DDOS from Cloudflare IP addresses even in Under Attack Mode

Hello, for the last three days I am being DDOS’d periodically with a huge amount of traffic (up to 100gb per hour). Initially Sloudflare, helped, but today I found that my apache server went down.

My settings are as follows:

  1. Root (/) page is always in under attack mode
  2. Firewall is creating JS Chalenge for every user not from 6 particular countries.

In server logs I see tens of thousands of requests per second from Sloudflare ip addresses, how did they get through JS Chalenge and why weren’t they stopped?

You’ll need to be restoring the actual visitor IP addresses to be able to make any meaningful decisions based on access logs.



