Allowing only required CloudFlare IP addresses instead of while CIDR ranges

Hi, Cloudflare community

We’d like to configure our Firewall to allow traffics hitting our production servers only coming from Cloudflare

From here, IP Ranges

I need to whitelist very big CIDR ranges. My manager has concern whether we should really allow these big ranges?

Currently, we are using Cloudflare DNS, WAF, SSL services

Can we narrow down the Cloudflare IP address ranges further?

Do we absolutely need to allow the entire CIDR ranges from the list? Or we can allow only 6~10 IP addresses only?

Thanks

It might be possible to narrow it down (though, support should be your point of contact in this case) but you will also run the risk of having to “constantly” update the list when addresses change and I guess they can change at any time within the mentioned ranges.

I believe that Cloudflare owns those blocks. So if you whitelist those, only Cloudflare will get in. Any more restrictive and you risk visitors not being able to reach your sites.

As @sandro said, Support can probably give you a better answer, but I doubt they’ll recommend anything more restrictive than what’s listed.

1 Like

Thanks, all
I will contact CloudFlare support then

1 Like

Another alternative you can look into is

https://support.cloudflare.com/hc/en-us/articles/204899617-Authenticated-Origin-Pulls

This method is based on verification of the TLS Client Certificate CF presents when making a HTTPS connection with your site, your web server can be set up to deny all requests that don’t present this specific certificate.

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.