Notifications
Clear all
Topic starter
14/07/2026 7:20 pm
We're running a managed WAF on our edge. Our own health check service (running from a known internal subnet) is getting blocked by the WAF's SQLi and XSS rules. This is causing false alerts and unnecessary incident noise.
Has anyone successfully created an exception for this? I'm looking for the most secure method—IP allowlisting feels too broad. Should we adjust the specific rules firing, or is there a way to mark our health check user-agent as trusted? Vendor is Cloudflare, but general principles apply.