How to exclude a section from the under attack rules

Hey all,
one of our subdomains serves up content for an iframe that is embedded into client sites. When we turn under attack on (as we had to recently) the iframes don’t work very well :wink:

Is there a way to set a page rule to exclude a subdomain from the usual under attack settings?

We would like to add a rate limit on it to stop people hammering that part, but having the interstitial is a problem.

All the Best,

You can configure a page rule with “Disable Security”. I am not absolutely sure this will also work under “I am under attack” (as that is somewhat of a nuclear option) but its worth a try.

