Cloudflare Sentinel
Block the bad actors at the Cloudflare edge, automatically.
Lavawall® Cloudflare Sentinel automatically blocks the bad actors probing your sites (vulnerability scanners, 404 floods, and attackers tripping your firewall) right at the Cloudflare edge, across every site you manage. It runs on the Cloudflare Free plan, and it is designed so it won't lock you out.
Start free, no credit card What is included
Edge blocking · every site at once · watch-only mode · runs on Cloudflare Free
Stop the noise. Block the threats. Keep your people in.
Every public site is under constant automated assault. Scanners map your pages looking for a weakness, floods of 404 requests probe for hidden paths, and attackers hammer at your firewall rules. Most of it never reaches a human, but it is real risk and real load. Cloudflare Sentinel handles it at the edge, before it touches your origin.
- Blocks vulnerability scanners and reconnaissance.
- Blocks 404 floods probing for hidden paths.
- Blocks attackers triggering your Cloudflare firewall.
- Works across all of your sites at the same time.
- Runs on the Cloudflare Free plan.
Designed not to lock you out
Automatic blocking is only safe if it knows who not to block. Sentinel protects your own infrastructure automatically, recognizes your office scanners and tools, and protects private and internal addresses, and you can add anything else to a manual allowlist. The allowlist is not an afterthought, it is what makes automatic blocking safe to leave running.

Watch first, block when you are ready
A watch-only dry-run mode shows exactly who Sentinel would block, without blocking anyone. Confirm the behaviour on your own sites, then turn enforcement on with confidence.
It cleans up after itself
Blocks expire automatically, stale entries are cleaned up, active threats are prioritized, and it stays within Cloudflare limits, with bulk cleanup tools when you want them.
Built for the way you actually work
Multi-tenant by design, with per-site management and sensitivity tuning, so you can be aggressive on one site and cautious on another.
The outcomes
Less automated noise reaching your origin, fewer scanners and floods to investigate, protection across every site at once, and no risk of blocking yourself.
What is included
- Blocking of vulnerability scanners, 404 floods, and firewall-tripping attackers at the Cloudflare edge.
- Allowlisting that protects your infrastructure automatically, recognizes your own scanners and tools, protects internal addresses, and accepts manual entries.
- Watch-only mode to preview blocking before you enforce it.
- Blocklist management with automatic expiry, stale-entry cleanup, threat prioritization, Cloudflare-limit awareness, and bulk cleanup.
- Multi-tenant control with per-site management and sensitivity tuning across every site you manage.
Frequently asked questions
- Will it ever lock me out?
- No. Sentinel protects your own infrastructure automatically, recognizes your office scanners and tools, and protects private and internal addresses, and you can add anything else to a manual allowlist. The allowlist is the core of the design.
- Can I try it without blocking anyone first?
- Yes. A watch-only dry-run mode lets you see exactly who Sentinel would block, without blocking anyone, so you can confirm the behaviour before you turn enforcement on.
- Does it work across all my sites at once?
- Yes. Sentinel is multi-tenant and works across every site you manage at the same time, with per-site management and sensitivity tuning.
- Will the blocklist fill up or hit Cloudflare limits?
- No. Blocks expire automatically, stale entries are cleaned up, active threats are prioritized, and it stays within Cloudflare limits, with bulk cleanup tools when you want them.
- Does it need a paid Cloudflare plan?
- No. Cloudflare Sentinel runs on the Cloudflare Free plan.