Cloudflare's Under Attack mode performs additional security checks to help mitigate layer 7 DDoS attacks. Validated users access your website and suspicious traffic is blocked. It is designed to be used as one of the last resorts when a zone is under attack (and will temporarily pause access to your site and impact your site analytics).
When enabled, visitors receive an interstitial page.
Turn on Under Attack modeUnder Attack mode is turned off by default for your zone.
To put your entire zone in Under Attack mode:
To enable Under Attack mode for specific pages or sections of your site, use a configuration rule to adjust the Security Level.
When incoming requests match
/admin
If you are using the Expression Editor, enter the following expression:(starts_with(http.request.uri.path, "/admin"))
Then the settings are
To turn it on for specific ASNs (hosts/ISPs that own IP addresses), countries, or IP ranges, use IP Access Rules.
Preview Under Attack modeTo preview what Under Attack mode looks like for your visitors:
The Checking your browser before accessing...
challenge determines whether to block or allow a visitor within five seconds. After passing the challenge, the visitor does not observe another challenge until the duration configured in Challenge Passage.
Since the Under Attack mode requires your browser to support JavaScript to display and pass the interstitial page, it is expected to observe impact on third party analytics tools.
RetroSearch is an open source project built by @garambo | Open a GitHub Issue
Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo
HTML:
3.2
| Encoding:
UTF-8
| Version:
0.7.4