Bot Protection and WAF rules

We have a SignalR app that is allowed on our site.
Our Cloudflare Bot Protection setting for Definitely automated is set to “Managed Challenged”.
This has blocked some of the connections to our SignalR app.
To override the Bot protection, I have added a WAF rule to skip if certain URLs are used.
The WAF rule I created is no 1 on the list.
In some cases, a legit URL is working, and, in some cases, the same URL is blocked.
What has preceded BOT fighting or WAF?

If you’re saying you are trying to use Managed Rules to skip Super Bot Fight Mode, use Custom Rules instead: Super Bot Fight Mode is now configurable!

If even with a Custom Rule to skip SBFM it is still being blocked, I would check Security → Events and check what is blocking it.

1 Like

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.