How to Allow Only Cloudflare Traffic on a Linux Server

This article explains how to restrict ports 80 and 443 on a Linux VPS or dedicated server to Cloudflare traffic only.

Overview

On Linux servers where the customer controls the firewall, direct origin access can be reduced by allowing HTTP and HTTPS only from Cloudflare IP ranges and blocking other sources.

  1. Confirm that your domain is fully proxied through Cloudflare.
  2. Keep SSH on a restricted trusted IP list or protect it separately with Cloudflare Access/Tunnel.
  3. Download the current Cloudflare IPv4 and IPv6 ranges from the Cloudflare documentation.
  4. Add allow rules for Cloudflare IP ranges on ports 80 and 443 using UFW, firewalld, nftables, iptables, or your provider firewall.
  5. Add deny rules for other sources on ports 80 and 443.
  6. Test the website through Cloudflare before ending the session.
  7. Document the change and schedule a periodic review of Cloudflare IP ranges.

Common Mistakes to Avoid

  • Applying rules over SSH without a recovery method.
  • Forgetting IPv6.
  • Blocking the hosting provider health checks or load balancer traffic if used.
  • Using outdated Cloudflare IP ranges.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support