Can cloudflared tunnels revel the origin ip of the server in any case?

any known reverse engg possible? had this question raised up by a client yesterday in client call.
13 Replies
z0rrn
z0rrn5mo ago
I think no but I'm not an expert.
hhf
hhfOP5mo ago
I have to sure before answering my clients.
andrew_nyr
andrew_nyr5mo ago
?pings
Flare
Flare5mo ago
Please do not ping community members for non-moderation reasons. Doing so will not solve your issue faster and will make people less likely to want to help you.
hhf
hhfOP5mo ago
understood my apologies
andrew_nyr
andrew_nyr5mo ago
The answer is no though, your origin IP will not be revealed when you are using a Cloudflare Tunnel with their reverse proxy.
hhf
hhfOP5mo ago
No description
itsmatteomanf
itsmatteomanf5mo ago
That is your private dashboard and those are private IPs, even if I know them, I can’t do anything
hhf
hhfOP5mo ago
So there is no way anyone can know on what public ip my vm is So my response to the client will be that there is no chance that ip's(public) of the vm will be exposed if we are using CF tunnels.? Client has not opened a single port on firewall or VM. And i really apologies again to the team for tagging them. sometimes typing fast can lead to embracement.
itsmatteomanf
itsmatteomanf5mo ago
No way directly from the web facing service, no. The server can still expose itself, if does API calls itself or reaches out. But a user connecting to the CF domain, served via tunnel won’t expose the IP. There has to be a coding error or some active call from the server to expose it.
hhf
hhfOP5mo ago
There is no api calls where public ip mentioned nor we have ever used public ip any where. We have been also monitoring it for couple of weeks. No leaks. But just to sure I wanted a confirmation from the community before giving a response. Thanks @itsmatteomanf 🙏 Because you guys know more. If someone has reported before or so. You guys answer 100 of queries. The input from you is more valuable than any docs written
itsmatteomanf
itsmatteomanf5mo ago
Thanks! Yeah, you should be good 🙂 Even a normal proxy works well with hiding the IP, but the port is still open and it’s one click away from making it public. This way it’s not possible at all.
hhf
hhfOP5mo ago
Cool. Thanks again. I will be able to keep this client on CF. I fought really hard for this one.
Want results from more Discord servers?
Add your server