Bobcares

Tips to fix cloudflare error 1015

by | Jun 16, 2020

Cloudflare rate-limiting feature is designed to protect online services from attack methods like brute force logins, DDoS attack, etc. However, this feature can block legitimate access to the services at times with Cloudflare error 1015 “You are being rate-limited”.

As a  part of our Server Management Services, we help webmasters, web hosts and other online service providers to fix similar Cloudflare errors.

Today, let us discuss the possible reasons and fixes for this error.

 

What is Cloudflare error 1015?

Cloudflare Rate Limiting identifies and mitigates excessive request rates to the domain or specific URLs. Once an individual IP address exceeds a rule threshold, further requests to the origin web server are blocked with an HTTP 429 response.

The user is displayed with an error message as below:

cloudflare error 1015

 

Generally, these blocks are temporary and will be removed automatically after the specified time period. Though it is meant to block/prevent the suspicious requests to the website at times legitimate requests also get rate limited by the rules. Let us get into some of those cases and the tips to fix it in each case.

 

Low rate limiting threshold

A very low threshold limit is the prime reason for the error 1015 in most cases. The rule settings option allows us to limit the number of page requests from an IP address in a given time interval.

cloudflare error 10151

In most cases, users assume that each page of the website is equal to one request. However, this is not true. Limiting the value of request based on this assumption yields frequent 1015 error.

For instance, try accessing the google developer tools console for a website. It can be accessed from the  More tools >> Developer tools option in Google chrome. Navigate to the Network tab and then refresh your page. You may find a result as below.

cloudflare error 1015

 

The bottom part of the page shows 50 requests. Thus a single page may contain about 50 requests or more.

Hence, one way to fix the Cloudflare rate limit error is to increase the request threshold to a moderate value.

 

Active Rate Limiting rules

At times, we receive requests that the users are getting 1015 error even after disabling the Rate Limiting.

To prevent this, we need to ensure that the Rate Limiting rules that were configured for the domain are removed. This is because, in rare cases, these rules can still work even though the Rate Limiting feature is disabled for the domain

Thus the preferred method is to re-enable the rate limit, delete all the rules set for it, and then disable the rate limit to make it actually stop processing the rules.

 

Aggressive Rate Limiting rule

Another common mistake that is made while setting the rate limit rule is to keep it highly aggressive. Cloudflare’s recommended value for the rate limit time is 10 seconds or more. If any rule is configured to block an IP address for 1 sec, it is more likely to block legitimate requests.

[Need assistance to fix Cloudflare errors? We’ll help you.]

 

Conclusion

In short Cloudflare error 1015 is triggered due to Firewall rules Rate Limiting the accesses from the IP addresses. Though this is a method adopted to work against DDoS attacks and brute force attempts, at times legitimate requests are also blocked with this error. Today we discussed some tips that our Support Engineers follow to fix the error message.

PREVENT YOUR SERVER FROM CRASHING!

Never again lose customers to poor server speed! Let us help you.

Our server experts will monitor & maintain your server 24/7 so that it remains lightning fast and secure.

GET STARTED

var google_conversion_label = "owonCMyG5nEQ0aD71QM";

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Never again lose customers to poor
server speed! Let us help you.

Privacy Preference Center

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

PHPSESSID - Preserves user session state across page requests.

gdpr[consent_types] - Used to store user consents.

gdpr[allowed_cookies] - Used to store user allowed cookies.

PHPSESSID, gdpr[consent_types], gdpr[allowed_cookies]
PHPSESSID
WHMCSpKDlPzh2chML

Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga - Preserves user session state across page requests.

_gat - Used by Google Analytics to throttle request rate

_gid - Registers a unique ID that is used to generate statistical data on how you use the website.

smartlookCookie - Used to collect user device and location information of the site visitors to improve the websites User Experience.

_ga, _gat, _gid
_ga, _gat, _gid
smartlookCookie
_clck, _clsk, CLID, ANONCHK, MR, MUID, SM

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

IDE - Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

test_cookie - Used to check if the user's browser supports cookies.

1P_JAR - Google cookie. These cookies are used to collect website statistics and track conversion rates.

NID - Registers a unique ID that identifies a returning user's device. The ID is used for serving ads that are most relevant to the user.

DV - Google ad personalisation

_reb2bgeo - The visitor's geographical location

_reb2bloaded - Whether or not the script loaded for the visitor

_reb2bref - The referring URL for the visit

_reb2bsessionID - The visitor's RB2B session ID

_reb2buid - The visitor's RB2B user ID

IDE, test_cookie, 1P_JAR, NID, DV, NID
IDE, test_cookie
1P_JAR, NID, DV
NID
hblid
_reb2bgeo, _reb2bloaded, _reb2bref, _reb2bsessionID, _reb2buid

Security

These are essential site cookies, used by the google reCAPTCHA. These cookies use an unique identifier to verify if a visitor is human or a bot.

SID, APISID, HSID, NID, PREF
SID, APISID, HSID, NID, PREF