ESC

Start typing to search across invoices, services, domains, tickets, and more...

Search... Ctrl+K
Network & IP

How to Hide Your Origin IP with Cloudflare: Allow Only Cloudflare to Reach Your Server

6 steps 20 min read 20 views 0
On this page

Once your site is behind Cloudflare, visitors and attackers see Cloudflare's edge IPs instead of your server's IP. But if your real IP has already leaked, or your server still accepts traffic on ports 80/443 from any address, attackers can simply bypass the CDN and hit your origin directly. This guide walks you through the whole process, from onboarding and finding leaks to locking down the firewall, so your origin is genuinely hidden.

Key Takeaways

  • Cloudflare's proxy only hides the IP your DNS resolves to; if the origin still accepts ports 80/443 from any address, attackers can bypass the CDN and hit the origin directly.
  • Common ways an origin server's real IP leaks include DNS history, unproxied subdomains, mail services, the SSL certificate returned when the IP is accessed directly, and outbound connections from the application.
  • The key to stopping attackers from bypassing Cloudflare is an origin firewall that allows ports 80/443 only from Cloudflare's official IP ranges.
  • Cloudflare's free plan only proxies HTTP/HTTPS traffic, so SSH, databases, game servers and other TCP/UDP services still rely on the server's own firewall and data-center-level DDoS protection.
  • IMIDC offers VPS and dedicated servers with DDoS protection and multi-IP support, and customers can open a Client Center ticket to ask about changing their IP.

Requirements / Before You Start

  • Your domain is already on Cloudflare (its nameservers point to the ones Cloudflare assigned)
  • Server OS: Ubuntu 22.04 / 24.04, Debian 12, Rocky Linux 9 or AlmaLinux 9, with Nginx as the web server
  • You can log in over SSH with sudo privileges
  • Make sure your SSH port is allowed in the firewall first, so you don't lock yourself out after changing the rules. It's also a good idea to keep your provider's VNC/console open as a backup way in

Step-by-Step Guide

Step 1: Turn On the Cloudflare Proxy

On the DNS page of the Cloudflare dashboard, set the proxy status of your site's A/AAAA records to "Proxied" (orange cloud). Now dig +short example.com should return Cloudflare IPs, not your server's IP.

Step 2: Set SSL Mode to Full (strict)

Under SSL/TLS, choose Full (strict). For the origin certificate you can use Let's Encrypt, or generate a free Origin CA certificate in the Cloudflare dashboard (trusted only by Cloudflare, valid for up to 15 years). Do not use Flexible mode: it sends traffic between Cloudflare and your origin in plain text and often causes redirect loops.

Step 3: Find Out How Your Real IP Might Leak

Before you moved to the CDN, your domain may already have resolved directly to your server's IP. Common leak sources include:

  • DNS history: public DNS history lookup sites keep past records.
  • Unproxied subdomains: subdomains such as mail, ftp or dev set to the grey cloud and pointing straight at the same server.
  • Mail services: an MX record pointing to the same machine, or outgoing emails from the site whose headers contain the server IP.
  • SSL certificates and the default site: if hitting port 443 by IP returns a certificate containing your domain, internet-wide scanners will index it.
  • Outbound connections from your app: webhooks, remote image fetching, pingbacks and similar features expose your origin IP to third parties.

If your IP has definitely leaked, Cloudflare alone can't fully fix it, and we recommend changing the server IP. IMIDC customers can open a ticket in the Client Center to ask about changing IPs or adding more.

Step 4: Allow Only Cloudflare IPs on Ports 80/443

Cloudflare publishes its official IP ranges at https://www.cloudflare.com/ips-v4 and https://www.cloudflare.com/ips-v6. The commands below read the latest lists directly.

Ubuntu / Debian (UFW):

sudo ufw allow OpenSSH        # If you changed the SSH port, use: sudo ufw allow <port>/tcp

for ip in $(curl -fsS https://www.cloudflare.com/ips-v4) $(curl -fsS https://www.cloudflare.com/ips-v6); do
  sudo ufw allow proto tcp from "$ip" to any port 80,443 comment 'Cloudflare'
done

# Remove earlier rules that opened 80/443 to everyone (delete whichever actually exist)
sudo ufw delete allow 'Nginx Full'
sudo ufw delete allow 80/tcp
sudo ufw delete allow 443/tcp

sudo ufw enable
sudo ufw status numbered

If deleting a rule prints "Could not delete non-existent rule", you can ignore it.

Rocky / Alma 9 (firewalld + ipset):

sudo firewall-cmd --permanent --new-ipset=cf4 --type=hash:net
sudo firewall-cmd --permanent --new-ipset=cf6 --type=hash:net --option=family=inet6

for ip in $(curl -fsS https://www.cloudflare.com/ips-v4); do
  sudo firewall-cmd --permanent --ipset=cf4 --add-entry="$ip"
done
for ip in $(curl -fsS https://www.cloudflare.com/ips-v6); do
  sudo firewall-cmd --permanent --ipset=cf6 --add-entry="$ip"
done

for svc in http https; do
  sudo firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source ipset=cf4 service name=$svc accept"
  sudo firewall-cmd --permanent --add-rich-rule="rule family=ipv6 source ipset=cf6 service name=$svc accept"
done

# Remove the http/https services that were open to all sources
sudo firewall-cmd --permanent --remove-service=http --remove-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all

Cloudflare's IP ranges change occasionally, so check them against the official list every few months.

Note: ports published by Docker bypass UFW rules. If your site runs in Docker, bind the container ports to 127.0.0.1 and let Nginx on the host serve the public traffic.

Step 5: Reject Requests Made Directly to the IP

Add a default site to Nginx that drops connections to the bare IP or unknown hostnames, so your certificate doesn't reveal your domain:

sudo tee /etc/nginx/conf.d/00-default.conf > /dev/null <<'EOF'
server {
    listen 80 default_server;
    listen [::]:80 default_server;
    server_name _;
    return 444;
}
server {
    listen 443 ssl default_server;
    listen [::]:443 ssl default_server;
    server_name _;
    ssl_reject_handshake on;
}
EOF

ssl_reject_handshake requires Nginx 1.19.4 or later. The stock versions on Ubuntu 24.04, Debian 12 and Rocky/Alma 9 all qualify; the 1.18 shipped with Ubuntu 22.04 does not, so upgrade from the official nginx.org repository. On Ubuntu/Debian, also remove the bundled default site to avoid a default_server conflict:

sudo rm -f /etc/nginx/sites-enabled/default

Step 6: Log Visitors' Real IPs in Nginx

Behind Cloudflare, the client IP in your Nginx logs becomes a Cloudflare edge IP. Restore the real one with the realip module:

{
  for ip in $(curl -fsS https://www.cloudflare.com/ips-v4) $(curl -fsS https://www.cloudflare.com/ips-v6); do
    echo "set_real_ip_from $ip;"
  done
  echo "real_ip_header CF-Connecting-IP;"
} | sudo tee /etc/nginx/conf.d/cloudflare-realip.conf > /dev/null

sudo nginx -t && sudo systemctl reload nginx

Step 7: Verify It Works

Run these from a different machine. The first should fail or time out, while access via the domain works normally:

curl -m 10 -I http://YOUR_SERVER_IP
curl -I https://example.com

FAQ

My site won't load after the change and shows Cloudflare error 521/522. Why?

It means Cloudflare can't connect to your origin. Check that the firewall includes every Cloudflare IP range (IPv6 included), that Nginx is running, and that your SSL mode matches your origin certificate.

Can Cloudflare protect SSH, game ports and other non-web services?

The free plan only proxies HTTP/HTTPS traffic, and only on specific ports. SSH, databases, game servers and other TCP/UDP services don't go through Cloudflare, so they still rely on the server's own firewall and data-center-level DDoS protection.

Is there a stricter origin check than an IP allowlist?

Yes. Enable Authenticated Origin Pulls (mTLS) in Cloudflare so that Nginx on your origin only accepts requests carrying Cloudflare's client certificate. This stops someone from pointing their own Cloudflare account at your IP.

What if my origin IP is already under attack?

First identify the attack type and traffic volume, then change the IP and complete the protection setup above. Large-volume attacks saturate upstream bandwidth outright, and at that point you need your provider's high-capacity DDoS protection to deal with them.

Summary

Hiding your origin IP comes down to three things: route all traffic through the Cloudflare proxy, find and eliminate past leaks, and make the origin firewall accept connections only from Cloudflare. For non-HTTP services or very large attacks, a CDN can't cope on its own. IMIDC offers VPS and dedicated servers with DDoS protection and support for multiple IPs, which can serve as the underlying protection for your origin. To change IPs or evaluate a protection plan, open a 24/7 ticket in the Client Center.

Related Products

Related Articles

Was this answer helpful?

Related Tutorials