If you use Cloudflare proxy servers to secure your web services I recommend you to allow external traffic only from Cloudflare. Otherwise you expose your web servers to attackers from the external network.
Whitelist Cloudflare proxy IPs (PortForward) on Unifi Dream Machine (UDM)
Reply