Replies: 3 comments
-
建议参考a post from ServerFault 可以试试这份配置 location / {
# v4
allow 173.245.48.0/20;
allow 103.21.244.0/22;
allow 103.22.200.0/22;
allow 103.31.4.0/22;
allow 141.101.64.0/18;
allow 108.162.192.0/18;
allow 190.93.240.0/20;
allow 188.114.96.0/20;
allow 197.234.240.0/22;
allow 198.41.128.0/17;
allow 162.158.0.0/15;
allow 104.16.0.0/13;
allow 104.24.0.0/14;
allow 172.64.0.0/13;
allow 131.0.72.0/22;
# v6
allow 2400:cb00::/32;
allow 2606:4700::/32;
allow 2803:f800::/32;
allow 2405:b500::/32;
allow 2405:8100::/32;
allow 2a06:98c0::/29;
allow 2c0f:f248::/32;
deny all;
} |
Beta Was this translation helpful? Give feedback.
0 replies
-
考虑到1panel作为一个产品,感觉更适合引入的方案是 在防火墙(网站-安全)下引入一个“IP访问白名单”的功能,开启后添加IP段?然后Cloudflare的这些IP作为预设 |
Beta Was this translation helpful? Give feedback.
0 replies
-
下个版本的 waf 支持 IP 黑白名单使用 IP 组 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
1Panel 版本
lts
请描述您的需求或者改进建议
给现在的openResty网站增加一个选项:Allow traffic from Cloudflare only, 这对于在海外机器安装1panel的会比较有用。
![image](https://private-user-images.githubusercontent.com/1935044/321134000-9ea5415d-bc6f-4d7c-8f56-0297b613e828.png?jwt=eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJpc3MiOiJnaXRodWIuY29tIiwiYXVkIjoicmF3LmdpdGh1YnVzZXJjb250ZW50LmNvbSIsImtleSI6ImtleTUiLCJleHAiOjE3MzkyMDk5OTMsIm5iZiI6MTczOTIwOTY5MywicGF0aCI6Ii8xOTM1MDQ0LzMyMTEzNDAwMC05ZWE1NDE1ZC1iYzZmLTRkN2MtOGY1Ni0wMjk3YjYxM2U4MjgucG5nP1gtQW16LUFsZ29yaXRobT1BV1M0LUhNQUMtU0hBMjU2JlgtQW16LUNyZWRlbnRpYWw9QUtJQVZDT0RZTFNBNTNQUUs0WkElMkYyMDI1MDIxMCUyRnVzLWVhc3QtMSUyRnMzJTJGYXdzNF9yZXF1ZXN0JlgtQW16LURhdGU9MjAyNTAyMTBUMTc0ODEzWiZYLUFtei1FeHBpcmVzPTMwMCZYLUFtei1TaWduYXR1cmU9Mzg3NzJiNTk0MzRlMzk4ZTVhOGJiZWYzZGNkMDJjZDQ1Nzk2M2UyNGYxZmEzNGE2MzFjMTM4ZjhiODM2ZjRhMiZYLUFtei1TaWduZWRIZWFkZXJzPWhvc3QifQ.7Hs3OJOmZe10jzbfeHr9IsAARinSF72yx2htXnqlnak)
请描述你建议的实现方案
No response
附加信息
No response
Beta Was this translation helpful? Give feedback.
All reactions