This article explains how to restrict ports 80 and 443 on a Linux VPS or dedicated server to Cloudflare traffic only.
Overview
On Linux servers where the customer controls the firewall, direct origin access can be reduced by allowing HTTP and HTTPS only from Cloudflare IP ranges and blocking other sources.
Recommended Steps
- Confirm that your domain is fully proxied through Cloudflare.
- Keep SSH on a restricted trusted IP list or protect it separately with Cloudflare Access/Tunnel.
- Download the current Cloudflare IPv4 and IPv6 ranges from the Cloudflare documentation.
- Add allow rules for Cloudflare IP ranges on ports 80 and 443 using UFW, firewalld, nftables, iptables, or your provider firewall.
- Add deny rules for other sources on ports 80 and 443.
- Test the website through Cloudflare before ending the session.
- Document the change and schedule a periodic review of Cloudflare IP ranges.
Common Mistakes to Avoid
- Applying rules over SSH without a recovery method.
- Forgetting IPv6.
- Blocking the hosting provider health checks or load balancer traffic if used.
- Using outdated Cloudflare IP ranges.