3 ms·
This was not about DDoS defense but the Bot Management feature, which is a paid Enterprise-only feature not enabled by default to block automated requests regar
by matteocontrini 11mo ago
This was not about DDoS defense but the Bot Management feature, which is a paid Enterprise-only feature not enabled by default to block automated requests regardless of whether an attack is going on.
https://developers.cloudflare.com/bots/get-started/bot-management/ https://developers.cloudflare.com/bots/get-started/bot-manag...
- inemesitaffia 11mo agoSo if you didn't enable it your stuff would work?
- matteocontrini 11mo agoIt would still fail if you were unluckily on the new proxy (it's not very clear why if the feature was not enabled, indeed): > Unrelated to this incident, we were and are currently migrating our customer traffic to a new version of our proxy service, internally known as FL2. Both versions were affected by the issue, although the impact observed was different. > Customers deployed on the new FL2 proxy engine, observed HTTP 5xx errors. Customers on our old proxy engine, known as FL, did not see errors, but bot scores were not generated correctly, resulting in all traffic receiving a bot score of zero. Customers that had rules deployed to block bots would have seen large numbers of false positives. Customers who were not using our bot score in their rules did not see any impact.
- nijave 11mo agoBots can also cause a DoS/DDoS. We use the feature to restrict certain AI scraper tools by user agent that adversly impact performance (they have a tendency to hammer "export all the data" endpoints much more than regular users do)