4 ms·
And if you have to disable WAF, what exactly is Cloudflare doing for you?
by a2tech 4y ago
And if you have to disable WAF, what exactly is Cloudflare doing for you?
- mpalfrey 4y agoWould it still do DDOS even without the WAF?
- mstrem 4y agoOur DDoS mitigation is separate yes and will still work.
- danielheath 4y agoEdge Cache with unmetered egress?
- perfecto_maduro 4y agounmetered up to a point, but yeah. Also network-level DDoS protection
- tills13 4y agoIf you are reaching the point where they are sending you emails asking about what you are doing, you should be paying for it.
- perfecto_maduro 4y agoyeah, but sadly there aren’t many CDNs that offer WAF, even the most basic one. I literally begged bunnyCDN to build one so we can switch from CF. It’s on their roadmap for like forever.
- Tijdreiziger 4y agoIn the article, the author disables the WAF only for Stripe outbound IPs, which can be presumed to be safe (unless Stripe's machines/IP space gets hacked). The WAF still works for traffic from all other IPs
- r1ch 4y agoEven with the WAF disabled (at least as much as I can disable it without the Enterprise plan, i.e. "Essentially Off"), I've found it will still block legitimate requests. Tainted CGNAT or dynamic IPs are my guess. The WAF doesn't really matter for my use case as the route is handled by a CF worker, in fact I'd prefer it doesn't get in the way.