The Cloudflare extension is installed and with that we can see the original IP address in access logs, not Cloudflare's IPs. So when fail2ban reads the access logs it's able to ban original IPs and send to Cloudflare.
And in litespeed we did this to see original IP:
1 - Go to your LiteSpeed Web Admin Console,
2 - Enable the option Use Client IP in Header in Configuration.
You think the best bet is to reduce "Dynamic Requests/second" to maybe 3? The website itself is a heavy vBulletin forum + Wordpress Blog.
Is there anything else I should do?