How to Allow Only Cloudflare Traffic on a Windows Server

This article explains the recommended approach for restricting direct web access on Windows Server without a control panel.

Overview

Windows Firewall can be used to allow inbound HTTP and HTTPS only from Cloudflare IP ranges. This is suitable when the customer manages the Windows server and understands firewall recovery procedures.

  1. Confirm the website DNS records are Proxied in Cloudflare.
  2. Verify that IIS or the web service works correctly over HTTPS.
  3. Prepare a recovery method such as console access before changing firewall rules.
  4. Create inbound allow rules for Cloudflare IPv4 and IPv6 ranges on TCP 80 and 443.
  5. Create block rules for other inbound sources on TCP 80 and 443.
  6. Keep RDP restricted to trusted IPs or protect remote access using Cloudflare Access/Tunnel.
  7. Test the website through Cloudflare and test that direct IP access is blocked.

Common Mistakes to Avoid

  • Blocking RDP by mistake.
  • Forgetting IPv6 inbound rules.
  • Applying the rule to the wrong Windows Firewall profile.
  • Using Flexible SSL instead of installing a certificate in IIS.
Share this:
FacebookXWhatsAppTelegramLinkedInGmailCopy Link
Updated on June 24, 2026
Was this article helpful?

Related Articles

Need Support?
Can't find the answer you're looking for?
Contact Support