Cloudflare Proxy Alone Won't Protect Your Origin Server, Here's What Will
Simply enabling Cloudflare's DNS proxy does not shield an origin server if attackers discover its real IP through DNS history tools, certificate transparency logs, or subdomain scanning. A comprehensive hardening approach requires three layers: restricting server firewall rules to accept traffic only from Cloudflare's published IP ranges, enabling Authenticated Origin Pulls so the origin verifies requests carry a Cloudflare-signed client certificate, and setting SSL/TLS mode to Full (strict) with a valid Cloudflare Origin CA certificate. Management ports such as SSH and database access must be locked separately to a VPN or bastion host, as Cloudflare does not proxy these connections. Each control should be independently verified — for example, running a direct curl request to the origin IP to confirm outside traffic is blocked — rather than assumed active after toggling a setting.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in