Cloudflare Free Plan User Blocks 55% of Requests With Custom WAF Rules

A user analyzed one week of firewall logs for their Cloudflare-protected website, finding 34,000 requests between September 17 and 24. Over half of the traffic triggered security actions, consisting of common background scans for files like .env, .git, and WordPress admin panels. The user implemented four custom WAF rules on the free plan to block these automated probes by targeting scanner paths, networks, and timing. They caution that automated analysis can mislabel legitimate routes and warn that rate-limiting rules are less effective than path-based blocking for slow scanners.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in