Furthermore, is the Bot Fight Mode option enabled?
Have you blocked access to your XML-RPC due to security reasons?
Do you have some security plugin installed like Wordfence Security?
Are you blocking your REST API access?
Or allowing only to autenticated user with granted rights /password to access it?
I’m having the same issue. I have a firewall rule in place to allow the user-agent of Zapier, but it still gets blocked by Super Bot Fight mode. We’re on a Pro account, but it seems that our firewall rules do not affect things that are blocked by Super Bot Fight mode? How do we make an exception for Zapier?
Furthermore, is the Bot Fight Mode option enabled? Yes.
Have you blocked access to your XML-RPC due to security reasons? - No Do you have some security plugin installed like Wordfence Security? - Yes. Are you blocking your REST API access? - No Or allowing only to autenticated user with granted rights /password to access it? - No.
Have you checked this one? - Yes, but I’m not sure it applies here.
The Zapier Support team was unable to help me and asked me to contact Cloudflare support.
I got a list of thousands of AWS IPs from Zapier to whitelist. But that can’t be the solution, as people are facing issues even after whitelisting IPs in the Firewall settings.
I am just not sure, if you allow Amazon AS number (AS16509) in the IP Access Rules with “Allow”, even if it would work, that would be a tricky one because a lot of “bad bots” and “price/product scrappers” also come from Amazon AS numbers too on a daily basis
Which in this case, is even worse (as we would allow everyone from Amazon to access our website and attack, if so) than allowing all of us-east-1, which also is not going to be the right solution.
Yep, I found also a possible workaround but hm … like using a Firewall Rule if “User-Agent” contains “Zapier” with the action “allow”, but again as @web stated it’s also blocked due to the Bot Fight Mode which executes before
@web@ankitbasu And disabling Bot Fight Mode isn’t an option too, right?
Correct - Bot Fight Mode really needs to stay enabled - it’s largely the reason we use CF on this particular site. What is the possible workaround you are looking at @fritex ?