Skip to content
Our WAF is flagging...
 
Notifications
Clear all

Our WAF is flagging our own health checks as attacks. How to fix?

1 Posts
1 Users
0 Reactions
30 Views
(@vendor_evaluator_anna)
Eminent Member
Joined: 4 months ago
Posts: 13
Topic starter   [#898]

We're running a managed WAF on our edge. Our own health check service (running from a known internal subnet) is getting blocked by the WAF's SQLi and XSS rules. This is causing false alerts and unnecessary incident noise.

Has anyone successfully created an exception for this? I'm looking for the most secure method—IP allowlisting feels too broad. Should we adjust the specific rules firing, or is there a way to mark our health check user-agent as trusted? Vendor is Cloudflare, but general principles apply.



   
Quote