From de8048e72710214a1935f22986ce1edeb9866196 Mon Sep 17 00:00:00 2001 From: henk Date: Tue, 13 Feb 2024 23:09:37 +0100 Subject: [PATCH] 2024-02-13 23:09:37 --- nginx/cloudflare/README.md | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) create mode 100644 nginx/cloudflare/README.md diff --git a/nginx/cloudflare/README.md b/nginx/cloudflare/README.md new file mode 100644 index 0000000..69fd24d --- /dev/null +++ b/nginx/cloudflare/README.md @@ -0,0 +1,33 @@ +Add the following to the /etc/nginx/nginx.conf +to get the real ip adresses from the cloudflare tunnels directed to in your logging. + +in + +http { + +set_real_ip_from 103.21.244.0/22; +set_real_ip_from 103.22.200.0/22; +set_real_ip_from 103.31.4.0/22; +set_real_ip_from 104.16.0.0/12; +set_real_ip_from 108.162.192.0/18; +set_real_ip_from 131.0.72.0/22; +set_real_ip_from 141.101.64.0/18; +set_real_ip_from 162.158.0.0/15; +set_real_ip_from 172.64.0.0/13; +set_real_ip_from 173.245.48.0/20; +set_real_ip_from 188.114.96.0/20; +set_real_ip_from 190.93.240.0/20; +set_real_ip_from 197.234.240.0/22; +set_real_ip_from 198.41.128.0/17; +set_real_ip_from 2400:cb00::/32; +set_real_ip_from 2606:4700::/32; +set_real_ip_from 2803:f800::/32; +set_real_ip_from 2405:b500::/32; +set_real_ip_from 2405:8100::/32; +set_real_ip_from 2c0f:f248::/32; +set_real_ip_from 2a06:98c0::/29; +set_real_ip_from 172.30.0.0/24; # the CF tunnel local ip's +set_real_ip_from 192.168.200.0/24; ; +real_ip_header CF-Connecting-IP; +# CF documentation and for any tunnel out ip add it here +