Your accessFlow audit may fail if your website’s firewall or bot protection blocks audit requests or presents a CAPTCHA challenge. These restrictions prevent accessFlow from reaching and testing your site.
To resolve this, follow the instructions below for the security service protecting your site. If you use multiple services, you may need to update each one.
After updating your security settings, run the accessFlow scan again.
Cloudflare configuration
Create a custom rule that matches accessFlow’s scanner IP address and skips the available security checks for those requests.
- In the Cloudflare dashboard, select the domain accessFlow audits.
- Go to Security rules and select Create rule > Custom rules.
- Enter a descriptive rule name, such as Allow accessFlow audits.
- Configure the rule to match incoming requests whose IP source address is 34.23.64.234.
- Under Choose action, select Skip.
- Select all available security features to skip, including the remaining custom rules, rate limiting rules, managed rules, and Super Bot Fight Mode rules, where available.
- Place this rule before rules that could block the scanner, then save and activate it.
- Repeat for each domain accessFlow audits.
Alternatively, if IP Access Rules is available in your dashboard, add 34.23.64.234 with the action Allow.
Note: Cloudflare’s Bot Fight Mode cannot be skipped using a custom rule. If it is blocking your audit, review Cloudflare’s guidance for blocked legitimate bots.
Firewall or WAF configuration
Add 34.23.64.234 to your firewall or web application firewall (WAF) allowlist for HTTPS traffic to each domain accessFlow audits.
This is the scanner’s outbound IP address for the US region. The scanner makes standard HTTPS requests. No other ports or protocols need to be allowed.
Bot protection service configuration
In your provider’s bot protection settings, create an allowlist rule for requests whose User Agent contains AccessFlowBot/1.0.
If your provider needs more information, share the accessFlow scanner information page.
Identity verification
accessFlow signs every audit request. Your provider can use accessFlow’s public keys to verify that requests come from the accessFlow scanner.
Share the public key directory with your provider or the team managing your website’s security if they require it for verification.