jazz1611 @aaPanel_Kern hello, we need block/prevent http flood like this in nginx free firewall GET /?s=dFBrl1hnoZ8wAsdFBrl1hnoZ8wAsdFBrl1hnoZ8wAsdFBrl1hnoZ8wAs GET /?oCBKzTeJOcV7ilkIE8UNd9fjWnrYvF6gmQbuP0pqsZHGMRoCBKzTeJOcV7ilkIE8UNd9fjWnrYvF6gmQbuP0pqsZHGMRoCBKzTeJOcV7ilkIE8UNd9fjWnrYvF6gmQbuP0pqsZHGMRoCBKzTeJOcV7ilkIE8UNd9fjWnrYvF6gmQbuP0pqsZHGMR GET /?lKAY0UpCZGz2dvNx4VyhkHTBjQ8PLcIJlKAY0UpCZGz2dvNx4VyhkHTBjQ8PLcIJlKAY0UpCZGz2dvNx4VyhkHTBjQ8PLcIJlKAY0UpCZGz2dvNx4VyhkHTBjQ8PLcIJ GET /wp-includes/js/jquery/jquery.min.js?ver=3kmWUJg0vRsCGqetBo7r4PcOzbn52pa8wiYN3kmWUJg0vRsCGqetBo7r4PcOzbn52pa8wiYN3kmWUJg0vRsCGqetBo7r4PcOzbn52pa8wiYN3kmWUJg0vRsCGqetBo7r4PcOzbn52pa8wiYN
aaPanel_Kern aaP_Bekti It is recommended to enable the cdn option. Otherwise, the ip of cloudflare will be banned by mistake
aaP_vini @aaPanel_Jose @aaPanel_Captain @aapanel_sniper How much better is this WAF than the free version? Is it comparable to WAF Cloudflare?
aaP_vini @aaPanel_Jose @aaPanel_Captain @aapanel_sniper How much better is this WAF than the free version? Is it comparable to WAF Cloudflare?
idflorin aaP_vini You really can't compare WAF with WAF Cloudflare WAF works at the server level WAF Cloudflare works at the DNS level. You can use both at the same time but it's not really recommended to do so, in my opinion.
aaP_vini idflorin @aaPanel_Jose @aaPanel_Captain @aapanel_sniper Does the level of protection of the aaPanel WAF eliminate the need to hire the Cloudflare WAF, then?Does the level of protection of the aaPanel WAF eliminate the need to hire the Cloudflare WAF, then?
aaP_taufik_y2t Why Nginx WAF pro version (paid version) not running realtime? Is will not work with 2 WAF run in same time? (pro and free), because free version is running well image for free version image for pro (paid) version
idflorin aaP_mdestafadilah_simrs it's too big the https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker/blob/master/robots.txt/robots.txt It's too long for my taste. My current UA filter looks like this: (HTTrack|Apache-HttpClient|harvest|dirbuster|pangolin|nmap|sqln|hydra|Parser|libwww|BBBike|sqlmap|w3af|owasp|Nikto|fimap|havij|zmeu|BabyKrokodil|netsparker|httperf|BLEXBot|barkrowler|MJ12Bot|Nutch|MBCrawler|MegaIndex|GrapeshotCrawler|CriteoBot|admantx|newspaper|CF-UC|comscore|Zoominfobot|SeznamBot|DataForSeoBot|Seekport|Java|HonoluluBot|Go-http-client|python-requests|Bytedance|Bytespider|Awario|spinner|tiny|thesis|ImagesiftBot|FriendlyCrawler|Amazonbot| SF/)
aaP_mdestafadilah_simrs idflorin thanks, btw so your filter it's enough? i try to install ultimate bad bot blocker, unsuccessfully, my nginx server not restart, rollback again and use your trick with custom UA Filter.