Last updated
Was this helpful?
How to allow Snyk API and Web scanner IPs in your WAF
Snyk API & Web uses specific public IP addresses to scan your targets. If you use a Web Application Firewall (WAF) in front of your target, it can block scan requests and cause the scan to fail. To avoid that, configure the WAF to allow Snyk IP addresses.
For a list of Snyk IP addresses, visit Scanner IP address.
Cloudflare provides documentation explaining how to configure access rules for its WAF. There is an overview of IP Access rules, and the configuration steps are described in Create an IP Access rule.
When following these steps, use this information:
IP, IP range, country name, or ASN - Enter the Snyk IP address for your case.
Action - Select Allow.
Zone - To apply the rule only to the current zone, select This website. To create the rule in all zones of your Cloudflare account, select All websites in account.
Notes - Optionally, provide text identifying the rule. For example, "Snyk API & Web IP".
After you create the rule, your target scans with Snyk run without being blocked by Cloudflare WAF.
Last updated
Was this helpful?
Was this helpful?

