One of the common steps taken to secure a WordPress installation is to restrict access to wp-login.php using .htaccess rules. This restricts who can login to the website by specifying which networks can and blocking everything else.
For example, this would restrict access to wp-login.php for all networks except for 126.96.36.199 and 188.8.131.52
order deny, allow deny from all allow from 184.108.40.206 allow from 220.127.116.11
But this won’t work when the website is connected through CloudFlare – as all requests will be coming through the CloudFlare network.
Instead, you can use the following
SetEnvIf X-FORWARDED-FOR 18.104.22.168 allow SetEnvIf X-FORWARDED-FOR 22.214.171.124 allow order deny,allow deny from all allow from env=allow