Web Application Firewall (WAF)¶
All site traffic is proxied through Cloudflare, which provides a Web Application Firewall that analyses every incoming request. Unless a request is explicitly whitelisted, Cloudflare applies bot protection, browser integrity checks, and other filters to block spam, DDoS attacks, and other malicious activity.
Info
As of October 5, 2023, all sites have their traffic proxied through Cloudflare.
Universal rules¶
These rules are active on all sites and are managed in the Cloudflare control panel at the domain level.
Whitelist: VPN / office IP¶
All requests originating from the office or VPN IP are automatically whitelisted.
Whitelist: API endpoints¶
The following paths bypass WAF filtering to ensure internal services function correctly:
| Condition | Value |
|---|---|
| Path | /wp-json/ |
| Path | /wc-api/ |
| Query string contains | wc-api= |
| Path | /wp/wp-admin/admin-ajax.php |
| Path | /wp/wp-cron.php |
| AS Number | 24940 (Hetzner) |
| AS Number | 24940 (Amazon) |
Site-specific rules¶
Barberklingen.nl¶
| Rule | Details |
|---|---|
| Managed challenge | Applied to all countries except DK and NL |
Implemented on September 30, 2023 to address excessive spam orders originating from outside the target markets.