that is right regarding any reverse-proxy service perhaps.
staying protected can be achieved by:
a) set your firewall to accept traffic from a trusted source only.
b) set new IP to your front-ends once moved behind a service such as CF.