Cloudflare Docs
DDoS Protection
Visit DDoS Protection on GitHub
Set theme to dark (⇧+D)

Rule categories

Rules in the Network-layer DDoS Attack Protection managed ruleset belong to the following categories (also known as tags):

NameDescription
greRules for DDoS attacks over Generic Routing Encapsulation (GRE) that usually target GRE endpoints.
espRules for DDoS attacks related to the Encapsulating Security Payload (ESP) protocol, which is part of the IPSec secure network protocol suite.
advancedRules related to features available to Enterprise customers, such as Adaptive DDoS Protection.
genericRules for detecting and mitigating floods of packets. These rules are useful for mitigating attacks that have no known signatures, but they may also trigger on unusually high volumes of legitimate traffic. To reduce the risk of false positives, their packet per second (pps) activation threshold is higher. These rules rate-limit traffic by default, but you can override them to block traffic if necessary.
read-onlyHighly targeted rules for mitigating DDoS attacks with a high confidence rate. These rules are read-only — you cannot override their sensitivity level or action.