Ah, Cloudflare. You claim to be security focused and help customers block threats to their sites, including unwanted bots. So, when are you going to clean your own house?
This week, like last week, the single largest source of traffic captured by my firewall was, again, AS13335 – Cloudflare WARP. The firewall blocked nearly 4x the amount of hits when compared to the next closest ASN; and that was from just one of their ASNs.
When the data is sorted by the number of unique IPs hitting the server, Cloudflare comes first and second, with AS14789 contributing a smaller number of hits.


You can see the scope of the unwanted traffic from Cloudflare WARP even more clearly when it is charted.

Since the last update, I have had to add a large number of Cloudflare CIDR blocks to my penalty_box list that is before the shield_hyperscaler rules in my firewall rules. The Penalty Box is a complete drop rule, with a time limit. Unfortunately, pretty much all the CIDR blocks in the penalty_box qualify for permanent blocks, and I will likely move them their in the near future.
You can see when I migrated the Cloudflare CIDR Blocks to the penalty_box ruleset in these time charts — the red items are shield_hyperscaler while the purple is penalty_box (I apologize to my brethren who have red/green color blindness).


I will continue to watch this over the next few weeks; if Cloudflare WARP continues to be this aggressive, they will end up in the permanent block ruleset.
Leave a Reply