Last active
March 10, 2023 18:56
-
-
Save oznakn/b1af081c99c2bfeb9dca2b15a17366ab to your computer and use it in GitHub Desktop.
Allow ports 80 and 443 from Cloudflare IPs
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
for i in `curl https://www.cloudflare.com/ips-v4`; do sudo ufw allow from "$i" proto tcp to any port 80; done | |
for i in `curl https://www.cloudflare.com/ips-v4`; do sudo ufw allow from "$i" proto tcp to any port 443; done | |
for i in `curl https://www.cloudflare.com/ips-v6`; do sudo ufw allow from "$i" proto tcp to any port 80; done | |
for i in `curl https://www.cloudflare.com/ips-v6`; do sudo ufw allow from "$i" proto tcp to any port 443; done |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
real_ip_header CF-Connecting-IP; | |
set_real_ip_from 173.245.48.0/20; | |
set_real_ip_from 103.21.244.0/22; | |
set_real_ip_from 103.22.200.0/22; | |
set_real_ip_from 103.31.4.0/22; | |
set_real_ip_from 141.101.64.0/18; | |
set_real_ip_from 108.162.192.0/18; | |
set_real_ip_from 190.93.240.0/20; | |
set_real_ip_from 188.114.96.0/20; | |
set_real_ip_from 197.234.240.0/22; | |
set_real_ip_from 198.41.128.0/17; | |
set_real_ip_from 162.158.0.0/15; | |
set_real_ip_from 104.16.0.0/13; | |
set_real_ip_from 104.24.0.0/14; | |
set_real_ip_from 172.64.0.0/13; | |
set_real_ip_from 131.0.72.0/22; | |
set_real_ip_from 2400:cb00::/32; | |
set_real_ip_from 2606:4700::/32; | |
set_real_ip_from 2803:f800::/32; | |
set_real_ip_from 2405:b500::/32; | |
set_real_ip_from 2405:8100::/32; | |
set_real_ip_from 2a06:98c0::/29; | |
set_real_ip_from 2c0f:f248::/32; |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment