WAF rule for blocking IP

What is the name of the domain?

clubnzb.com

What is the issue you’re encountering

What is the correct WAF rule to block IP adresses who is “visiting” our website 35+ times / sec?

What steps have you taken to resolve the issue?

Blocking the requested IP adress manual

May I ask if the IP address is always the same or it changes?, furthermore is the path of the visit the same or changes as well?

If you’re using a Pro plan, I’d suggest using Rate Limiting rule would help in such case:

Otherwise, IP Access Rules:

1 Like

The IP changes when I blocked it.
Always VPN (HidemyIP)
The “rule” must me 20x/sec knocking with the IP is block / add firewall

AND no pro plan, only free plan

You can create a single rate limiting rule on the free plan too:

Whre is this setting?
Under: Rate limiting rules
I got also Field - Oparator and Value

Click edit expression and type “true” to match all requests.