
Destination IP / http.dst.ip?

ufw firewall to allow only Cloudflare IPs to the local HTTPS portufw is a simple frontend for iptables, very common.ufw installed IMHOufw, it is pretty simple and very useful for these tasks. Also helps avoiding yourself shooting in the foot, aka locking yourself out by accident.
Destination IPhttp.dst.ipcertbot renewufwufwufwufwfor cfip in `curl -sw '\n' https://www.cloudflare.com/ips-v{4,6}`; do ufw allow from $cfip to any port 443 comment 'Cloudflare IP'; done