Rule 100015 - Ports aren’t always displayed in Firewall Events

I recently enabled the Rule 100015 (Anomaly:Port - Non Standard Port: not 80 or 443) from Cloudflare Specials rule group and noticed that the ports aren’t always displayed in the Firewall Events.


Firewall event SHOWING the port

  • Ray ID: 51d612b2c9d44024
  • Method: GET
  • Host: **********.com:2083
  • Path: /
  • Query string: Empty query string
  • User agent: Empty user agent
  • Service: WAF
  • Rule ID: 100015

Firewall event NOT SHOWING the port

  • Ray ID: 51d300a1ad46ba6a
  • Method: GET
  • Host: **********.com
  • Path: /
  • Query string: Empty query string
  • User agent: Mozilla/5.0 (compatible; Nimbostratus-Bot/v1.3.2; http://cloudsystemnetworks.com)
  • Service: WAF
  • Rule ID: 100015

Is this a bug or is there a correct way to interpret the event when the port number is omitted?

Thank you guys!

1 Like

This topic was automatically closed after 30 days. New replies are no longer allowed.