Exclude a prefix
To exclude a prefix or a prefix subset from Advanced DDoS Protection:
-
In the Cloudflare dashboard, go to the L3/4 DDoS protection page.
Go to DDoS Managed Rules -
Go to Advanced Protection.
-
Add the prefix you previously onboarded to Magic Transit to Advanced TCP Protection.
-
Add the prefix (or subset) you wish to exclude as a new, separate prefix in Advanced TCP Protection.
-
For the prefix you added in the previous step, select Exclude Subset in the Enrolled Prefixes list.