You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何配置仅允许通过Cloudflare访问网站并仅接受HTTPS请求

解决方案:仅允许Cloudflare访问并强制HTTPS

一、限制服务器端口仅接受Cloudflare IP访问

直接IP能绕过Cloudflare安全规则,核心是你的服务器端口目前对所有公网IP开放,第一步要把网站的80(HTTP)和443(HTTPS)端口,仅向Cloudflare的IP段开放:

  1. 获取Cloudflare官方IP段
    Cloudflare的IP段分为IPv4和IPv6:

    • IPv4:103.21.244.0/22, 103.22.200.0/22, 103.31.4.0/22, 104.16.0.0/13, 104.24.0.0/14, 108.162.192.0/18, 131.0.72.0/22, 141.101.64.0/18, 162.158.0.0/15, 172.64.0.0/13, 173.245.48.0/20, 188.114.96.0/20, 190.93.240.0/20, 197.234.240.0/22, 198.41.128.0/17
    • IPv6:2400:cb00::/32, 2606:4700::/32, 2803:f800::/32, 2405:b500::/32, 2405:8100::/32, 2a06:98c0::/29, 2c0f:f248::/32
  2. 在服务器/路由器防火墙配置规则
    根据你的环境选择对应配置:

    • Linux(iptables):
      先允许Cloudflare IP访问端口,再拒绝其他所有IP:

      # 允许Cloudflare IPv4访问80/443
      for ip in 103.21.244.0/22 103.22.200.0/22 103.31.4.0/22 104.16.0.0/13 104.24.0.0/14 108.162.192.0/18 131.0.72.0/22 141.101.64.0/18 162.158.0.0/15 172.64.0.0/13 173.245.48.0/20 188.114.96.0/20 190.93.240.0/20 197.234.240.0/22 198.41.128.0/17; do
          iptables -A INPUT -p tcp -s $ip --dport 80 -j ACCEPT
          iptables -A INPUT -p tcp -s $ip --dport 443 -j ACCEPT
      done
      
      # 允许Cloudflare IPv6访问80/443(支持IPv6时执行)
      for ip in 2400:cb00::/32 2606:4700::/32 2803:f800::/32 2405:b500::/32 2405:8100::/32 2a06:98c0::/29 2c0f:f248::/32; do
          ip6tables -A INPUT -p tcp -s $ip --dport 80 -j ACCEPT
          ip6tables -A INPUT -p tcp -s $ip --dport 443 -j ACCEPT
      done
      
      # 拒绝其他IP访问80/443
      iptables -A INPUT -p tcp --dport 80 -j DROP
      iptables -A INPUT -p tcp --dport 443 -j DROP
      ip6tables -A INPUT -p tcp --dport 80 -j DROP
      ip6tables -A INPUT -p tcp --dport 443 -j DROP
      

      保存规则(如iptables-save > /etc/iptables/rules.v4)。

    • Linux(ufw):

      # 允许Cloudflare IPv4访问端口
      for ip in 103.21.244.0/22 103.22.200.0/22 103.31.4.0/22 104.16.0.0/13 104.24.0.0/14 108.162.192.0/18 131.0.72.0/22 141.101.64.0/18 162.158.0.0/15 172.64.0.0/13 173.245.48.0/20 188.114.96.0/20 190.93.240.0/20 197.234.240.0/22 198.41.128.0/17; do
          ufw allow from $ip to any port 80,443
      done
      
      # 拒绝其他IP访问端口
      ufw deny 80/tcp
      ufw deny 443/tcp
      

      重启ufw生效:ufw reload。

    • Windows防火墙:
      打开「高级安全Windows防火墙」,新建入站规则,选择「端口」并指定80、443,允许连接后添加Cloudflare IP段为允许的远程地址,将该规则优先级设为高于默认拒绝规则。

    • 路由器端口转发:
      不要直接开放80/443端口到服务器,在路由器防火墙中设置仅允许Cloudflare IP段访问转发端口,或直接配置IP白名单规则。

  3. 定期更新IP段
    Cloudflare IP段可能更新,建议写脚本每周自动更新防火墙规则,避免规则失效。

二、强制仅接受HTTPS请求

确保所有HTTP请求都重定向到HTTPS,服务器仅响应HTTPS请求:

  1. Web服务器配置重定向

    • Nginx:
      在网站配置文件中添加HTTP重定向块:

      server {
          listen 80;
          server_name your-domain.com www.your-domain.com;
          return 301 https://$server_name$request_uri;
      }
      
      server {
          listen 443 ssl;
          server_name your-domain.com www.your-domain.com;
      
          # 配置Cloudflare Origin CA证书(或你的SSL证书)
          ssl_certificate /path/to/origin.crt;
          ssl_certificate_key /path/to/origin.key;
      
          # 其他网站配置
      }
      

      重启Nginx:systemctl restart nginx。

    • Apache:
      在.htaccess或虚拟主机配置中添加重写规则:

      RewriteEngine On
      RewriteCond %{HTTPS} off
      RewriteRule ^(.*)$ https://%{HTTP_HOST}%{REQUEST_URI} [L,R=301]
      

      启用mod_rewrite模块后重启Apache。

  2. Cloudflare端强化设置
    在Cloudflare控制台「SSL/TLS」选项中,设置加密模式为「严格」,开启「始终使用HTTPS」和「自动HTTPS重写」,确保域名访问强制走HTTPS。

三、验证配置效果

  • 用服务器公网IP直接访问http://your-server-ip或https://your-server-ip,应显示连接被拒绝。
  • 用域名访问http://your-domain.com,应自动跳转到https://your-domain.com,且Cloudflare安全规则正常生效。

内容的提问来源于stack exchange,提问作者ibbe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 09:10:40