Skip to content

Commit 4de4979

Browse files
Update content for zone-lockdown following WAF team feedback
1 parent 7d8f757 commit 4de4979

File tree

1 file changed

+1
-3
lines changed

1 file changed

+1
-3
lines changed

src/content/partials/smart-shield/zone-lockdown.mdx

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -4,9 +4,7 @@
44

55
Currently, any Cloudflare customer on a paid plan can configure Health Checks against any host or IP. [Zone Lockdown](/waf/tools/zone-lockdown/) specifies a list of one or more IP addresses, CIDR ranges, or networks that are the only IPs allowed to access a domain, subdomain, or URL. It allows multiple destinations in a single rule as well as IPv4 and IPv6 addresses. IP addresses not specified in the Zone Lockdown rule are denied access to the specified resources.
66

7-
When a customer enables zone lockdown, any Health Checks targeting that zone regardless of ownership will still get through because Cloudflare's ASN is on an allow-list.
8-
9-
Cloudflare's ASN is on an allow-list. This allows health checks to bypass zone lockdown. However, this creates a vulnerability and that behavior will change, resulting in Health Checks no longer being allowed through zone lockdown by default. Customers who use zone lockdown and want their health checks to continue passing can follow the guide below to bypass zone lockdown.
7+
Customers who use zone lockdown and want their health checks to continue passing can follow the guide below to bypass zone lockdown.
108

119
## Bypass zone lockdown
1210

0 commit comments

Comments
 (0)