3 ms·
Cloudflare will only block inbound traffic in two situations: - if the request contains an exploit (the Cloudflare WAF) - if the website owner created a rule t
by freitasm 5y ago
Cloudflare will only block inbound traffic in two situations:
- if the request contains an exploit (the Cloudflare WAF)
- if the website owner created a rule to block a request
Most of the "this website uses Cloudflare to protect..." is a consequence of the second one.
To make things easier Cloudflare has a switch to automate the second one - basically it just looks at IP threat levels based on honeypot services all around. Visitors receive a "level" based on IP, region, browser version, etc and if the level is above the switch (Low, High, Medium) then it's blocked.
People go for this option - set the switch to High and block almosty everything. Other people will set it to Low or Off and then create their own firewall rules - for example a website owner can create a complex set of rules (in addition to the Cloudflare WAF exploit, or replacing it). See https://community.cloudflare.com/t/the-firewall-rules-we-follow/308849 https://community.cloudflare.com/t/the-firewall-rules-we-fol... for an example.
People will see the page sayng "Cloudflare blocked you" when in fact was most likely the website owner.