Use IP Lists to refer to a group of IP addresses collectively, by name, in your firewall rule expression. You can choose to create your own custom list of IP addresses or use a list managed by Cloudflare.
For example, use a list of known office IP addresses in a firewall rule that allows requests from the addresses on the list to bypass security features. Or you may want to block requests that don’t come from the known office addresses.
When you update the content of a list, any rules that use the list are automatically updated, so you can make a single change to your firewall rules list rather than modify rules individually.
Cloudflare stores your lists at the account level and sends to the edge, so you can view, manage, and incorporate them into firewall rules for any of your zones.
Advantages of IP Lists
Using IP Lists has these advantages:
- When creating a firewall rule, using an IP List is easier and less error-prone than adding a long list of IP addresses to a firewall rules expression.
- When updating a set of firewall rules that target the same group of IP addresses, using an IP List is easier and less error prone than editing multiple firewall rules.
- IP Lists are easier to read and more informative, particularly when you use descriptive names for your lists.
Managed IP Lists: Open Proxies
Use Managed IP Lists to access Cloudflare’s IP threat intelligence.
Cloudflare scans public, open proxy lists for reachable, open proxies. After verifying the proxies, Cloudflare determines their exit IPs and creates a list of IPs you can use when writing rules via the dashboard or API.
The number of IP Lists you can create depends on the Cloudflare plans associated with the zones in your account. Regardless of plan, you can store up to a total of 10,000 items, spread across all of your lists.
|Number of IP Lists||1||10||10||10|
User role requirements
The following user roles have access to the List management functionality:
- Super Administrator
Using lists in expressions
Both the Cloudflare dashboard and the Cloudflare API support IP Lists.