StackPath IPs Blocked by ConfigServer Firewall

I put my website behind StackPath's CDN to see if it would speed it up some for some users. It was working great by all accounts.

Someone then tried to do some SQL injection etc etc and mod_security picked it up... boom... StackPath's CDN IP blocked in CSF.

StackPath do pass an X-FORWARDED-FOR header. Is there no way to get CSF to block that IP as opposed to the CDN's?

I am using LF_IPSET = ON

I presume a way around this would be to disable mod_security completely for any domains behind StackPath (using CSF ModSec Control) and turn on the StackPath WAF instead? Any problems with that plan?

