Origin lock accepts HTTP/HTTPS only from official CDN ranges. Direct hits to the server IP on 80/443 are dropped.
- Confirm orange-cloud DNS already works.
- DDoS / CDN → Refresh CF IPs (
lsf --cf-refresh). - Set
CF_ORIGIN_ONLY=1inlsf.conf. - Enable / Restart.
Same pattern for Bunny: Refresh Bunny IPs and BUNNY_ORIGIN_ONLY=1. Refresh often — Bunny edges rotate. If a refresh leaves the list empty, LSF skips origin-lock instead of dropping all HTTP.
