@Gargron Make sure you prevent spoofing…

Drop any incoming Fastly-Client-IP stuff coming in to fastly from external as per this page: developer.fastly.com/reference

Drop any incoming X-Forwarded-For stuff coming in to fastly from external as per this page: developer.fastly.com/reference