Hướng dẫn giải pháp Solution guide មគ្គុទ្ទេសករណ៍ដំណោះស្រាយ Application Services Application Services Application Services ~10 phút ~10 min ~10 នាទី Đồng bộ 2026-06-10 Synced 2026-06-10 ធ្វើសមកាល 2026-06-10

Bảo vệ biểu mẫu của bạn khỏi spam và lạm dụng (Miễn phí, chuyên nghiệp và doanh nghiệp) Protect your forms from spam and abuse (Free, Pro, and Business) ការពារប្លាស្ទិចរបស់អ្នកពីអាសអាភាសនិងការទូទាត់ (ដោយឥតគិតថ្លៃ, អ្នកជំនាញនិងអាជីវកម្ម)

Hướng dẫn chi tiết đồng bộ từ docs Cloudflare — mỗi section có backlink tới đúng vị trí trên trang gốc. Detailed guide synced from Cloudflare docs — each section links to the matching anchor on the official page. មគ្គុទ្ទេសក៍លម្អិតធ្វើសមកាលពី docs Cloudflare — ផ្នែកនីមួយៗមានតំណទៅទីតាំងត្រូវគ្នានៅទំព័រផ្លូវការ។

← Danh mục ← Catalog ← បញ្ជី

Giải thích nhanh Quick context បរិបទរហ័ស

Thuộc nhóm Application Services — tập trung bảo vệ, tăng tốc và vận hành ứng dụng/web phía trước origin. Tutorial «Bảo vệ your forms từ spam và abuse (Free, Pro, và Business)» giúp bạn làm quen luồng triển khai thật — phù hợp đọc trước khi mở tài liệu gốc tiếng Anh. Đọc phần tóm tắt và lưu ý trước — sau đó mở docs gốc để copy lệnh và cấu hình chi tiết.

Block spam submissions, fake account creation, and card testing on your web forms using a layered defense.

ការកាត់បន្ថយការដឹកជញ្ជូនអាសអាភាស, ការបង្កើតគណនីធ្លាក់ចុះនិងការធ្វើតេស្តកាតនៅលើវេទិកាបណ្ដាញរបស់អ្នកដោយប្រើការពារដែលមានតម្រូវការ។

Lưu ý Note ចំណាំ

Lưu ý trước khi làm Notes before you start ចំណាំមុនពេលចាប់ផ្តើម

  • Đây là bản tóm tắt trên Orange Cloud Learning Hub — không thay thế tài liệu chính thức.
  • Luôn mở liên kết «Tài liệu gốc» bên dưới khi cần lệnh CLI, snippet code và ảnh minh họa đầy đủ.
  • Docs Cloudflare cập nhật thường xuyên — đối chiếu ngày «Rà soát lần cuối» trên trang gốc khi triển khai production.
  • This is a summary on Orange Cloud Learning Hub — it does not replace the official documentation.
  • Open the Official docs link below for CLI commands, code snippets, and full screenshots.
  • Cloudflare docs change frequently — verify the Last reviewed date on the official page before production use.
  • នេះគឺជាការបញ្ជាក់អំពី Orange Cloud Learning Hub — វាគឺជាការផ្លាស់ប្តូរនៃឯកសារផ្លូវការ។
  • ចុចតំណភ្ជាប់ Docs Official នៅខាងក្រោមសម្រាប់ការបញ្ជា CLI, សៀវភៅកូដនិងរូបថតពេញលេញ។
  • Cloudflare បានផ្លាស់ប្តូរជាធម្មតានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅពេលវេលានៅ។

Overview Overview Overview

Phần «Tổng quan» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Overview" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Overview» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Các hình thức liên hệ, đăng ký và thanh toán là mục tiêu phổ biến cho việc lạm dụng tự động. Hướng dẫn này bao gồm form bảo vệ: xác minh rằng khách truy cập là con người, hạn chế các bài đăng lặp đi lặp lại, và chặn các mô hình tấn công đã biết. Quá trình làm việc cốt lõi sử dụng các tính năng có sẵn trên tất cả các gói. Các tính năng Pro và Business Plan được bao gồm dưới dạng Callouts.
Contact, registration, and checkout forms are common targets for automated abuse. This guide covers form protection: verifying that visitors are human, limiting repeated submissions, and blocking known attack patterns. The core workflow uses features available on all plans. Pro and Business plan features are included as callouts.
គំរូការទាក់ទង, ការចុះឈ្មោះនិងការទូទាត់គឺជាគោលបំណងធម្មតាសម្រាប់ការទូទាត់ដោយស្វ័យប្រវត្តិ។ វគ្គសិក្សានេះគ្របដណ្តប់ការពារ form: ការត្រួតពិនិត្យថាអ្នកទស្សនកិច្ចគឺជាមនុស្ស, ការកាត់បន្ថយការដឹកជញ្ជូនដំណោះស្រាយនិងការកាត់បន្ថយគំរូការជោគជ័យដែលបានដឹង។ ប្រព័ន្ធប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ គម្រោង Pro និង Business Plan ត្រូវបានរួមបញ្ចូលជា Callouts ។
Hầu hết các thủ tục trong hướng dẫn này được cấu hình theo tên miền hoặc zone. Chọn tên miền của bạn trong bảng điều khiển Cloudflare trước khi bắt đầu. Turnstile là ngoại lệ: widget được cấu hình ở cấp độ tài khoản.
Most procedures in this guide are configured per domain or zone. Select your domain in the Cloudflare dashboard before starting. Turnstile is the exception: widgets are configured at the account level.
ភាគច្រើននៃដំណើរការនៅក្នុងឧបករណ៍នេះត្រូវបានកំណត់តាមតំបន់ឬ zone ។ សូមជ្រើសរើសឧបករណ៍របស់អ្នកនៅក្នុងឧបករណ៍ Cloudflare មុនពេលចាប់ផ្តើម។ Turnstile គឺជាការប៉ះពាល់: widgets ត្រូវបានកំណត់នៅលើកម្រិតគណនី។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thêm Turnstile vào biểu mẫu của bạn Add Turnstile to your forms Add Turnstile to your forms (បន្ថែម Turnstile ទៅលើរូបរាងរបស់អ្នក)

Phần «Thêm Turnstile vào forms» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add Turnstile to your forms" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «Add Turnstile to your forms (បន្ថែម Turnstile ទៅលើរូបរាងរបស់អ្នក)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Turnstile xác minh khách truy cập là con người mà không có thách thức rõ ràng. Hướng dẫn này sử dụng Chế độ quản lý, tự động chọn giữa một thách thức không tương tác hoặc hộp kiểm dựa trên mức độ rủi ro của khách truy cập. Đối với các chế độ widget khác, hãy tham khảo Widget types.
Turnstile verifies visitors are human without visible challenges. This guide uses Managed mode, which automatically chooses between a non-interactive or checkbox challenge based on visitor risk level. For other widget modes, refer to Widget types.
Turnstile អនុញ្ញាតឱ្យអ្នកស្វែងរកជាមនុស្សដោយគ្មានបញ្ហាដែលអាចមើលឃើញ។ វគ្គបណ្តុះបណ្តាលនេះប្រើម៉ូដែលគ្រប់គ្រងដែលបានជ្រើសរើសដោយស្វ័យប្រវត្តិរវាងការសាកល្បងដែលមិនគិតថ្លៃឬការសាកល្បងបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តុះបណ្តាល។ សម្រាប់របៀប widget ផ្សេងទៀត សូមមើល Widget types ។
Thêm Turnstile liên quan đến ba bước: tạo một widget trong bảng điều khiển, thêm đoạn trích phía khách hàng vào trang form của bạn, và xác nhận token trên máy chủ của bạn trước khi xử lý bản gửi.
Adding Turnstile involves three steps: create a widget in the dashboard, add the client-side snippet to your form page, and validate the token on your server before processing the submission.
ការបន្ថែម Turnstile រួមបញ្ចូលទាំងបីដំណោះស្រាយ: ការបង្កើតឧបករណ៍នៅក្នុងប្រព័ន្ធប្រតិបត្តិការ, ការបន្ថែមឧបករណ៍ផ្លាស់ប្តូរតាមអតិថិជនទៅលើទំព័រ form របស់អ្នកនិងការត្រួតពិនិត្យឧបករណ៍នេះនៅលើប្រព័ន្ធប្រតិបត្តិការរបស់អ្នកមុនពេលដំណើរការការ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Tạo widget Turnstile Create a Turnstile widget ការបង្កើត Turnstile widget

Phần «Tạo Turnstile widget» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Create a Turnstile widget" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបង្កើត Turnstile widget» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
  1. Trong bảng điều khiển Cloudflare, đi đến trang Turnstile.
  1. In the Cloudflare dashboard, go to the Turnstile page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Turnstile ។
  1. Chọn Add widget
  2. Điền vào các thông tin cần thiết:
  1. Select Add widget.
  2. Fill out the required information:
  1. សូមជ្រើស Add widget ។
  2. សូមបញ្ជាក់អំពីព័ត៌មានដែលត្រូវការ:
Widget name: Một tên mô tả cho widget của bạn. Hostname management: Các miền mà widget sẽ được sử dụng. * Widget mode: Chọn từ quản lý, không tương tác, hoặc vô hình.
Widget name: A descriptive name for your widget. Hostname management: Domains where the widget will be used. * Widget mode: Choose from Managed, Non-Interactive, or Invisible.
Widget name: ឈ្មោះសៀវភៅសម្រាប់ឧបករណ៍របស់អ្នក។ Hostname management: តំបន់ដែលអ្នកនឹងប្រើ widget នេះ។ * Widget mode: ជ្រើសពី Managed, Non-Interactive ឬ Invisible ។
  1. (Tùy chọn) Cài đặt Pre-clearance support cho các ứng dụng đơn trang.
  2. Chọn Create để lưu widget của bạn.
  3. Sao chép sitekey và khóa bí mật của bạn, và lưu trữ khóa bí mật một cách an toàn.
  1. (Optional) Configure Pre-clearance support for single-page applications.
  2. Select Create to save your widget.
  3. Copy your sitekey and secret key, and store the secret key securely.
  1. (គោលបំណង) ការកំណត់ Pre-clearance support សម្រាប់កម្មវិធីមួយទំព័រ។
  2. ចុច Create ដើម្បីផ្ទុក widget របស់អ្នក។
  3. ចម្លង sitekey និង key secret របស់អ្នកហើយផ្ទុក key secret ជាសុវត្ថិភាព។
Lưu trữ sitekey và khóa bí mật. Bạn sẽ sử dụng sitekey trong đoạn trích client-side và khóa bí mật cho xác nhận server-side.
Store the sitekey and secret key. You will use the sitekey in the client-side snippet and the secret key for server-side validation.
ទាញយក sitekey និង key secret ។ អ្នកនឹងប្រើ sitekey នៅក្នុងកំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់កំណត់។

Thêm snippet client-side Add the client-side snippet លក្ខណៈពិសេសនៃ snippet client-side

Phần «Thêm client-side snippet» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add the client-side snippet" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «លក្ខណៈពិសេសនៃ snippet client-side» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thêm Turnstile kịch bản và widget div yếu tố vào mỗi form bạn muốn bảo vệ. Thay thế <YOUR-SITE-KEY> bằng sitekey từ bước trước.
Add the Turnstile script and widget div element to each form you want to protect. Replace <YOUR-SITE-KEY> with the sitekey from the previous step.
បន្ថែមប្រព័ន្ធប្រតិបត្តិការ Turnstile និងប្រព័ន្ធប្រតិបត្តិការ div សម្រាប់ប្រព័ន្ធប្រតិបត្តិការ form ដែលអ្នកចង់ការពារ។ សូមផ្លាស់ប្តូរ <YOUR-SITE-KEY> ជាមួយនឹង sitekey ពីដំណោះស្រាយមុន។
text
<form id="contact-form" action="/submit" method="POST">

  <input type="text" name="name" placeholder="Name" required />

  <input type="email" name="email" placeholder="Email" required />

  <textarea name="message" placeholder="Message" required></textarea>

  <div class="cf-turnstile" data-sitekey="<YOUR-SITE-KEY>"></div>

  <button type="submit">Submit</button>

</form>


<script src="https://challenges.cloudflare.com/turnstile/v0/api.js" async defer></script>
Widget hiển thị trong form và tạo ra một token khi khách truy cập vượt qua xác minh. Token được bao gồm trong bài gửi form dưới dạng trường cf-turnstile-response.
The widget renders in the form and generates a token when the visitor passes verification. The token is included in the form submission as the cf-turnstile-response field.
ឧបករណ៍នេះធ្វើឱ្យប្រសើរឡើងនៅក្នុង form និងបង្កើត token នៅពេលដែលអ្នកចូលរួមបញ្ចូលការត្រួតពិនិត្យ។ ស្លាកនេះត្រូវបានរួមបញ្ចូលនៅក្នុងការដឹកជញ្ជូន form ដូចជាឧបករណ៍ cf-turnstile-response ។

Xác nhận token trên máy chủ của bạn Validate the token on your server ការត្រួតពិនិត្យ token នៅលើបណ្តាញរបស់អ្នក

Phần «Validate token on your server» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Validate the token on your server" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការត្រួតពិនិត្យ token នៅលើបណ្តាញរបស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Server-side validation là cần thiết. Các widget phía khách hàng một mình không bảo vệ các biểu mẫu của bạn bởi vì kẻ tấn công có thể gửi trực tiếp đến điểm cuối của bạn form. Token chỉ có thể được xác nhận một lần.
Server-side validation is required. The client-side widget alone does not protect your forms because attackers can submit directly to your form endpoint. Tokens can only be validated once.
ការត្រួតពិនិត្យ server-side ដែលត្រូវការ។ ប្រព័ន្ធ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ ប្រតិបត្តិការ Tokens អាចត្រូវបានត្រួតពិនិត្យឡើងវិញតែមួយដង។
Gọi Siteverify API trước khi xử lý bất kỳ form gửi:
Call the Siteverify API before processing any form submission:
ទូរស័ព្ទ Siteverify API មុនពេលដំណើរការ form ការបញ្ជូនណាមួយ:
Máy chủ .js
server.js
ប្រព័ន្ធប្រតិបត្តិការ .js
text
const SECRET_KEY = "<YOUR-SECRET-KEY>";


async function validateTurnstile(token, remoteip) {

  try {

    const response = await fetch(

      "https://challenges.cloudflare.com/turnstile/v0/siteverify",

      {

        method: "POST",

        headers: { "Content-Type": "application/json" },

        body: JSON.stringify({

          secret: SECRET_KEY,

          response: token,

          remoteip: remoteip,

        }),

      },

    );


    const result = await response.json();

    return result;

  } catch (error) {

    console.error("Turnstile validation error:", error);

    return { success: false, "error-codes": ["internal-error"] };

  }

}
Thay thế "<YOUR-SECRET-KEY>" bằng khóa bí mật Turnstile của bạn. Điểm cuối trả về một đối tượng JSON với trường success. Chỉ xử lý form nếu success là true.
Replace "<YOUR-SECRET-KEY>" with your Turnstile secret key. The endpoint returns a JSON object with a success field. Only process the form submission if success is true.
ការផ្លាស់ប្តូរ "<YOUR-SECRET-KEY>" ដោយ Turnstile secret key របស់អ្នក។ កុំព្យូទ័រ Endpoint បានបង្ហាញនូវ JSON object ជាមួយនឹងការ success ។ ការដំណើរការ form គឺតែប្រសិនបើ success គឺ true ។
Đối với các ví dụ xác thực trong PHP, Python, Java và C#, hãy tham khảo Validate the token.
For validation examples in PHP, Python, Java, and C#, refer to Validate the token.
សម្រាប់ឧទាហរណ៍ការត្រួតពិនិត្យនៅក្នុង PHP, Python, Java និង C# សូមមើល Validate the token ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Giới hạn tỷ lệ form điểm cuối gửi Rate limit form submission endpoints ទំហំទំហំ form ដំណឹងបញ្ចូល

Phần «Rate limit form submission endpoints» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Rate limit form submission endpoints" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទំហំទំហំ form ដំណឹងបញ្ចូល» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Một số kịch bản lạm dụng bỏ lỡ trình duyệt hoàn toàn và POST trực tiếp đến các điểm cuối form của bạn. Ứng dụng bảo mật rate limiting rules nắm bắt các yêu cầu này bởi vì xác minh phía khách hàng chỉ chạy trong một trình duyệt.
Some abuse scripts skip the browser entirely and POST directly to your form endpoints. Application Security rate limiting rules catch these requests because client-side verification only runs in a browser.
សៀវភៅផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់ផ្សេងគ្នានៃការប្រើប្រាស់។ ការសុវត្ថិភាពកម្មវិធី rate limiting rules ទទួលបានតម្រូវការទាំងនេះដោយសារតែការត្រួតពិនិត្យរបស់កុំព្យូទ័រតែធ្វើដំណើរនៅក្នុងបណ្តាញមួយ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Tìm tỷ lệ yêu cầu Baseline của bạn Find your baseline request rate ស្វែងរកតម្រូវការ Baseline របស់អ្នក

Phần «Find your baseline request rate» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Find your baseline request rate" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ស្វែងរកតម្រូវការ Baseline របស់អ្នក» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Trước khi tạo quy tắc rate limiting, hãy kiểm tra tỷ lệ gửi bình thường cho các điểm cuối form của bạn. Ngưỡng giới hạn lãi suất của bạn nên cao hơn mức cơ bản này để tránh chặn lưu lượng truy cập hợp pháp.
Before creating a rate limiting rule, check the normal submission rate for your form endpoints. Your rate limit threshold should be above this baseline to avoid blocking legitimate traffic.
មុនពេលដែលអ្នកបង្កើតกฎ rate limiting សូមពិនិត្យមើលកម្រិតបញ្ជូនធម្មតាសម្រាប់កំណត់បញ្ចប់ form របស់អ្នក។ ទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំ
  1. Trong bảng điều khiển Cloudflare, đi đến trang Analytics.
  1. In the Cloudflare dashboard, go to the Analytics page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Analytics ។
  1. Trong tab Traffic, chọn một khoảng thời gian với lưu lượng truy cập không đạt đỉnh hoặc với hoạt động khách truy cập thấp nhất.
  2. Sử dụng nút Add filter để thu hẹp kết quả đến lưu lượng truy cập điểm cuối form.
  3. Lưu ý tỷ lệ yêu cầu điển hình cho mỗi địa chỉ IP. Giới hạn lãi suất của bạn nên ở trên giới hạn cơ bản này.
  1. In the Traffic tab, select a time period with non-peak traffic, or with the lowest visitor activity.
  2. Use the Add filter button to narrow results to your form endpoint traffic.
  3. Note the typical request rate per IP address. Your rate limit should be above this baseline.
  1. នៅលើទម្រង់ Traffic, ជ្រើសរើសអំឡុងពេលដែលការដឹកជញ្ជូនមិនមានកម្រិតខ្ពស់ឬមានប្រតិបត្តិការអតិថិជនទាបបំផុត។
  2. ប្រើកញ្ចក់ Add filter ដើម្បីកាត់បន្ថយផលិតផលដល់ការដឹកជញ្ជូន endpoint របស់អ្នក form ។
  3. សូមពិនិត្យមើលទំហំសំណួរធម្មតាសម្រាប់អាសយដ្ឋាន IP ។ តម្លៃរបស់អ្នកគួរតែខ្ពស់ជាងគោលដៅនេះ។
Nếu bạn không có đủ dữ liệu lưu lượng truy cập để thiết lập điểm khởi điểm, hãy bắt đầu với ngưỡng bảo thủ và điều chỉnh dựa trên Sự kiện bảo mật sau khi triển khai.
If you do not have enough traffic data to establish a baseline, start with a conservative threshold and adjust based on Security Events after deployment.
ប្រសិនបើអ្នកមិនមានទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យទិន្នន័យ។
Enterprise: Phân tích tỷ lệ yêu cầu
Enterprise: Request rate analysis
Enterprise: ការដោះស្រាយតម្លៃទម្រង់
Tab Request rate analysis trong Security Analytics hiển thị phân phối tỷ lệ yêu cầu cho khách hàng duy nhất hàng đầu của bạn. Để biết chi tiết, hãy tham khảo Find appropriate rate limit.
The Request rate analysis tab in Security Analytics displays request rate distributions for your top unique clients. For details, refer to Find appropriate rate limit.
ស្លាក Request rate analysis នៅលើ Security Analytics បង្ហាញការផ្លាស់ប្តូរទំហំសំណួរសម្រាប់អតិថិជនតែមួយគត់របស់អ្នក។ ប្រសិនបើអ្នកមានព័ត៌មានបន្ថែមទៀត, សូមមើល Find appropriate rate limit ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Tạo quy tắc rate limiting Create a rate limiting rule ការបង្កើតច្បាប់ rate limiting

Tạo rule that limits how many times a single IP address can submit to your form endpoint within a given period. Adjust the path, threshold, and period for your site.

Read the "Create a rate limiting rule" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបង្កើតច្បាប់ rate limiting» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Tạo quy tắc giới hạn số lần một địa chỉ IP duy nhất có thể gửi đến điểm cuối form của bạn trong một khoảng thời gian nhất định. Điều chỉnh con đường, ngưỡng và thời gian cho trang web của bạn.
Create a rule that limits how many times a single IP address can submit to your form endpoint within a given period. Adjust the path, threshold, and period for your site.
បានបង្កើតกฎដែលកាត់បន្ថយចំនួនប្រហែលជាអាសយដ្ឋាន IP មួយអាចផ្ញើទៅ form របស់អ្នកក្នុងអំឡុងពេលវេលាមួយ។ ការផ្លាស់ប្តូរដំណើរការទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំទំហំ
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security rules.
  1. In the Cloudflare dashboard, go to the Security rules page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security rules ។
  1. Chọn Create rule và chọn Rate limiting rules.
  2. Nhập tên cho quy tắc (ví dụ: "Rate limit contact form submissions").
  3. Trong When incoming requests match, chọn Edit expression và nhập: (http.request.uri.path eq "/contact" and http.request.method eq "POST")
  1. Select Create rule and choose Rate limiting rules.
  2. Enter a name for the rule (for example, "Rate limit contact form submissions").
  3. Under When incoming requests match, select Edit expression and enter: (http.request.uri.path eq "/contact" and http.request.method eq "POST")
  1. ចុច Create rule ហើយចុច Rate limiting rules ។
  2. បញ្ចូលឈ្មោះសម្រាប់ច្បាប់នេះ (ដូចជា "កំណត់តម្លៃទាក់ទង form submissions") ។
  3. នៅក្រោម When incoming requests match, ជ្រើស Edit expression និងចុះឈ្មោះ: (http.request.uri.path eq "/contact" and http.request.method eq "POST")
Thay thế "/contact" bằng đường dẫn điểm cuối của bạn form.
Replace "/contact" with your form endpoint path.
សូមផ្លាស់ប្តូរ "/contact" ជាមួយ form របស់អ្នក។
  1. Trong With the same characteristics, hãy xác minh rằng IP đã được chọn. Trên các gói miễn phí, điều này được đặt trước thành IP.
  2. Trong When rate exceeds, nhập 5 cho Requests và chọn một giá trị cho Period. Trên gói miễn phí, hãy chọn 10 seconds. Pro và trên các kế hoạch cung cấp thời gian bổ sung. Đối với các giá trị có sẵn theo kế hoạch, hãy tham khảo Rate limiting parameters.
  3. Trong Then take action, chọn action từ thả xuống Choose action. Trên gói miễn phí, hãy chọn Block. Trên Pro và trên, Managed Challenge được khuyến cáo vì nó cho phép người dùng hợp pháp kích hoạt giới hạn để vượt qua bằng cách hoàn thành một thách thức.
  4. Trong For duration, chọn một thời gian cho action. Trên gói miễn phí, hãy chọn 10 seconds. Pro và trên các kế hoạch cung cấp thời gian dài hơn. Đây là thời gian action áp dụng sau khi giới hạn tỷ lệ được kích hoạt.
  5. Chọn Deploy
  1. Under With the same characteristics, verify that IP is selected. On Free plans, this is preset to IP.
  2. Under When rate exceeds, enter 5 for Requests and select a value for Period. On Free plans, select 10 seconds. Pro and above plans offer additional periods. For available values by plan, refer to Rate limiting parameters.
  3. Under Then take action, select an action from the Choose action dropdown. On Free plans, select Block. On Pro and above, Managed Challenge is recommended because it allows legitimate users who trigger the limit to pass by completing a challenge.
  4. Under For duration, select a duration for the action. On Free plans, select 10 seconds. Pro and above plans offer longer durations. This is how long the action applies after the rate limit is triggered.
  5. Select Deploy.
  1. នៅក្រោម With the same characteristics សូមបញ្ជាក់ថា IP ត្រូវបានជ្រើសរើស។ នៅលើគម្រោងដោយឥតគិតថ្លៃវាត្រូវបានកំណត់ទៅ IP។
  2. នៅក្រោម When rate exceeds, ទាញយក 5 សម្រាប់ Requests ហើយជ្រើសរើសតម្លៃសម្រាប់ Period ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច 10 seconds ។ គម្រោង pro និង above បានផ្តល់ជូននូវពេលវេលាបន្ថែមទៀត។ សម្រាប់គុណសម្បត្តិដែលអាចរកបានដោយគំនិត, សូមមើល Rate limiting parameters ។
  3. នៅក្រោម Then take action, ជ្រើស action ពីការបង្វិល Choose action ។ នៅលើគម្រោងដោយឥតគិតថ្លៃចុច Block ។ នៅលើអ្នកជំនាញនិងខ្ពស់ជាងនេះ, Managed Challenge ត្រូវបានផ្តល់អនុសាសន៍ដោយសារតែវាអាចអនុញ្ញាតឱ្យអ្នកប្រើដែលមានសុវត្ថិភាពដែលកាត់បន្ថយការកាត់បន្ថយដោយបញ្ចប់ការជោគជ័យ។
  4. Under For duration, select a duration for the action. On Free plans, select 10 seconds. Pro and above plans offer longer durations. This is how long the action applies after the rate limit is triggered.
  5. សូមជ្រើស Deploy ។
Các thông số quy tắc Rate limiting (tính năng đếm, thời gian, số lượng quy tắc) thay đổi theo kế hoạch. Đối với ma trận sẵn có đầy đủ, hãy tham khảo Rate limiting rules.
Rate limiting rule parameters (counting characteristics, periods, number of rules) vary by plan. For the full availability matrix, refer to Rate limiting rules.
Rate limiting rule parameters (counting characteristics, periods, number of rules) vary by plan. For the full availability matrix, refer to Rate limiting rules.

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thiết lập câu trả lời tùy chỉnh cho các yêu cầu bị chặn (Pro và cao hơn) Configure a custom response for blocked requests (Pro and above) ការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជា (Pro and above)

Phần «Cấu hình custom response for blocked requests (Pro và above)» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Configure a custom response for blocked requests (Pro and above)" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជាការបញ្ជា (Pro and above)» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thay vì hiển thị trang lỗi mặc định Cloudflare khi đạt đến giới hạn tỷ lệ, bạn có thể cấu hình một phản ứng tùy chỉnh. Để biết chi tiết, hãy tham khảo Create a rate limiting rule in the dashboard.
Instead of showing the default Cloudflare error page when a rate limit is reached, you can configure a custom response. For details, refer to Create a rate limiting rule in the dashboard.
ទោះជាយ៉ាងណាក៏ដោយអ្នកមិនអាចបង្ហាញទំព័រអំណាចទូទៅ Cloudflare នៅពេលដែលមានតម្លៃបញ្ចប់អ្នកអាចកំណត់ការឆ្លើយតបដោយផ្ទាល់។ ប្រសិនបើអ្នកមានព័ត៌មានបន្ថែមទៀត, សូមមើល Create a rate limiting rule in the dashboard ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thêm các quy tắc bảo mật ứng dụng cho các mô hình lạm dụng đã biết Add Application Security rules for known abuse patterns បន្ថែមច្បាប់សុវត្ថិភាពកម្មវិធីសម្រាប់គំរូការទូទាត់ដែលបានដឹង

Phần «Thêm ứng dụng Security rules for known abuse patterns» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Add Application Security rules for known abuse patterns" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «បន្ថែមច្បាប់សុវត្ថិភាពកម្មវិធីសម្រាប់គំរូការទូទាត់ដែលបានដឹង» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Rate limiting không bắt được các mô hình tấn công mục tiêu như SQL injection hoặc cross-site scripting (XSS) trong các trường form. Ứng dụng bảo mật custom rules và managed rulesets cho phép bạn chặn các mô hình cụ thể nhắm mục tiêu các điểm cuối form của bạn. Quy tắc tùy chỉnh chạy trước quy tắc rate limiting và tập quy tắc được quản lý trong execution order.
Rate limiting alone does not catch targeted attack patterns like SQL injection or cross-site scripting (XSS) in form fields. Application Security custom rules and managed rulesets let you block these specific patterns targeting your form endpoints. Custom rules run before rate limiting rules and managed rulesets in the execution order.
Rate limiting alone does not catch targeted attack patterns like SQL injection or cross-site scripting (XSS) in form fields. Application Security custom rules and managed rulesets let you block these specific patterns targeting your form endpoints. Custom rules run before rate limiting rules and managed rulesets in the execution order.

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thách thức các yêu cầu không phải bot đến các điểm cuối form Challenge non-bot requests to form endpoints ការជួញដូរតម្រូវការដែលមិនជា bot ទៅ form endpoints

Tạo custom rule that challenges POST requests to your form endpoints from sources that are not verified bots.

Read the "Challenge non-bot requests to form endpoints" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការជួញដូរតម្រូវការដែលមិនជា bot ទៅ form endpoints» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Tạo một quy tắc tùy chỉnh thách thức các yêu cầu POST đến các điểm cuối form của bạn từ các nguồn không phải là bot đã xác minh.
Create a custom rule that challenges POST requests to your form endpoints from sources that are not verified bots.
បានបង្កើតច្បាប់ផ្ទាល់ខ្លួនដែលជំរុញសំណួរ POST ទៅ form របស់អ្នក endpoints ពីប្រភពដែលមិនជា bots បានត្រួតពិនិត្យឡើងវិញ។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security rules.
  1. In the Cloudflare dashboard, go to the Security rules page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security rules ។
  1. Chọn Create rule \> Custom rules.
  2. Nhập tên cho quy tắc (ví dụ: "Challenge spam form submissions").
  3. Trong When incoming requests match, chọn Edit expression và nhập:
  1. Select Create rule \> Custom rules.
  2. Enter a name for the rule (for example, "Challenge spam form submissions").
  3. Under When incoming requests match, select Edit expression and enter:
  1. សូមចុច Create rule > Custom rules ។
  2. Enter a name for the rule (for example, "Challenge spam form submissions").
  3. នៅក្រោម When incoming requests match សូមជ្រើស Edit expression ហើយចូលទៅក្នុង:
text
(http.request.uri.path eq "/contact" and http.request.method eq "POST" and not cf.client.bot)
Thay thế /contact bằng đường dẫn điểm cuối của bạn form. Điều khoản not cf.client.bot miễn trừ các bot đã được xác minh (chẳng hạn như crawler công cụ tìm kiếm) khỏi quy tắc.
Replace /contact with your form endpoint path. The not cf.client.bot clause exempts verified bots (such as search engine crawlers) from the rule.
Replace /contact with your form endpoint path. The not cf.client.bot clause exempts verified bots (such as search engine crawlers) from the rule.
  1. Trong Then take action, chọn Challenge quản lý.
  1. Under Then take action, select Managed Challenge.
  1. នៅក្រោម Then take action, ជ្រើសរើស Managed Challenge ។
Bắt đầu với Managed Challenge để quan sát yêu cầu nào được đánh dấu trước khi chuyển sang Block.
Start with Managed Challenge to observe which requests are flagged before switching to Block.
Start with Managed Challenge to observe which requests are flagged before switching to Block.
  1. Chọn Deploy
  1. Select Deploy.
  1. សូមជ្រើស Deploy ។
Sau khi triển khai, hãy xem lại Security Events để kiểm tra xem quy tắc có khớp với lưu lượng truy cập hợp pháp hay không. Nếu người dùng hợp pháp đang bị thách thức, hãy thu hẹp biểu thức hoặc chuyển sang action ít hung hăng hơn.
After deploying, review Security Events to check whether the rule is matching legitimate traffic. If legitimate users are being challenged, narrow the expression or switch to a less aggressive action.
After deploying, review Security Events to check whether the rule is matching legitimate traffic. If legitimate users are being challenged, narrow the expression or switch to a less aggressive action.
Pro plans và above: Managed rulesets (Các quy tắc quản lý)
Pro plans and above: Managed rulesets
Pro plans and above: Managed rulesets
Cloudflare Managed Ruleset bảo vệ chống lại các mô hình tấn công web phổ biến, bao gồm các cuộc tấn công nhúng dựa trên form (SQL injection, XSS). Kiểm tra quy tắc được triển khai trên trang Security rules dưới Managed rules. Để biết tính sẵn có của gói, hãy tham khảo Managed Rules.
The Cloudflare Managed Ruleset protects against common web attack patterns, including form-based injection attacks (SQL injection, XSS). Verify the ruleset is deployed on the Security rules page under Managed rules. For plan availability, refer to Managed Rules.
កម្រិត Cloudflare Managed Ruleset អនុញ្ញាតឱ្យការពារប្រឆាំងនឹងគំរូការប្រឆាំងនឹងការប្រឆាំងនឹងគេហទំព័រដែលជាទូទៅរួមទាំងការប្រឆាំងនឹងការប្រឆាំងនឹងការប្រឆាំងនឹង form (SQL injection, XSS) ។ សូមពិនិត្យមើលកំណត់គ្រប់គ្រងដែលត្រូវបានដំឡើងនៅក្នុងទំព័រ Security rules នៅក្រោម Managed rules ។ សម្រាប់ការធ្វើតេស្តរបស់អ្នក, សូមមើល Managed Rules ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chuyển sang Bot Protection Turn on bot protection ចុចលើការពារ bot

Phần «Turn on bot protection» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Turn on bot protection" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ចុចលើការពារ bot» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Bot Fight Mode thách thức các yêu cầu phù hợp với các mô hình bot đã biết trên toàn bộ tên miền của bạn. Nó có sẵn trên tất cả các kế hoạch và không yêu cầu cấu hình ngoài việc bật nó.
Bot Fight Mode challenges requests that match known bot patterns across your entire domain. It is available on all plans and requires no configuration beyond turning it on.
Bot Fight Mode គោលដៅតម្រូវការដែលតម្រូវការជាមួយនឹងគំរូ bot ដែលបានដឹងនៅទូទាំងតំបន់បណ្ដាញរបស់អ្នក។ វាគឺអាចរកបាននៅលើទម្រង់ទាំងអស់ហើយមិនត្រូវការកំណត់បញ្ជាផ្សេងទៀតជាងការផ្លាស់ប្តូរវា។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security Settings.
  1. In the Cloudflare dashboard, go to the Security Settings page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security Settings ។
  1. Lọc theo Bot traffic
  2. Đi đến Bot fight mode
  3. Nhấn Bot fight mode vào.
  1. Filter by Bot traffic.
  2. Go to Bot fight mode.
  3. Turn Bot fight mode on.
  1. កញ្ចប់ដោយ Bot traffic
  2. សូមចូលទៅ Bot fight mode ។
  3. ចុច Bot fight mode នៅលើ។
  1. Đăng nhập vào Cloudflare dashboard ↗ và chọn tài khoản và tên miền của bạn.
  2. Đi đến Security \> Bots.
  3. Đối với Bot Fight Mode, hãy chọn On.
  1. Log in to the Cloudflare dashboard ↗, and select your account and domain.
  2. Go to Security \> Bots.
  3. For Bot Fight Mode, select On.
  1. ចុច Cloudflare dashboard ↗ ហើយជ្រើសគណនីរបស់អ្នកនិងតំបន់បណ្ដាញរបស់អ្នក។
  2. ចុចទៅ Security \> Bots ។
  3. សម្រាប់ Bot Fight Mode ចុច On ។
Bot Fight Mode bảo vệ toàn bộ tên miền của bạn mà không có hạn chế điểm cuối. Bạn không thể tạo ngoại lệ bằng cách sử dụng các quy tắc tùy chỉnh để bỏ qua chế độ Bot Fight.
Bot Fight Mode protects your entire domain without endpoint restrictions. You cannot create exceptions using custom rules to bypass Bot Fight Mode.
Bot Fight Mode អនុញ្ញាតឱ្យការពារអាសយដ្ឋានទាំងអស់របស់អ្នកដោយគ្មានការកាត់បន្ថយ endpoint ។ អ្នកមិនអាចបង្កើតការប៉ះពាល់ដោយប្រើច្បាប់ផ្ទាល់ខ្លួនដើម្បីឆ្លងកាត់ Bot Fight Mode ។
Pro, Business và Enterprise
Pro, Business, and Enterprise
ក្រុមហ៊ុន Pro, Business និង Enterprise
Super Bot Fight Mode cung cấp nhiều điều khiển hạt hơn. Bạn có thể cấu hình cách miền của bạn đáp ứng với các loại lưu lượng bot khác nhau (tự động nhất định, có thể tự động, được xác minh robot) và tạo ngoại lệ bằng cách sử dụng các quy tắc tùy chỉnh với Skip action. Khách hàng doanh nghiệp với Bot Management có thể sử dụng cf.bot_management.score trong các biểu thức quy tắc tùy chỉnh để bảo vệ bot cụ thể.
Super Bot Fight Mode provides more granular controls. You can configure how your domain responds to different categories of bot traffic (definitely automated, likely automated, verified bots) and create exceptions using custom rules with the Skip action. Enterprise customers with Bot Management can use cf.bot_management.score in custom rule expressions for path-specific bot protection.
Super Bot Fight Mode ផ្តល់នូវការគ្រប់គ្រងបន្ថែមទៀត។ អ្នកអាចកំណត់របៀបដែលតំបន់បណ្ដាញរបស់អ្នកឆ្លើយតបទៅនឹងប្រភេទផ្សេងគ្នានៃការដឹកជញ្ជូនប្លាស្ទិច (ប្លាស្ទិចដោយស្វ័យប្រវត្តិដោយបញ្ជាក់, អាចដោយស្វ័យប្រវត្តិដោយស្វ័យប្រវត្តិដោយស្វ័យប្រវត្តិដោយបញ្ជាក់) និងបង្កើតការប៉ះពាល់ដោយប្រើច្បាប់ផ្ទាល់ខ្លួនជាមួយ Skip action ។ អ្នកអតិថិជនអាជីវកម្មដែលមាន Bot Management អាចប្រើ cf.bot_management.score នៅក្នុងការបង្ហាញច្បាប់ផ្ទាល់ខ្លួនសម្រាប់ការការការពារ bot ដែលមានលក្ខណៈពិសេស។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Theo dõi các điểm cuối của bạn form Monitor your form endpoints ការត្រួតពិនិត្យរបស់អ្នក form endpoints

Phần «Monitor your form endpoints» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Monitor your form endpoints" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការត្រួតពិនិត្យរបស់អ្នក form endpoints» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Sau khi triển khai Turnstile, rate limiting quy tắc, và quy tắc bảo mật ứng dụng, theo dõi các điểm cuối của bạn form để xác minh các quy tắc của bạn đang hoạt động và để phát hiện các mô hình tấn công mới.
After deploying Turnstile, rate limiting rules, and Application Security rules, monitor your form endpoints to verify your rules are working and to detect new attack patterns.
បន្ទាប់ពីការដំឡើង Turnstile, rate limiting ដំណោះស្រាយនិងដំណោះស្រាយសុវត្ថិភាពកម្មវិធី, ការត្រួតពិនិត្យចំណុចបញ្ចប់ form របស់អ្នកដើម្បីត្រួតពិនិត្យឱ្យដំណោះស្រាយរបស់អ្នកធ្វើការនិងរកឃើញគំរូការជោគជ័យថ្មី។

Review sự kiện an ninh Review Security Events ការសាកល្បងសកម្មភាពសុវត្ថិភាព

Phần «Review Security Events» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Review Security Events" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការសាកល្បងសកម្មភាពសុវត្ថិភាព» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Security Events hiển thị các yêu cầu mà các sản phẩm bảo mật Cloudflare đã hành động hoặc đánh dấu, bao gồm các khối, thách thức và bỏ qua. Lọc theo đường dẫn điểm cuối của bạn form để xem những gì đang bị chặn và những gì đang đi qua. Một khối lượng lớn các yêu cầu bị chặn hoặc thách thức đến con đường form của bạn xác nhận rằng các quy tắc đang hoạt động.
Security Events shows requests that Cloudflare security products acted on or flagged, including blocks, challenges, and skips. Filter by your form endpoint paths to see what is being blocked and what is getting through. A high volume of blocked or challenged requests to your form paths confirms the rules are active.
Security Events បង្ហាញពីសំណួរដែលផលិតផលសុវត្ថិភាព Cloudflare បានអនុវត្តឬប្លុករួមបញ្ចូលទាំងការប្លុកការបំបែកនិងការបង្វិល។ តម្រងដោយ form ដំណោះស្រាយបញ្ចប់របស់អ្នកដើម្បីមើលអ្វីដែលត្រូវបានកាត់បន្ថយនិងអ្វីដែលត្រូវបានដោះស្រាយ។ ទំហំខ្ពស់នៃតម្រូវការដែលត្រូវបានកាត់បន្ថយឬការជួញដូរទៅនឹងផ្លូវរបស់អ្នក form បានបញ្ជាក់ថាត្រូវបានដំឡើង។
  1. Trong bảng điều khiển Cloudflare, đi đến trang Analytics.
  1. In the Cloudflare dashboard, go to the Analytics page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Analytics ។
  1. Chọn tab Events
  2. Sử dụng nút Add filter để thu hẹp kết quả đến lưu lượng truy cập điểm cuối form.
  3. Kiểm tra các log sampled. Đối với mỗi sự kiện, hãy kiểm tra:
  1. Select the Events tab.
  2. Use the Add filter button to narrow results to your form endpoint traffic.
  3. Review the sampled logs. For each event, check:
  1. សូមចុច Events ។
  2. ប្រើកញ្ចក់ Add filter ដើម្បីកាត់បន្ថយផលិតផលដល់ការដឹកជញ្ជូន endpoint របស់អ្នក form ។
  3. សូមពិនិត្យមើលដំណាក់កាល sampled ។ ក្នុងការធ្វើការទាំងអស់, សូមពិនិត្យឡើងវិញ:
Action taken: Cho dù yêu cầu đã bị chặn, thách thức, hoặc cho phép Source: Quy tắc hoặc tính năng kích hoạt action IP address: Cho dù một IP duy nhất đang tạo ra nhiều sự kiện URI path: Cho dù yêu cầu nhắm mục tiêu các điểm cuối của bạn form cụ thể
Action taken: Whether the request was blocked, challenged, or allowed Source: The rule or feature that triggered the action IP address: Whether a single IP is generating many events URI path: Whether requests target your form endpoints specifically
Action taken: ប្រសិនបើតម្រូវការនេះត្រូវបានកាត់បន្ថយឬអនុញ្ញាត Source: គោលការណ៍ឬលក្ខណៈដែលធ្វើឱ្យ action IP address: ប្រសិនបើតម្រូវការមួយ IP ត្រូវបានបង្កើតកម្មវិធីជាច្រើន URI path: ប្រសិនបើតម្រូវការនេះមានតម្រូវការតម្រូវការ form របស់អ្នក។
Nếu người dùng hợp pháp đang bị thách thức, hãy thu hẹp biểu thức quy tắc hoặc chuyển sang action ít hung hăng hơn.
If legitimate users are being challenged, narrow the rule expression or switch to a less aggressive action.
ប្រសិនបើអ្នកប្រើដែលមានលក្ខខណ្ឌត្រឹមត្រូវត្រូវបានគេចាត់បន្ថយការបង្ហាញច្បាប់ឬផ្លាស់ប្តូរទៅ action ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Thiết lập cảnh báo sự kiện bảo mật Set up security event alerts ទាញយកប្រព័ន្ធប្រតិបត្តិការ Security Event Alerts

Cấu hình a notification to receive alerts when there is an unusual spike in security events on your domain.

Read the "Set up security event alerts" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ទាញយកប្រព័ន្ធប្រតិបត្តិការ Security Event Alerts» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Thiết lập thông báo để nhận cảnh báo khi có sự gia tăng bất thường trong các sự kiện bảo mật trên tên miền của bạn.
Configure a notification to receive alerts when there is an unusual spike in security events on your domain.
ទាញយកការបញ្ជាក់ដើម្បីទទួលបានការបញ្ជាក់នៅពេលដែលមានកម្រិតខ្ពស់នៃការសុវត្ថិភាពនៅលើតំបន់របស់អ្នក។
Đối với các loại cảnh báo, ngưỡng kích hoạt và hướng dẫn thiết lập, hãy tham khảo Alerts for security events.
For alert types, trigger thresholds, and setup instructions, refer to Alerts for security events.
ប្រសិនបើអ្នកមានប្រភេទអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរអក្សរ Alerts for security events ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Chuyển sang giám sát tài nguyên phía khách hàng Turn on client-side resource monitoring ការត្រួតពិនិត្យសេវាកម្មរបស់អតិថិជន

Phần «Turn on client-side resource monitoring» — đọc hướng dẫn bên dưới, dùng liên kết docs gốc để xem ảnh minh họa và tab cấu hình đầy đủ.

Read the "Turn on client-side resource monitoring" section below — open the official docs link for full screenshots and configuration tabs.

អានផ្នែក «ការត្រួតពិនិត្យសេវាកម្មរបស់អតិថិជន» ខាងក្រោម — បើកតំណ docs ផ្លូវការសម្រាប់រូបភាព និង tab កំណត់។

Mở section docs gốc ↗ Open source section ↗ បើកផ្នែក docs ផ្លូវការ ↗
Nếu một kịch bản của bên thứ ba được tiêm vào trang form của bạn, nó có thể lọc dữ liệu đã gửi, bao gồm thông tin thanh toán. Client-Side Security giám sát các kịch bản của bên thứ ba trên pages của bạn cho các thay đổi và các cuộc tấn công chuỗi cung ứng tiềm năng.
If a third-party script is injected into your form page, it can exfiltrate submitted data, including payment information. Client-Side Security monitors third-party scripts on your pages for changes and potential supply chain attacks.
ប្រសិនបើប្រព័ន្ធប្រតិបត្តិការផ្សេងទៀតត្រូវបានដំឡើងនៅក្នុងទំព័រ form របស់អ្នកវាអាចបញ្ចូលទិន្នន័យដែលបានបញ្ជូនរួមទាំងទិន្នន័យការទូទាត់។ Client-Side Security អនុញ្ញាតឱ្យអ្នកត្រួតពិនិត្យប្រព័ន្ធប្រតិបត្តិការរបស់អ្នកនៅលើ pages របស់អ្នកសម្រាប់ការផ្លាស់ប្តូរនិងការសាកល្បងប្រព័ន្ធផ្គត់ផ្គង់។
Để cho phép giám sát:
To enable monitoring:
ដើម្បីអនុញ្ញាតការត្រួតពិនិត្យ:
  1. Trong bảng điều khiển Cloudflare, đi đến trang Security Settings.
  1. In the Cloudflare dashboard, go to the Security Settings page.
  1. ក្នុងប្រព័ន្ធប្រតិបត្តិការ Cloudflare សូមចូលទៅក្នុងទំព័រ Security Settings ។
  1. (Tùy chọn) Filter by Client-side abuse.
  2. Nhấp vào Continuous script monitoring
  1. (Optional) Filter by Client-side abuse.
  2. Turn on Continuous script monitoring.
  1. (តម្រូវការ) Filter by Client-side abuse.
  2. សូមចុច Continuous script monitoring ។
Sau khi kích hoạt, hãy xem lại các kịch bản được phát hiện trên trang Web assets dưới tab Client-side resources để xác định bất kỳ kịch bản bất ngờ nào trên form pages của bạn. Để biết dòng công việc cài đặt đầy đủ, hãy tham khảo Get started with client-side security.
After enabling, review detected scripts on the Web assets page under the Client-side resources tab to identify any unexpected scripts on your form pages. For the full setup workflow, refer to Get started with client-side security.
បន្ទាប់ពីអនុញ្ញាតឱ្យធ្វើឱ្យប្រសើរឡើង, សូមពិនិត្យមើលប្រព័ន្ធប្រតិបត្តិការដែលបានរកឃើញនៅលើទំព័រ Web assets នៅក្រោមប្រព័ន្ធប្រតិបត្តិការ Client-side resources ដើម្បីរកឃើញប្រព័ន្ធប្រតិបត្តិការដែលមិនគិតថ្លៃនៅលើប្រព័ន្ធប្រតិបត្តិការ form pages របស់អ្នក។ សម្រាប់ដំណើរការដំឡើងពេញលេញសូមមើល Get started with client-side security ។

Liên kết liên quan (docs Cloudflare) Related links (Cloudflare docs) តំណពាក់ព័ន្ធ (docs Cloudflare)

Xem bản đầy đủ trên developers.cloudflare.com (ảnh, tab cấu hình). View the full guide on developers.cloudflare.com (images, config tabs). មើលមគ្គុទ្ទេសក៍ពេញលើ developers.cloudflare.com (រូបភាព, tab កំណត់)។

Tài liệu gốc ↗ Official docs ↗ ឯកសារផ្លូវការ ↗