Cloudflare Under Attack Mode: What It Is and When to Use It
Cloudflare Under Attack Mode: Apa Itu dan Kapan Harus Dipakai?
Pernah nggak sih website lo tiba-tiba lelet banget, atau malah error nggak bisa diakses? Terus lo cek log, dan ternyata ada traffic aneh yang datang bertubi-tubi. Kayak ada yang sengaja nyerang gitu.
Nah, kalau lo pake Cloudflare, ada satu fitur yang bisa lo aktifin buat ngatasin situasi kayak gini: Under Attack Mode.
Gw bakal bahas tuntas soal fitur ini—mulai dari apa itu, cara kerjanya, kapan harus dipake, sampe gimana penerapannya kalo lo punya website pake XAMPP dan Cloudflare Tunnel. Oke, langsung aja.
Apa Itu Cloudflare Under Attack Mode?
Jadi gini, Under Attack Mode (UAM) adalah fitur keamanan tambahan dari Cloudflare yang dirancang khusus buat nge-handle website yang lagi diserang, terutama serangan DDoS Layer 7 atau yang biasa disebut HTTP flood.
Mungkin lo pernah denger istilah DDoS. Intinya, si penyerang ngirim request ke website lo dalam jumlah besar banget, sampe server-nya kewalahan dan akhirnya down. Nah, Layer 7 ini artinya serangan terjadi di level aplikasi—jadi request-nya kelihatan kayak request normal dari browser, tapi sebenarnya bot.
Nah, UAM ini tugasnya menyaring traffic. Pas diaktifin, Cloudflare bakal ngecek setiap pengunjung dulu sebelum requestnya diteruskan ke server lo.
Gimana Cara Kerja Under Attack Mode?
Mungkin lo penasaran, "Terus bedanya sama yang biasa gimana?"
Oke, begini:
- Kondisi Normal: Pengunjung datang, langsung tembus Cloudflare, langsung ke server website lo. Cepet, nggak ada halangan.
- Under Attack Mode Aktif: Sebelum sampe ke server, pengunjung bakal diminta ngelewatin Browser Security Check atau Managed Challenge. Biasanya ini cuma beberapa detik, dan browser normal bakal ngelewatin secara otomatis.
Challenge-nya bisa berupa:
- Pemeriksaan JavaScript
- Cookie
- Kadang human verification kayak captcha
Nah, ini bedanya: bot atau script biasa nggak akan bisa ngelewatin challenge ini karena mereka nggak punya kemampuan buat ngejalanin JavaScript atau nyimpen cookie seperti browser normal.
Jadi, intinya: UAM ini kayak "pintu gerbang tambahan" yang nge-filter siapa aja yang boleh masuk ke server lo. Yang legit lewat, yang mencurigakan ditahan.
Dampaknya ke Pengguna dan Layanan
Fitur ini emang keren, tapi lo juga harus sadar konsekuensinya:
- Sedikit tambahan waktu akses: Karena ada challenge, pengunjung bakal nunggu beberapa detik tambahan. Nggak lama sih, tapi bisa terasa.
- Potensi masalah buat client non-browser: API, webhook, bot, atau script automation bakal kena masalah karena mereka nggak bisa ngelewatin challenge. Jadi kalau website lo ada service yang pake API, ini bisa bermasalah.
- Analitik mungkin kepengaruh: Karena sebagian traffic difilter dulu, ada kemungkinan data di Google Analytics atau tool lainnya jadi nggak akurat.
Tapi tenang, fitur ini bukan buat dipake sehari-hari kok. Ini lebih kayak "tombol darurat" buat situasi genting.
Kapan Harus Mengaktifkan Under Attack Mode?
Jawabannya simpel: pas website lo lagi diserang.
Tapi biar lebih jelas, ini kondisi-kondisi yang menurut gw ideal buat aktifin UAM:
- Server mulai berat atau down karena traffic abnormal.
- Log server nunjukin pola request yang mencurigakan—misalnya banyak request dari IP yang sama, atau user agent aneh.
- Pola serangan Layer 7/HTTP flood terdeteksi.
Yang perlu diingat: Under Attack Mode BUKAN fitur yang harus selalu nyala. Kalau lo aktifin terus-terusan, pengalaman pengunjung bisa terganggu, dan client non-browser lo bisa error.
Untuk perlindungan sehari-hari, lebih baik pake kombinasi fitur Cloudflare lain kayak DDoS Protection, WAF (Web Application Firewall), Rate Limiting, dan aturan keamanan lainnya. Itu udah cukup buat jaga website di kondisi normal.
Penerapan Secara Selektif (Nggak Seluruh Website)
Salah satu hal keren dari Cloudflare adalah lo bisa menerapkan UAM secara spesifik, bukan ke seluruh website.
Misalnya lo punya website e-commerce. Bagian homepage dan product page mungkin nggak perlu UAM, tapi lo bisa aktifin di:
- Halaman login
- Halaman admin
- Endpoint tertentu kayak /checkout atau /payment
- Atau berdasarkan IP, negara, ASN, atau karakteristik traffic tertentu
Dengan cara ini, lo bisa ngasih perlindungan ekstra di area yang paling sensitif, tanpa mengorbankan performa seluruh website.
Cloudflare nyebut ini dengan istilah Managed Challenge di aturan WAF. Jadi lo bisa bikin aturan khusus yang isinya: "Kalau request ke path ini, jalankan challenge." Keren kan?
Kaitan dengan XAMPP + Cloudflare Tunnel
Nah, ini penting buat yang punya website lokal pakai XAMPP/Apache dan dihubungkan ke internet lewat Cloudflare Tunnel.
Di arsitektur ini, Cloudflare Tunnel bertugas buat nyambungin server lokal lo ke Cloudflare, dan Cloudflare ada di depan sebagai gateway. Jadi semua request dari internet bakal lewat Cloudflare dulu, baru diterusin ke Apache/PHP/MySQL di lokal.
Nah, di sini UAM bisa jadi lapisan pertahanan tambahan yang sangat berguna. Kenapa? Karena UAM difilter di Cloudflare, sebelum request sampe ke server lokal lo. Jadi kalau ada serangan besar, Apache lo nggak bakal kewalahan—karena Cloudflare udah nge-filter duluan.
Tapi tetap ingat: UAM bukan pengganti keamanan server origin. Lo tetep harus jaga keamanan XAMPP/Apache lo sendiri. Jangan sampe server origin lo bobol cuma karena lo terlalu percaya sama Cloudflare.
Gw saranin:
- Pastikan Apache/PHP lo di-update
- Gak boleh ada akses langsung ke server lokal dari internet selain lewat Cloudflare Tunnel
- Konfigurasi .htaccess atau firewall di lokal tetep penting
Kesimpulan
Jadi, inti dari semua ini: Cloudflare Under Attack Mode adalah alat pertahanan darurat buat website yang lagi diserang, terutama serangan DDoS Layer 7. Fungsinya nyaring traffic sebelum sampe ke server, tapi ada konsekuensi ke pengalaman pengguna dan layanan non-browser.
- Jangan aktifin terus-terusan—ini bukan fitur harian.
- Gunakan WAF, Rate Limiting, dan DDoS Protection sebagai pertahanan sehari-hari.
- Terapkan secara selektif ke area sensitif kaya login/admin.
- Kalau pake XAMPP + Cloudflare Tunnel, UAM bisa sangat membantu buat ngurangin beban server lokal pas serangan.
Semoga penjelasan ini membantu lo yang lagi bingung soal UAM. Kalo ada pertanyaan atau pengalaman serangan yang menarik, boleh sharing di kolom komentar ya. Gw usahain jawab sebisanya.
FAQ — Pertanyaan Seputar Cloudflare Under Attack Mode
Apakah Under Attack Mode sama dengan Cloudflare WAF?
Tidak. Under Attack Mode adalah fitur terpisah yang berfungsi sebagai challenge berbasis browser untuk menyaring traffic selama serangan. WAF (Web Application Firewall) adalah fitur yang lebih luas untuk memfilter traffic berdasarkan aturan keamanan tertentu secara terus-menerus.
Apakah Under Attack Mode bisa digunakan untuk melindungi API?
Kurang disarankan. API dan client non-browser biasanya tidak bisa melewati challenge JavaScript yang diberikan UAM. Untuk API, sebaiknya gunakan Rate Limiting, API Shield, atau aturan WAF yang lebih spesifik.
Berapa lama sebaiknya Under Attack Mode diaktifkan?
Hanya selama serangan berlangsung. Setelah traffic kembali normal, segera nonaktifkan agar tidak mengganggu pengalaman pengguna dan layanan non-browser.
Apakah Under Attack Mode bisa dikombinasikan dengan Cloudflare Tunnel?
Bisa. Dalam arsitektur XAMPP + Cloudflare Tunnel, UAM menjadi lapisan perlindungan tambahan sebelum request diteruskan ke server origin, sehingga mengurangi beban server lokal saat terjadi serangan.
Bagaimana cara mengaktifkan Under Attack Mode di Cloudflare?
Masuk ke dashboard Cloudflare, pilih website Anda, buka menu Security > Settings, lalu cari opsi "Under Attack Mode" dan aktifkan. Anda juga bisa menggunakan WAF rules dengan Managed Challenge untuk penerapan yang lebih selektif.
Cloudflare Under Attack Mode: What It Is and When to Use It
Ever had your website suddenly slow down to a crawl, or even become completely inaccessible? You check your server logs and notice a flood of suspicious traffic. Feels like someone's deliberately attacking you, right?
If you're using Cloudflare, there's one feature you can enable to handle exactly this situation: Under Attack Mode.
I'll walk you through everything about this feature—what it is, how it works, when to use it, and how to implement it if you're running a website with XAMPP and Cloudflare Tunnel. Let's dive right in.
What Is Cloudflare Under Attack Mode?
So here's the deal: Under Attack Mode (UAM) is an additional security feature from Cloudflare designed specifically to handle websites that are under attack, particularly Layer 7 DDoS attacks—also known as HTTP floods.
You've probably heard of DDoS attacks. Basically, the attacker sends a massive number of requests to your website, overwhelming the server and taking it offline. Layer 7 means the attack happens at the application level, so the requests look like normal browser traffic, but they're actually bots.
UAM's job is to filter this traffic. When activated, Cloudflare will check every visitor before forwarding the request to your server.
How Does Under Attack Mode Work?
You might be wondering, "How is this different from normal operation?"
Here's the breakdown:
- Normal Conditions: Visitors come in, pass straight through Cloudflare, and hit your server directly. Fast, no friction.
- Under Attack Mode Active: Before reaching your server, visitors must pass a Browser Security Check or Managed Challenge. Usually, this takes just a few seconds, and normal browsers pass it automatically.
The challenge could involve:
- JavaScript verification
- Cookie handling
- Sometimes a human verification like a captcha
Here's the key difference: bots or scripts cannot pass these challenges because they don't have the ability to run JavaScript or store cookies like a normal browser.
So in essence, UAM acts like an "extra gate" that filters who gets to access your server. Legit visitors pass through, suspicious ones get blocked.
Impact on Users and Services
This feature is powerful, but you also need to be aware of the consequences:
- Slightly increased access time: Because of the challenge, visitors experience a few extra seconds of waiting. Not long, but noticeable.
- Potential issues for non-browser clients: APIs, webhooks, bots, or automation scripts will likely fail because they can't pass the challenge. So if your website relies on API services, this could cause problems.
- Analytics might be affected: Since some traffic is filtered, data in Google Analytics or similar tools might become inaccurate.
But don't worry—this feature isn't meant to be used daily. Think of it more like an "emergency button" for critical situations.
When Should You Enable Under Attack Mode?
The simple answer is: when your website is under attack.
To be more specific, here are the conditions where I'd recommend activating UAM:
- Server starts getting slow or goes down due to abnormal traffic.
- Server logs show suspicious request patterns—for example, many requests from the same IP, or strange user agents.
- Layer 7/HTTP flood attack patterns are detected.
Keep this in mind: Under Attack Mode is NOT meant to stay on all the time. If you leave it on permanently, you'll degrade the user experience, and non-browser clients might break.
For everyday protection, rely on a combination of other Cloudflare features like DDoS Protection, WAF (Web Application Firewall), Rate Limiting, and other security rules. That's usually enough to keep your website safe under normal conditions.
Selective Application (Not Entire Website)
One of the coolest things about Cloudflare is that you can apply UAM selectively, rather than to your entire website.
For example, you might run an e-commerce site. The homepage and product pages might not need UAM, but you could enable it for:
- Login pages
- Admin areas
- Specific endpoints like /checkout or /payment
- Or based on IP, country, ASN, or certain traffic characteristics
This way, you provide extra protection to the most sensitive areas without compromising the performance of your entire website.
Cloudflare calls this the Managed Challenge within WAF rules. You can create custom rules that say: "If a request hits this path, run a challenge." Pretty cool, right?
How This Relates to XAMPP + Cloudflare Tunnel
This is important for anyone running a local website with XAMPP/Apache and connecting it to the internet via Cloudflare Tunnel.
In this architecture, Cloudflare Tunnel connects your local server to Cloudflare, and Cloudflare sits in front as a gateway. So all internet traffic passes through Cloudflare first, then gets forwarded to Apache/PHP/MySQL locally.
Here, UAM can serve as an additional defense layer that's incredibly useful. Why? Because UAM filters traffic at Cloudflare before it ever reaches your local server. So if there's a major attack, your Apache server won't get overwhelmed—Cloudflare filters it out first.
But remember: UAM is not a replacement for server-origin security. You still need to secure your XAMPP/Apache setup properly. Don't let your server get compromised just because you trust Cloudflare too much.
My advice:
- Keep Apache/PHP updated
- Never allow direct internet access to your local server except through Cloudflare Tunnel
- Local configurations like .htaccess or firewalls still matter
Final Thoughts
So, the bottom line is this: Cloudflare Under Attack Mode is an emergency defense tool for websites under attack, especially Layer 7 DDoS attacks. It filters traffic before it reaches your server, but it does have consequences for user experience and non-browser services.
- Don't keep it always on—this is not a daily-use feature.
- Rely on WAF, Rate Limiting, and DDoS Protection as your daily defense.
- Apply it selectively to sensitive areas like login or admin pages.
- If you're using XAMPP + Cloudflare Tunnel, UAM can be very helpful in reducing the load on your local server during attacks.
Hope this clears things up for anyone who's been confused about UAM. If you have questions or interesting attack experiences, feel free to share in the comments. I'll do my best to respond.
FAQ — Common Questions About Cloudflare Under Attack Mode
Is Under Attack Mode the same as Cloudflare WAF?
No. Under Attack Mode is a separate feature that acts as a browser-based challenge to filter traffic during an attack. WAF (Web Application Firewall) is a broader feature that filters traffic based on security rules continuously.
Can Under Attack Mode be used to protect APIs?
Not recommended. APIs and non-browser clients typically can't pass the JavaScript challenges that UAM presents. For APIs, stick with Rate Limiting, API Shield, or more specific WAF rules.
How long should Under Attack Mode stay enabled?
Only while the attack is ongoing. Once traffic returns to normal, disable it to avoid affecting user experience and non-browser services.
Can Under Attack Mode be used with Cloudflare Tunnel?
Yes. In a XAMPP + Cloudflare Tunnel setup, UAM adds an extra layer of protection before requests reach your origin server, reducing the load on your local server during attacks.
How do I enable Under Attack Mode on Cloudflare?
Go to your Cloudflare dashboard, select your website, open Security > Settings, and toggle on "Under Attack Mode." You can also use WAF rules with Managed Challenge for more selective application.
Terima kasih sudah mampir! Jika kamu menikmati konten ini dan ingin menunjukkan dukunganmu, bagaimana kalau mentraktirku secangkir kopi? 😊 Ini adalah gestur kecil yang sangat membantu untuk menjaga semangatku agar terus membuat konten-konten keren. Tidak ada paksaan, tapi secangkir kopi darimu pasti akan membuat hariku jadi sedikit lebih cerah. ☕️
Thank you for stopping by! If you enjoy the content and would like to show your support, how about treating me to a cup of coffee? �� It’s a small gesture that helps keep me motivated to continue creating awesome content. No pressure, but your coffee would definitely make my day a little brighter. ☕️ Buy Me Coffee

Post a Comment for "Cloudflare Under Attack Mode: What It Is and When to Use It"
Post a Comment
You are welcome to share your ideas with us in comments!