Restore the client address from a trusted proxy before limiting requests by IP. Otherwise many visitors can be counted as one CDN server.
Why the wrong people get blocked
Alice and Bob both pass through the same CDN address. Without real-IP handling, Nginx sees that CDN address for both. Alice's traffic can consume the quota that Bob appears to share.
Trust the proxy, not any incoming header
This illustrative configuration belongs inside . The documentation-only address must be replaced by actual trusted proxy ranges; the example assumes the proxy maintains correctly:
