Impact of Cloudflare's “Under Attack” mode on website usability

EchoWave

Newbie
Joined
Sep 10, 2024
Messages
9
Reaction score
1
Yesterday, a client's server experienced increased load due to a targeted attack, with requests coming from a large number of different IP addresses. For additional protection, Cloudflare was connected, proxying was configured, and after enabling “I'm under attack” mode, the malicious traffic disappeared and the server is now running smoothly.

However, as a result, a captcha appeared on the site for visitors, and the client was dissatisfied with this innovation. We are interested in the experience of others: have you encountered a similar situation on your clients' sites or your own resources? How did visitors react to the captcha, and what approaches help to ensure a balance between security and comfort when using the site?
 
This is standard for DDoS protection. You need to explain to your client that there isn't a better method to block those attacks, and that not paying thousands of dollars monthly for different protections is not advisable.
In my case, the under attack mode is activated via API when the RPS exceeds the standard threshold, and deactivated when it stops. This is the best practice for such cases, and also automatic.
 
Yesterday, a client's server experienced increased load due to a targeted attack, with requests coming from a large number of different IP addresses. For additional protection, Cloudflare was connected, proxying was configured, and after enabling “I'm under attack” mode, the malicious traffic disappeared and the server is now running smoothly.

However, as a result, a captcha appeared on the site for visitors, and the client was dissatisfied with this innovation. We are interested in the experience of others: have you encountered a similar situation on your clients' sites or your own resources? How did visitors react to the captcha, and what approaches help to ensure a balance between security and comfort when using the site?
Use DDoS-Guard.net or Stormwall even them are a little better than CF. Of course CF have more power, resources to block, but you only will stop these attacks with paid plans and is not cheap. CF is focused in many things, they don't focus anymore in their DDoS Protection like when they started.

Then move your hosting to one hosting that have a great ddos protection. The best solution is to use your own DDoS Solution + Good provider

I can recommend
https://ginernet.com/en/
OVH (with Anti-DDoS Pro)
 
Back
Top