DNS only domain setup WAF custom rules

What is the name of the domain?

riverview.nsw.edu.au

What is the issue you’re encountering

We would like to implement the custom rule for allow certain ip address can access https://forms-dev.riverview.nsw.edu.au/manage/*, and block other access

What is the current SSL/TLS setting?

Full (strict)

What are the steps to reproduce the issue?

The rule does not seem to be working at the moment for the DNS subdomain. If we purchase the Account-level web application firewall (WAF) add-on, will it work for this purpose? Many thanks.

forms-dev is delegated to AWS nameservers and is not proxied through Cloudflare, therefore Cloudflare settings will have no effect on requests to this subdomain…
https://cf.sjr.dev/tools/check?c793e08debc045b8b0a4da7b40236685#dns

5 Likes

Thanks for that, what about this subdomain? The current setting would like below.

forms.riverview.nsw.edu.au
ns-947.awsdns-54.net DNS only
ns-1721.awsdns-23.co.uk DNS only
ns-236.awsdns-29.com DNS only
ns-1093.awsdns-08.org DNS only

What is the Cloudflare IP address for A/AAAA records?

Thanks, Alex

As that is set up the same, it is also not using the proxy…
https://cf.sjr.dev/tools/check?5a8582865e584c19a4e7c4222fb44e47#dns

If you want to use the Cloudflare WAF for these subdomains you would need to remove the delegation, add the A records for them instead into your Cloudflare DNS and proxy those records.

4 Likes

Thanks a lot. Is it possible to remove the screenshot (Dev_Forms_Custom_Rules.png) I uploaded previously?

Thanks, Alex

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.

I flagged your post that has the screenshot and noted your request.

1 Like