Cloudflare exception #785
-
ProblemYour domains are proxied through Cloudflare (orange cloud toggle) and you see one or more of your sites as "Down" in the repo README summary. DetailsIf "Bot Fight Mode" is ON, you will get a You can verify your setting state from the Cloudflare Dashboard:
It wouldn't make sense to turn this setting OFF and reduce your site security. The actions in this repo use a bot to complete the checks of your sites. This bot is named "Koj Bot." SolutionYou can whitelist the Microsoft ASN from which this bot originates from. This is the only method I have found to work. Using a custom WAF Rule to allow this bot by ASN and User Agent does not work. From the Cloudflare Dashboard:
CommentsI spent about an hour trying various WAF Rules so I wouldn't have to whitelist the ASN. But it just wasn't possible. Cloudflare detects the bot behavior and just stops it. Related issue #343 |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 4 replies
-
I don't understand why excluding Microsoft ASN would be the problem? |
Beta Was this translation helpful? Give feedback.
-
looks like this doesnt work anymore you need to disable it or just not use this, the rules don't affect bot fighting anymore. |
Beta Was this translation helpful? Give feedback.
It does. Because I still have it enabled and it works for me. Cloudflare even tells you the order of protection on the right. The ASN source comes before Bots. Thus it gets passed right along. Your rules always come before Cloudflare's rules. If the IP/ASN is allowed, it will be allowed regardless of bot or human traffic.