4 ms·
Unfortunately, that doesn't work as traffic is proxied through CloudFlare. i.e. all the traffic reaching my machine comes from CloudFlare IPs. The only way to k
by stanislavb 2y ago
Unfortunately, that doesn't work as traffic is proxied through CloudFlare. i.e. all the traffic reaching my machine comes from CloudFlare IPs. The only way to know the real IP is at web-server level (e.g. Nginx).
Usually, I can block similar traffic at CloudFlare level; however, that's somehow not the case with that IP.
- LinuxBender 2y agoThis is not for you to get the real IP. What I described is for you to give to Cloudflare support so that they can look through any logs they may have and find the needle in the haystack of data. I am making an assumption that they log access to anything that might act like a forward proxy abusing their worker code, etc... Only Cloudflare employees could really say if the data is useful. If it is then they could get the real IP address and maybe even do some captures of their own to update their attack / bot detection assuming this is of interest to them. If they are unable to help then the best I could suggest would be to keep that abusive IP blocked at the risk of legit people also being blocked. Another potential option would be to just exclude logging from that IP or URL request patterns if they are not actually hurting your server. NGinx and Apache allow excluding or including status codes to log to get rid of noise. One can always disable this when debugging.