Configuring subdomain for non-proxied traffic

I’m apparently a brainlet, how do I set up a subdomain that redirects to my origin server (for services that require direct non-proxied connections like SSH) BUT that subdomain blocks all HTTP traffic? Cause I figured out how to set up the A record/CNAME easy enough to do the redirect to origin, but I can’t figure out the blocking HTTP traffic part.

If it’s not proxied by Cloudflare, then you’ll have to do any traffic filtering at your host. Maybe they have a firewall that can restrict by service.

