Re: CloudFlare + firewall-drop

121 views
Skip to first unread message
Message has been deleted

Jesus Linares

unread,
Mar 2, 2023, 12:26:19 PM3/2/23
to Wazuh mailing list
Hi,

The firewall-drop active response is a local command in your agent. For example, Linux will use iptables. So, it should be enough to protect your agent. That said, if you want to block the IP in Cloudflare too, you will need to create your own script using the Cloudflare API. Here you can find more information: https://documentation.wazuh.com/current/user-manual/capabilities/active-response/custom-active-response.html.

I hope it helps.


On Thursday, March 2, 2023 at 1:22:30 PM UTC+1 val...@cingerr.com wrote:
Hi

Since I've configured firewall-drop currently but one of my Agents is protected with cloudflare-waf in Layer7 and there are ways that if someone , gets blocked with firewall-drop they still can access the website, is there a way i could also ban it automatically in cloudflare also?


Thanks.

Reply all
Reply to author
Forward
0 new messages