Start typing to search across invoices, services, domains, tickets, and more...
Once your site is behind Cloudflare, visitors and attackers see Cloudflare's edge IPs instead of your server's IP. But if your real IP has already leaked, or your server still accepts traffic on ports 80/443 from any address, attackers can simply bypass the CDN and hit your origin directly. This guide walks you through the whole process, from onboarding and finding leaks to locking down the firewall, so your origin is genuinely hidden.
On the DNS page of the Cloudflare dashboard, set the proxy status of your site's A/AAAA records to "Proxied" (orange cloud). Now dig +short example.com should return Cloudflare IPs, not your server's IP.
Under SSL/TLS, choose Full (strict). For the origin certificate you can use Let's Encrypt, or generate a free Origin CA certificate in the Cloudflare dashboard (trusted only by Cloudflare, valid for up to 15 years). Do not use Flexible mode: it sends traffic between Cloudflare and your origin in plain text and often causes redirect loops.
Before you moved to the CDN, your domain may already have resolved directly to your server's IP. Common leak sources include:
mail, ftp or dev set to the grey cloud and pointing straight at the same server.If your IP has definitely leaked, Cloudflare alone can't fully fix it, and we recommend changing the server IP. IMIDC customers can open a ticket in the Client Center to ask about changing IPs or adding more.
Cloudflare publishes its official IP ranges at https://www.cloudflare.com/ips-v4 and https://www.cloudflare.com/ips-v6. The commands below read the latest lists directly.
Ubuntu / Debian (UFW):
sudo ufw allow OpenSSH # If you changed the SSH port, use: sudo ufw allow <port>/tcp
for ip in $(curl -fsS https://www.cloudflare.com/ips-v4) $(curl -fsS https://www.cloudflare.com/ips-v6); do
sudo ufw allow proto tcp from "$ip" to any port 80,443 comment 'Cloudflare'
done
# Remove earlier rules that opened 80/443 to everyone (delete whichever actually exist)
sudo ufw delete allow 'Nginx Full'
sudo ufw delete allow 80/tcp
sudo ufw delete allow 443/tcp
sudo ufw enable
sudo ufw status numbered
If deleting a rule prints "Could not delete non-existent rule", you can ignore it.
Rocky / Alma 9 (firewalld + ipset):
sudo firewall-cmd --permanent --new-ipset=cf4 --type=hash:net
sudo firewall-cmd --permanent --new-ipset=cf6 --type=hash:net --option=family=inet6
for ip in $(curl -fsS https://www.cloudflare.com/ips-v4); do
sudo firewall-cmd --permanent --ipset=cf4 --add-entry="$ip"
done
for ip in $(curl -fsS https://www.cloudflare.com/ips-v6); do
sudo firewall-cmd --permanent --ipset=cf6 --add-entry="$ip"
done
for svc in http https; do
sudo firewall-cmd --permanent --add-rich-rule="rule family=ipv4 source ipset=cf4 service name=$svc accept"
sudo firewall-cmd --permanent --add-rich-rule="rule family=ipv6 source ipset=cf6 service name=$svc accept"
done
# Remove the http/https services that were open to all sources
sudo firewall-cmd --permanent --remove-service=http --remove-service=https
sudo firewall-cmd --reload
sudo firewall-cmd --list-all
Cloudflare's IP ranges change occasionally, so check them against the official list every few months.
Note: ports published by Docker bypass UFW rules. If your site runs in Docker, bind the container ports to
127.0.0.1and let Nginx on the host serve the public traffic.
Add a default site to Nginx that drops connections to the bare IP or unknown hostnames, so your certificate doesn't reveal your domain:
sudo tee /etc/nginx/conf.d/00-default.conf > /dev/null <<'EOF'
server {
listen 80 default_server;
listen [::]:80 default_server;
server_name _;
return 444;
}
server {
listen 443 ssl default_server;
listen [::]:443 ssl default_server;
server_name _;
ssl_reject_handshake on;
}
EOF
ssl_reject_handshake requires Nginx 1.19.4 or later. The stock versions on Ubuntu 24.04, Debian 12 and Rocky/Alma 9 all qualify; the 1.18 shipped with Ubuntu 22.04 does not, so upgrade from the official nginx.org repository. On Ubuntu/Debian, also remove the bundled default site to avoid a default_server conflict:
sudo rm -f /etc/nginx/sites-enabled/default
Behind Cloudflare, the client IP in your Nginx logs becomes a Cloudflare edge IP. Restore the real one with the realip module:
{
for ip in $(curl -fsS https://www.cloudflare.com/ips-v4) $(curl -fsS https://www.cloudflare.com/ips-v6); do
echo "set_real_ip_from $ip;"
done
echo "real_ip_header CF-Connecting-IP;"
} | sudo tee /etc/nginx/conf.d/cloudflare-realip.conf > /dev/null
sudo nginx -t && sudo systemctl reload nginx
Run these from a different machine. The first should fail or time out, while access via the domain works normally:
curl -m 10 -I http://YOUR_SERVER_IP
curl -I https://example.com
It means Cloudflare can't connect to your origin. Check that the firewall includes every Cloudflare IP range (IPv6 included), that Nginx is running, and that your SSL mode matches your origin certificate.
The free plan only proxies HTTP/HTTPS traffic, and only on specific ports. SSH, databases, game servers and other TCP/UDP services don't go through Cloudflare, so they still rely on the server's own firewall and data-center-level DDoS protection.
Yes. Enable Authenticated Origin Pulls (mTLS) in Cloudflare so that Nginx on your origin only accepts requests carrying Cloudflare's client certificate. This stops someone from pointing their own Cloudflare account at your IP.
First identify the attack type and traffic volume, then change the IP and complete the protection setup above. Large-volume attacks saturate upstream bandwidth outright, and at that point you need your provider's high-capacity DDoS protection to deal with them.
Hiding your origin IP comes down to three things: route all traffic through the Cloudflare proxy, find and eliminate past leaks, and make the origin firewall accept connections only from Cloudflare. For non-HTTP services or very large attacks, a CDN can't cope on its own. IMIDC offers VPS and dedicated servers with DDoS protection and support for multiple IPs, which can serve as the underlying protection for your origin. To change IPs or evaluate a protection plan, open a 24/7 ticket in the Client Center.