I was sharing it as reference material rather than a suggestion to employ exactly that same configuration. I don’t know if that is what you need. If it is, you can create that as a Custom Rule in the WAF.
Jetpack writes this: If you are using Cloudflare they also support only allowing traffic coming from servers with a specific ASN (autonomous system number). To configure that, you can allow access to 2635 .
If you block anything that matches what I shared, it allows only traffic from ASN 2635 to connect to /xmlrpc.php. If that is your goal, you csn use it as written. If you want something else, you can adapt your rules further.