CloudFlare IPs have been bombadding my site with requests

For days Cloudflare IPs have been bombarding my site with requests. I have no idea why, but when I check my site’s raw access logs, I see many Cloudflare IPs beginning with 172.70.%.% such as the few below making lots of requests with “JSitemapbot/1.0”. This shoots up my servers load until I block the entire US from accessing my site.
172.70.135.187
172.71.222.132
172.70.175.92
172.70.174.195
172.70.175.202
172.70.174.148
172.70.174.149
172.70.174.194
172.70.174.188
172.70.135.117
How do I fix this?
The IPs are more than I can list here and I have uploaded my access log to this URL because your uploader does not allow me to upload it.

These are standard proxy addresses, so that won’t be “Cloudflare” but regular client requests via the proxies.

You should rewrite IP addresses to get the actual address - https://support.cloudflare.com/hc/en-us/articles/200170786-Restoring-original-visitor-IPs

Of course, you could also block based on the user agent.

1 Like

For days Cloudflare IPs have been bombarding my site with requests. I have no idea why, but when I check my site’s raw access logs, I see many Cloudflare IPs beginning with 172.70.%.% such as the few below making lots of requests with “JSitemapbot/1.0”. This shoots up my servers load until I block the entire US from accessing my site.
172.70.135.187
172.71.222.132
172.70.175.92
172.70.174.195
172.70.175.202
172.70.174.148
172.70.174.149
172.70.174.194
172.70.174.188
172.70.135.117
How do I fix this?
The IPs are more than I can list here and I have uploaded my access log to this URL because your uploader does not allow me to upload it.

Please clarify the’’ block based on User Agent" .

Which of the Cloudflare tools do I use for this? Can you outline steps?

https://community.cloudflare.com/search?q=user%20agent%20blocking

1 Like

The user agent with the most hits is A Google User Agent.

Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/107.0.5304.110 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)

Seems they are mostly legit bots. What Do I do in this case.

This topic was automatically closed 10 hours after the last reply. New replies are no longer allowed.