Please can someone tell me if we can lock down our Cloudflare CDN so that it only gets requests from our own website? Our current legacy CDN, MaxCDN, does not allow us to lock down requests, and so it is possible to abuse the CDN URL by requesting the CDN endpoint with any page on our website. We don’t want a WAF, we just want to lock down requests for our own assets.


Cloudflare acts as a transparent proxy so there isn’t a CDN URL. You can enable hotlink protection which can help with people directly linking to assets. https://support.cloudflare.com/hc/en-us/articles/200171036-What-does-Scrape-Shield-do-