jmeter and Cloudflare : 1020 error ; works with Postman

Viewed 2438

New to Jmeter so I am not sure if my set-up is correct.

Basically I have these set of API's that I need to Perf test. Starting with a setting up a basic connection from Jmeter - I am receiving 1020 error from cloudflare

Access denied | "domain" used Cloudflare to restrict access and <div class="cf-alert cf-alert-error cf-cookie-error hidden" id="cookie-alert" data-translate="enable_cookies">Please enable cookies.</div>

It works with POSTMAN. So wondering what changes I'll need in jmeter. I have enabled save cookie in jmeter.properties file

API is for logging into a portal: verified username/password. VPN connection verified as this works from postman.

2 Answers

If you're absolutely sure that the request works in postman (although I'm getting this 1020 error even with the real browser) you should be able to get the same behavior in JMeter as well, just make sure to send the identical request (pay attention to HTTP Headers as well)

The easiest is just recording your Postman request using JMeter's HTTP(S) Test Script Recorder, just configure Postman to use JMeter as the proxy enter image description here

and run your request - JMeter will generate appropriate HTTP Request sampler and HTTP Header Manager

If you need to use VPN for proper access you might need to configure source IP address at the "Advanced" tab of the HTTP Request sampler like it's described in Using IP Spoofing to Simulate Requests from Different IP Addresses with JMeter article

enter image description here

In any case load testing an API behind Cloudflare might be not the best idea as Cloudflare provides DDoS protection and may (and will) block this type of traffic so you need to either whitelist your IP address(es) or let them know about your load testing activities, I believe they will be able to suggest a better workaround than anyone here

This is related with the securities features of CloudFare, either DDos protection or bot blocking. Exceptions can be configured from the CloudFare control panel.

If you don't have access to this panel you'll have to ask the corresponding person inside your company tasked with this job.

Related