On an Ubuntu web server, I am configuring UFW to whitelist the Cloudflare IPs, but for some reason, the 162.158.0.0/15 range continues to be blocked.
Do I need to change the order of the rules even though I don't have any "deny" rules?
This is how the ufw is configured:
22/tcp LIMIT IN Anywhere
80,443/tcp (Apache Full) ALLOW IN Anywhere
80/tcp ALLOW IN 103.21.244.0/22
80/tcp ALLOW IN 103.22.200.0/22
80/tcp ALLOW IN 103.31.4.0/22
80/tcp ALLOW IN 104.16.0.0/13
80/tcp ALLOW IN 104.24.0.0/14
80/tcp ALLOW IN 108.162.192.0/18
80/tcp ALLOW IN 131.0.72.0/22
80/tcp ALLOW IN 141.101.64.0/18
80/tcp ALLOW IN 162.158.0.0/15
80/tcp ALLOW IN 172.64.0.0/13
80/tcp ALLOW IN 173.245.48.0/20
80/tcp ALLOW IN 188.114.96.0/20
80/tcp ALLOW IN 190.93.240.0/20
80/tcp ALLOW IN 197.234.240.0/22
80/tcp ALLOW IN 198.41.128.0/17
443/tcp ALLOW IN 103.21.244.0/22
443/tcp ALLOW IN 103.22.200.0/22
443/tcp ALLOW IN 103.31.4.0/22
443/tcp ALLOW IN 104.16.0.0/13
443/tcp ALLOW IN 104.24.0.0/14
443/tcp ALLOW IN 108.162.192.0/18
443/tcp ALLOW IN 131.0.72.0/22
443/tcp ALLOW IN 141.101.64.0/18
443/tcp ALLOW IN 162.158.0.0/15
443/tcp ALLOW IN 172.64.0.0/13
443/tcp ALLOW IN 173.245.48.0/20
443/tcp ALLOW IN 188.114.96.0/20
443/tcp ALLOW IN 190.93.240.0/20
443/tcp ALLOW IN 197.234.240.0/22
443/tcp ALLOW IN 198.41.128.0/17
22/tcp (v6) LIMIT IN Anywhere (v6)
80,443/tcp (Apache Full (v6)) ALLOW IN Anywhere (v6)
80/tcp ALLOW IN 2400:cb00::/32
80/tcp ALLOW IN 2405:8100::/32
80/tcp ALLOW IN 2405:b500::/32
80/tcp ALLOW IN 2606:4700::/32
80/tcp ALLOW IN 2803:f800::/32
80/tcp ALLOW IN 2a06:98c0::/29
80/tcp ALLOW IN 2c0f:f248::/32
443/tcp ALLOW IN 2400:cb00::/32
443/tcp ALLOW IN 2405:8100::/32
443/tcp ALLOW IN 2405:b500::/32
443/tcp ALLOW IN 2606:4700::/32
443/tcp ALLOW IN 2803:f800::/32
443/tcp ALLOW IN 2a06:98c0::/29
443/tcp ALLOW IN 2c0f:f248::/32
This is an example of the block I see in the ufw logs:
Oct 23 18:16:49 server kernel: [14492.469894] [UFW BLOCK] IN=eth0 OUT= MAC=aa:54:00:00 SRC=162.158.62.224 DST=192.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=58 ID=0 DF PROTO=TCP SPT=46078 DPT=443 WINDOW=0 RES=0x00 RST URGP=0
PS: Edited the source IP and Mac.