Even with the WAF disabled (at least as much as I can disable it without the Enterprise plan, i.e. "Essentially Off"), I've found it will still block legitimate requests. Tainted CGNAT or dynamic IPs are my guess.
The WAF doesn't really matter for my use case as the route is handled by a CF worker, in fact I'd prefer it doesn't get in the way.
Edge Cache with unmetered egress?
unmetered up to a point, but yeah. Also network-level DDoS protection
If you are reaching the point where they are sending you emails asking about what you are doing, you should be paying for it.
In the article, the author disables the WAF only for Stripe outbound IPs, which can be presumed to be safe (unless Stripe's machines/IP space gets hacked). The WAF still works for traffic from all other IPs
yeah, but sadly there aren’t many CDNs that offer WAF, even the most basic one. I literally begged bunnyCDN to build one so we can switch from CF. It’s on their roadmap for like forever.
Would it still do DDOS even without the WAF?
Our DDoS mitigation is separate yes and will still work.