4 ms·
Adding to what has already been said- New registrations are the food for probing. You could have an IP on someone's naughty list from a previous user. It's any
by cameron_b 3y ago
Adding to what has already been said-
New registrations are the food for probing.
You could have an IP on someone's naughty list from a previous user.
It's any other day on the internet.
That's just what the neighborhood ( the whole internet ) looks like from the sidewalk.
So,
Set up a free Cloudflare account, move your DNS of record to them, and run traffic through Cloudflare to your server.
- gustavus 3y agoPlease don't do this, find another way. Almost 1/2 the internet is inaccessible to me at this point because at some point CF decided that I was a bad actor and now I can't get to anything.
- Erratic6576 3y agoHave you tried changing the web browser or VPN?
- throwaway67743 3y agoEnabled cookies? Checked your TCP/IP settings?
- hedora 3y agoI used to have similar problems (and also hell bans at random web sites) because I had a small ISP that uses CGNAT. Somewhere in my zip code, there was probably an infected windows box or something. You might check your IP in an IP reputation database. I eventually switched to a larger, more soulless ISP (also CGNAT) because we can’t have nice things on the internet any more.
- deleted 3y ago[deleted]
- diggan 3y ago> So, Set up a free Cloudflare account, move your DNS of record to them, and run traffic through Cloudflare to your server. Since the author is not actually experiencing any issues, they're just curious, there really isn't any need for this.
- joeyrobert 3y agoI recommend this method for self-hosting too. I have gigabit Internet and cloudflare proxying unlocks the ability to host locally without exposing my home IP. Plus all the advantages of DDoS mitigation.
- codegeek 3y agoCloudflare won't protect your IP being hit directly. If your IP can be accessed publicly, it will get hit. period. You could use nginx etc to do a 444 status code but can't stop these scripts/bots from hitting ur IP completely.
- solardev 3y agoNormally you'd just configure the firewall to drop all packets not from Cloudflare. Maybe also get a new static IP first.
- dizhn 3y agoIs there a different set of IPs for Warp? That would have to be denied too.
- lormayna 3y agoYes and no. If you have an iptables rule that drop anything not coming from CF IPs, the attacking packets are not passed to the application and dropped in kernel mode. Otherwise the packet will be passed to user mode application that consume more resources to analyse and drop the connection.
- deleted 3y ago[deleted]
- kkielhofner 3y agoCloudflare tunnels: https://www.cloudflare.com/products/tunnel/ https://www.cloudflare.com/products/tunnel/ I haven’t had anything exposed to the Internet in a long while.
- piperswe 3y agoIf you set up Cloudflare Tunnel, you don't even need to be set up to accept any incoming connections. With Access, you can even run SSH through that tunnel. You can then setup your firewall to drop any incoming packets for non-established connections, closing a significant hole for DoS attacks and such.
- ozim 3y agoPro Tip - if you can get cheap IPv6 host cloudflare proxy will work for you as well for IPv4 as they will handle it. You setup only AAAA record and you are reachable from IPv4 as well as much as other cloudflare caching benefits that you get.
- taskforcegemini 3y agothat is terrible advice for the internet as a whole. cloudflare is too ubiquitous already which comes with a lot of potential danger. In other words: if you can afford not to use cloudflare, please don't.