Override examples
The following scenarios detail how you can make use of override rules as a solution to common Network DDoS Protection issues.
If you have VPN traffic concentrated to a single or a few single destination IP addresses and the traffic is being blocked by a UDP rule, you can create an override rule for the UDP rule to the destination IPs or ranges.
If you recognize that the traffic flagged by the adaptive rule based on UDP and destination port is an attack, you create an override rule to enable the adaptive rule in mitigation mode, setting the action to block the traffic.
To avoid disruptions during initial deployment, you can create a Log only – Essentially Off ruleset override that allows all traffic while logging detection results. This lets you safely observe and analyze DDoS activity before enabling enforcement.
-
In the Cloudflare dashboard, go to the Security rules page.
Go to Security rules -
Go to the DDoS protection tab.
-
On HTTP DDoS attack protection, select Create override.
-
Set the Scope to Apply to all incoming packets.
-
Under Ruleset configuration:
- Set the Ruleset action to Log.
- Set the Ruleset sensitivity to Essentially Off.
-
Select Save.
Was this helpful?
- Resources
- API
- New to Cloudflare?
- Directory
- Sponsorships
- Open Source
- Support
- Help Center
- System Status
- Compliance
- GDPR
- Company
- cloudflare.com
- Our team
- Careers
- © 2025 Cloudflare, Inc.
- Privacy Policy
- Terms of Use
- Report Security Issues
- Trademark