Hello, i have big problems with HTTP attack, they attack me from all country with 10.000 ips, i dont now how to block them, i cant block 10.000 ips, how can help me to protect my website from HTTP attack?
I enable Under Attack, Web Application Firewall and i block all ips to origin ip, just cloudflare have whitelist, all connection are go to cloudflare filter.
You can add some Firewall Rules to slow down the attack.
I suggest you add a rule that checks Threat Score, and if it’s above a certain number, like 50, add a Challenge. Then keep lowering that number until it stops most of the attack, but still doesn’t challenge regular visitors.