This article explains which ports work with the standard Cloudflare proxy and what to do with non-standard services.
Overview
Cloudflare proxies specific HTTP and HTTPS ports by default. Services outside those ports may need DNS Only, Origin Rules, Cloudflare Tunnel, Cloudflare Access, or Cloudflare Spectrum depending on the use case.
Recommended Steps
- Use normal proxied DNS for websites on supported HTTP/HTTPS ports.
- For a web app on a supported alternate port, confirm the port is compatible before proxying.
- Use Origin Rules when Cloudflare should connect to a different destination port for a specific hostname or path.
- Use Cloudflare Tunnel for private apps or when inbound ports should remain closed.
- Use Access/Tunnel for SSH, RDP, or private non-HTTP applications.
- Keep unsupported public services as DNS Only unless a compatible Cloudflare product is configured.
Common Mistakes to Avoid
- Expecting every TCP or UDP port to work through the normal orange-cloud proxy.
- Proxying cPanel, Plesk, mail, FTP, SSH, or RDP without checking compatibility.
- Opening unusual ports publicly when Tunnel would be safer.
- Forgetting that proxy support and caching behavior may differ by port.