Cloudflare Docs
DDoS Protection
Edit this page on GitHub
Set theme to dark (⇧+D)

Create a filter

A filter modifies Advanced TCP Protection’s execution mode — monitoring, mitigation (enabled), or disabled — for all incoming packets matching an expression.

Each protection system component (SYN flood protection or out-of-state TCP protection) should have at least one rule, but filters are optional.

​​ Procedure

To create a filter for one of the system components:

  1. Log in to the Cloudflare dashboard and select your account.

  2. Go to Account Home > L3/4 DDoS > Advanced TCP Protection.

  3. Under the system component for which you are creating the filter (SYN Flood Protection or Out-of-state TCP Protection), select Create next to the type of filter you want to create:

    • Mitigation Filter: The protection system will drop packets matching the filter expression.
    • Monitoring Filter: The protection system will log packets matching the filter expression.
    • Off Filter: The protection system will ignore packets matching the filter expression.
  4. Under When incoming packets match, define a filter expression using the Expression Builder (specifying one or more values for Field, Operator, and Value), or manually enter an expression using the Expression Editor. For more information, refer to Edit rule expressions.

  5. Select Save.