能否通过Cloudflare DNS实现同子域名按端口定向至不同IP?
Great question—let’s cut straight to the chase: DNS (including Cloudflare’s DNS service) can’t do port-based routing by design. DNS only maps domain names to IP addresses; it has no awareness of TCP/UDP ports (that’s the transport layer’s job, handled after the DNS lookup completes). So you can’t configure a DNS record that sends traffic to different IPs just based on the requested port.
But don’t worry—Cloudflare has other tools to achieve exactly what you’re asking for in both scenarios. Let’s break this down:
Scenario 1: Route one.example.com to different IPs by port
Your goal:
one.example.com:80&one.example.com:443→1.1.1.1one.example.com:23455→2.2.2.2
Here are two reliable ways to set this up:
- Option 1: Cloudflare Load Balancing with Pool Rules
- Create two origin pools: one for
1.1.1.1(targeting ports 80/443) and another for2.2.2.2(targeting port 23455). - Set up a load balancer for
one.example.com, then add a routing rule that checks the request port. Route traffic to the2.2.2.2pool if the port is 23455; send all other traffic to the1.1.1.1pool.
- Create two origin pools: one for
- Option 2: Cloudflare Tunnel + Zero Trust Access
- Set up separate Cloudflare Tunnels for both
1.1.1.1(exposing ports 80/443) and2.2.2.2(exposing port 23455). - Create Zero Trust access rules that direct incoming traffic to the appropriate tunnel based on the requested port.
- Set up separate Cloudflare Tunnels for both
Scenario 2: Default to 1.1.1.1, but override ports 80/443 to 2.2.2.2 (with direct access to 2.2.2.2:23455)
Your goal:
- Default
one.example.com→1.1.1.1 one.example.com:80&one.example.com:443→2.2.2.2- Traffic to
2.2.2.2:23455bypasses1.1.1.1entirely
Here’s how to make this work:
- Set the default DNS record: Point
one.example.comto1.1.1.1and enable Cloudflare’s proxy (the orange cloud icon) so traffic goes through Cloudflare’s network. - Override ports 80/443 with Load Balancing:
- Create a load balancer for
one.example.comwith a default pool pointing to1.1.1.1. - Add a rule that matches requests to ports 80 or 443, and routes those to a pool containing
2.2.2.2.
- Create a load balancer for
- Direct access to
2.2.2.2:23455:- If you can use a different subdomain (e.g.,
port23455.one.example.com), create an unproxied DNS record (gray cloud) pointing directly to2.2.2.2. Users will connect straight to2.2.2.2:23455without going through1.1.1.1. - If you need to keep the same
one.example.comsubdomain, set up a Cloudflare Tunnel for2.2.2.2:23455. Traffic will go through Cloudflare’s network but won’t touch1.1.1.1at all.
- If you can use a different subdomain (e.g.,
Key Takeaway
DNS itself doesn’t handle port-based routing, but Cloudflare’s higher-layer tools (Load Balancing, Tunnels, and routing rules) let you replicate the behavior you want without relying on DNS tricks.
内容的提问来源于stack exchange,提问作者Matthias

