In fact, it's possible that the person he was hitting was in "I'm under attack" mode or similar, which would try to reduce bot hits to the web server by any means necessary to prevent a layer 7 attack from taking the site offline.
In fact, it's possible that the person he was hitting was in "I'm under attack" mode or similar, which would try to reduce bot hits to the web server by any means necessary to prevent a layer 7 attack from taking the site offline.
In a security context, automatically poking a hole through for RSS is automatically giving attackers an easy-to-use door straight through to the underlying site to DDoS them.
You might want to say "Oh, well, then, let's just set some bandwidth rules", which will certainly work for specific sites, but it's going to be difficult for CloudFlare to correctly guess them generically. (Not necessarily impossible, but it is impossible if you measure it from the POV of them never being wrong. It would only be a heuristic guess.)
And if your web application allows queries that produce RSS feeds that could still result in a really bad L7 attack if you simply were to ignore all feeds. No caching + randomized queries on a small site would knock it offline in no time.
https://support.cloudflare.com/hc/en-us/articles/200168306-I...
It's pretty much dead simple though, basically you put in a path like "/feed.rss", you can also use wildcards like "/feeds/*" and then set up a configuration for it including parameters like cache time and security level. In the case of a feed, high caching and minimum security are probably reasonable for most sites. Free users are limited to only a few rules (5 I think), but paying even for the cheapest plan removes the limit.