Browsing is absolutely intolerable these days, with almost every website having a block screen, "we're checking your browser...", stuff like that. Lately I just close these websites immediately.
It depends on what you define as unwanted traffic.
Personally I do not have an issue with bots as long as they behave and are not straight up malicious, so I rely on a combination of rate limiting, a fine-tuned OWASP CRS ruleset and an aggressive Fail2ban enforcement (hit 2 triggers and you get a 24 hour ban, 2 bans and you get banned for 30 days).
My sites also make extensive use of static elements and caching.
How do you deal with DDoS attacks on your infra / sites? Especially ones from residential proxies or vpn networks? These are the hardest to defend against as they often are relentless and no amount of proof-of-work, captchas or otherwise seems to stop them from coming. I don't think it's something you can easily block at any firewall level, the sheer volume of IP(s) and Subnets is too much.
Browsing is absolutely intolerable these days, with almost every website having a block screen, "we're checking your browser...", stuff like that. Lately I just close these websites immediately.
Cloudflare: "We reduced bot traffic by 80%"
Me: "Bro you reduced all traffic by 90%, my customers are pissed"
It depends on what you define as unwanted traffic.
Personally I do not have an issue with bots as long as they behave and are not straight up malicious, so I rely on a combination of rate limiting, a fine-tuned OWASP CRS ruleset and an aggressive Fail2ban enforcement (hit 2 triggers and you get a 24 hour ban, 2 bans and you get banned for 30 days).
My sites also make extensive use of static elements and caching.
How do you deal with DDoS attacks on your infra / sites? Especially ones from residential proxies or vpn networks? These are the hardest to defend against as they often are relentless and no amount of proof-of-work, captchas or otherwise seems to stop them from coming. I don't think it's something you can easily block at any firewall level, the sheer volume of IP(s) and Subnets is too much.