Cloudflare
Cloudflare Spectrum

The Solution

Cloudflare Spectrum + Load Balancing

TLS Fingerprinting with Passthrough

The Constraint

With true TLS passthrough, Cloudflare forwards encrypted packets without inspecting the TLS handshake.

JA3/JA4 fingerprinting is available only when TLS is terminated at Cloudflare edge (Bot Management L7).

Alternative Approach

Option 1: If HTTPS web traffic can be terminated at Cloudflare, JA3/JA4 becomes available for that traffic via Bot Management.

Option 2: Continue with passthrough for protocols requiring it (SMTP) and leverage other L4 controls — IP filtering, geo blocking, and L3/L4 DDoS protection.

Trade-off: True passthrough maintains end-to-end encryption but limits visibility. A hybrid architecture can maximise security where TLS termination is acceptable.

Proposed Architecture

Clients

Clients

CCTV / Alarm Systems

Cloudflare

Cloudflare Spectrum

L4 Proxy + DDoS + IP Rules

Load Balancer

Cloudflare LB

Weighted + Health Checks

Origin

IMMIX Origin

TLS Termination

Encrypted End-to-End

TLS passes through uninterrupted

Source IP Preserved

Proxy Protocol to origin

Weighted Distribution

Across backend servers

The Solution Cloudflare Spectrum + Load Balancing