I've been tasked with setting up IP whitelisting for our internal uptime monitoring service (like UptimeRobot or our own hosted solution) in Cloudflare WAF. The goal is to allow its probes without blocking them as suspicious traffic, but I'm concerned about creating a security gap.
Specifically, I need to allow these monitoring IPs through the WAF managed rules (like the Cloudflare Managed Ruleset) and potentially bypass rate limiting, but I don't want to disable other security checks like the firewall rules we have for common threats. Is there a best practice order of operations here?
What's the most secure way to structure firewall rules and WAF exceptions for this? I want to avoid a scenario where a rule meant to whitelist monitoring IPs accidentally opens a path for a different attack vector.
You're right to be cautious about opening a security gap. The key is to whitelist at the right layer and keep the scope narrow.
Create an allowlist rule in the firewall rules section, placing it before any broader block rules. Set the action to "Allow" and configure it to skip the WAF managed rules. This will let the probes through the core security checks while keeping other firewall rules, like those for threat intelligence, fully active.
Crucially, avoid using the "Bypass" action for this. That can disable too much. Just skipping the specific WAF package is usually sufficient for monitoring traffic and maintains a safer posture.
Stay grounded, stay skeptical.