WAF custom rule fails to Block the Non USA IPs

What is the name of the domain?

What is the issue you’re encountering

The WAF Custom rule unable to block the IPs belongs to out of USA in most case.

What steps have you taken to resolve the issue?

Make the A record and CNAME record proxy.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Full (strict)

What are the steps to reproduce the issue?

Just Load the https://seniorleadsboost.com site from Non USA country using VPN.

From the UK I am blocked on www but not for your apex domain.
https://cf.sjr.org.uk/tools/check?d4d59626d55c49e8b37dc6167d3f6f20#connection-server-https
https://cf.sjr.org.uk/tools/check?3cabfbd86fa4495e93dc9e6ac1be011c#connection-server-https

Who is your host? If they use Cloudflare, then make sure to also use the CNAME for the apex domain DNS record instead of an A record so requests pass through your account first.

Otherwise, can you show a screenshot of your WAF rule.

First of all thank to look at this issue,

We used the Go High Level CRM to host our site.


Above I uploaded the WAF custom rule to Block traffic from non UAS countries.

Thank you.

GHL use Cloudflare for SaaS so as I mentioned above, you need to use only the proxied CNAME they give you for any records that point to them, including the apex domain record.

Do not use A or AAAA records otherwise the request will go direct to GHL’s Cloudflare account and not pass through yours, so your rule won’t take effect.

1 Like

I have tried organizing A record With CNAME record by many way but fails.
Can you please guide me to set that new CNAME record after delete the current A record?

Thank you

Can you show a screenshot of your Cloudflare DNS records?

Delete the A record at the top.

Then create a proxied CNAME for @ pointing to sites.ludicrous.cloud.

1 Like

That works perfectly!
Thanks a lot, @sjr . You’ve made my day!

1 Like

This topic was automatically closed 2 days after the last reply. New replies are no longer allowed.