When "Under Attack Mode" is enabled on Cloudflare, it breaks my site

What is the name of the domain?

What is the issue you’re encountering

When I enable the “Under Attack Mode” on Cloudflare, it breaks my site.

What steps have you taken to resolve the issue?

I have to refresh the page about 3 times for the site to load correctly.

What are the steps to reproduce the issue?

Go to transportforum.com if I still have the “under attack mode” enabled. I can’t keep it on for long because it breaks my site.

Are you actually under attack? UAM is a blunt tool that can have side effects so should only be used to give breathing room while responding to attack, follow this guide if you are under attack.

Use of high security mode, Bot Fight Mode (Super Bot Fight Mode on paid plans is better) and more targetted challenges are better ways of blocking the more regular bot traffic.

As it’s not doing it now, what are you having to refresh to get to your site? If it is the Cloudflare challenge page then check for browser plugins that may be interfering with the challenge.

1 Like

I don’t think I’m actually under attack but I keep getting “503 Service Unavailable” errors frequently from my hosting company because of exceeding resource limits which I believe is due to some kinds of bots crawling my site (not real users). My “Bot Fight Mode” and “Block AI Bots” settings are enabled but they don’t seem to help. The “AI Labyrinth” is disabled because it also seems to cause my site to break often. The “High Security Mode” as you suggested used to help but it’s no longer available, the “Security Level” setting can no longer be set manually, it’s now automated, see this link about that:

Are you restoring vistor IPs? Have you configured your origin to not block Cloudflare IPs?

My website is just a phpBB forum and it doesn’t depend on the incoming IP address of the original visitor (even for logged in users but most of them aren’t) so the article “Restoring original visitor IPs” doesn’t seem relevant

If your host is throttling your site because it doesn’t understand that you have a reverse proxy in front of it, it could be relevant.