Answer these questions to help the Community help you with Security questions.
What is the domain name ?
snacky.live
Have you searched for an answer?
yes , i added waf rules to block all counties and except saudi arabia
also add min score
Describe the issue you are having:
the waf is not blocking counties but the min thread score is blocking but not all traffic
What error message or number are you receiving?
securtiy center Infrastructure showing the waf in domain is off
What steps have you taken to resolve the issue?
add another rules
2.turn off the rules then turn it back
clear cache
Are you sure the connections are coming through Cloudflare or are there direct IP connections?
yes they use a get requset with random /?[random 8 to 12 string and number]
How are you seeing these requests reach your server? Are there access logs showing Cloudflare IPs?
yes around 4k ip from diffrent locations some aws some tor some digtalocheans
i am under attack or bot did not work only threat score manage to reduce last attack from 68 to 32 gb
animesnacky:
yes
How have you confirmed this? Does your origin block connections from non-Cloudflare IP addresses?
1 Like
fritex
April 6, 2023, 12:09am
8
Helpful article:
This guide is for those users of Cloudflare who experience medium-high level complexity DDoS attacks.
Continue reading if you want to accomplish the following:
Becoming more familiar with the Cloudflare Dashboard and crafting custom firewall rules.
Understanding the standard behavior of DDoS attacks and deploying effective firewall rules.
Realizing how powerful and valuable Cloudflare Firewall Rules are.
I initially thought of making a more complex guide (I will). However, I realized that no…
animesnacky:
aws
If you’re not on AWS block it by the ASN with the IP Access Rules, at least temporary.
AS38895
Amazon.com Tech Telecom
AS14618
AMAZON-AES
AS16509
AMAZON-02
How to:
Last but not the least, kindly see more by reading Cloudflare articles which contain a lot of helpful information for better understanding and usage as well in terms of Security and Protection:
3 Likes
system
Closed
April 9, 2023, 12:09am
9
This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.