@Gargron Make sure you prevent spoofing…
Drop any incoming Fastly-Client-IP stuff coming in to fastly from external as per this page: https://developer.fastly.com/reference/http/http-headers/Fastly-Client-IP/
Drop any incoming X-Forwarded-For stuff coming in to fastly from external as per this page: https://developer.fastly.com/reference/http/http-headers/X-Forwarded-For/