I have a question , with this statement below , do I apply the rules to my firewall on an inbound or outbound direction for cloudflare ? …thinking inbound / port forwarding but wanted to confirm
In terms of a stateful firewall/port forwarding, you want inbound! Cloudflare will be initiating the connection to you/your web server from their Proxy IPs. You will of course be responding outbound to them, but stateful firewalls will allow that/you most likely don’t have any restrictions on outbound connections otherwise you wouldn’t be able to use this forum!

