This technique is in use for years, just get IP classes from CF website and set them in your iptables for ports 80/443 + any other IPs (yours, from your organization etc) and drop the rest.
Another way to get IPs is reading e-mail headers (register account on target website to get e-mail etc), so many sites behind CloudFlare expose their webservers IPs there.