Timelines and What's Included
| Stage |
Description |
Estimated Duration |
| Analysis |
Audit of 1C configuration, exchange structure, current issues |
1–2 days |
| Schema Design |
Agree on data set (products, prices, orders) and architecture |
2–5 days |
| Standard Exchange Setup |
Configure CommerceML, batch mode, binding by article |
1–2 weeks |
| Extended Integration |
Custom REST, multi-warehouse, multiple prices, partial shipment |
2–4 weeks |
| Full Custom Integration |
1C + site + Bitrix24, async queues, monitoring |
1–2 months |
Work results include: documented exchange schema, configured synchronization scenarios, monitoring dashboard, operator training, and warranty support after launch. Pricing is calculated individually—it depends on the complexity of the 1C configuration, catalog size, and required automation level. We'll evaluate your project in 1 day—write to us, let's discuss. Order integration and get stable exchange in 1–2 weeks.
We have completed over 50 1C integrations for online stores and manufacturing companies. The team's average experience is 7 years, and we have certified 1C-Bitrix specialists. Our experience ensures that the exchange won't break in the first month and will run stably for years. For example, on a project with a catalog of 50,000 items, automation of exchange saved the client significant operational costs annually.
Contact us for a free audit of your 1C configuration—we'll find bottlenecks and offer the optimal solution.