Cloudflare WAF and managed challenges

Create a narrowly scoped Cloudflare skip rule when a Web Application Firewall (WAF), rate-limit, Super Bot Fight Mode, or managed challenge blocks FormTester 365.

Before creating the rule

Turn off the FormTester 365 proxy for this website so Cloudflare can see the fixed testing addresses:

  • IPv4: 45.56.67.77
  • IPv6: 2600:3c00::f03c:92ff:fef9:6b3b

Open the website in FormTester 365, open its settings, and under Proxy settings enable the override and set the proxy to off.

Create a Cloudflare skip rule

  1. Sign in to the Cloudflare dashboard and select the site.
  2. Go to Security → Security rules.
  3. Select Create rule → Custom rules.
  4. Give the rule a recognizable name, such as FormTester 365.
  5. Match IP Source Address against either FormTester 365 address.
  6. Add the form page or submission path to the expression when possible.
  7. Choose Skip as the action.
  8. Select only the products causing the block, such as managed rules, rate limiting, or Super Bot Fight Mode.
  9. Deploy the rule and run a manual test in FormTester 365.

Cloudflare does not allow skip rules to bypass every product on every plan. Bot Fight Mode on the Free plan cannot be skipped with this action.

An embedded Cloudflare Turnstile widget is separate from a WAF challenge. If the page contains a Turnstile widget, follow the Cloudflare Turnstile guide.

See Cloudflare's skip-rule documentation for the current rule options.

Was this helpful?