This article explains the recommended approach for restricting direct web access on Windows Server without a control panel.
Overview
Windows Firewall can be used to allow inbound HTTP and HTTPS only from Cloudflare IP ranges. This is suitable when the customer manages the Windows server and understands firewall recovery procedures.
Recommended Steps
- Confirm the website DNS records are Proxied in Cloudflare.
- Verify that IIS or the web service works correctly over HTTPS.
- Prepare a recovery method such as console access before changing firewall rules.
- Create inbound allow rules for Cloudflare IPv4 and IPv6 ranges on TCP 80 and 443.
- Create block rules for other inbound sources on TCP 80 and 443.
- Keep RDP restricted to trusted IPs or protect remote access using Cloudflare Access/Tunnel.
- Test the website through Cloudflare and test that direct IP access is blocked.
Common Mistakes to Avoid
- Blocking RDP by mistake.
- Forgetting IPv6 inbound rules.
- Applying the rule to the wrong Windows Firewall profile.
- Using Flexible SSL instead of installing a certificate in IIS.