Ip list cloudeflarenet

Hi All
Hello, i would like to have the full liste of IP used for cloudeflarenet apple and the country associated. i’m working for a big company and need to add them in a trust list in order to not block our customers that are using Iphone VPN.

the list could be like this

104.28.138.2 United States CLOUDFLARENET
104.28.139.2 Indonesia Bali Denpasar CLOUDFLARENET
104.28.140.2 Brazil Federal District Brasília CLOUDFLARENET
104.28.141.2 United States Texas Round Rock CLOUDFLARENET
104.28.142.2 United States CLOUDFLARENET
104.28.143.2 United States CLOUDFLARENET
104.28.144.2 Chile Santiago Metropolitan Lampa CLOUDFLARENET
104.28.145.2 United States Washington Kent CLOUDFLARENET
104.28.146.2 United States New York New York CLOUDFLARENET
104.28.147.2 Armenia Yerevan Yerevan CLOUDFLARENET
104.28.148.2 Germany Bavaria Freising CLOUDFLARENET
104.28.149.2 South Korea CLOUDFLARENET
104.28.150.2 France Bouches-du-Rhône Istres CLOUDFLARENET
104.28.151.2 Germany Hesse Dreieich CLOUDFLARENET
104.28.152.2 Chile Santiago Metropolitan Lampa CLOUDFLARENET
104.28.153.2 United States Washington Kent CLOUDFLARENET
104.28.154.2 United States New York New York CLOUDFLARENET
104.28.155.2 Armenia Yerevan Yerevan CLOUDFLARENET
104.28.156.2 Germany Bavaria Freising CLOUDFLARENET

Cloudflare has more than one million IPv4 addresses:

I bet your best option to attempt to get some kind of information so granular for the Cloudflare IP addresses, would be to check the individual IP addresses in one or more databases linking IP addresses to geographical information (country, region, city), e.g.:

Then using the first entry as an example, you can try splitting 103.21.244.0/22 out to the four /24’s (103.21.244.0/24, 103.21.245.0/24, 103.21.246.0/24, 103.21.247.0/24), and then check one or more of the individual IP addresses across these smaller pieces, for their relevant geographical information (country, region, city).

All of the IP addresses you are listing in your example, should be a part of the 104.24.0.0/14 subnet that is listed on the IP Ranges page, so for administrative ease, it would likely be much easier of allowing 104.24.0.0/14 than the individual ones.

However, if this part is your sole goal:

The list of IP addresses that the “iCloud Private Relay” service uses, appears to be available from Apple here:

https://mask-api.icloud.com/egress-ip-ranges.csv

They are shared in RFC8805 format, and while several of them goes down to a city level, there are also many examples where it only goes to a country (and not more specific than that).

2 Likes

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.