> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.faaaster.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# How does the "Under Attack" protection work on Faaaster?

The "Under Attack" protection, in the site's **Security** tab (**Anti-bot protection** card), challenges visitors when your site is under attack. In **Automatic** mode, the recommended setting, it triggers and releases on its own, protecting the attacked address first.

It's set on the production environment and monitors the pressure your site is actually under, not just the volume of traffic.

## The modes

| Mode | What it does |
| --- | --- |
| **Disabled** | No monitoring. |
| **Automatic** | Faaaster triggers the protection when the pressure warrants it, and releases it as soon as things are back to normal. **The recommended setting.** |
| **Forced** | The challenge applies to the whole site, regardless of the pressure, until the mode is changed again. The interface asks for confirmation: "Force global protection?". Keep it for an ongoing attack. |

A fourth mode, **Observe**, is reserved for the Faaaster team: if it's active on your site, the selector shows **Operator mode active**.

## What triggers it

Faaaster doesn't rely on traffic volume, but on how much the site is struggling:

- **slow PHP response**;
- **PHP 502 error** or **504**;
- **persistent pressure** — CPU load and PHP-FPM queue persistently high.

The protection releases on its own at the **pressure returned to normal** signal.

## Targeted before global

In automatic mode, Faaaster starts with **targeted** protection on the most requested paths — the URL actually under attack — and only widens it to **global** if that isn't enough.

> **This is what sets it apart from a blunt block.** Your legitimate visitors keep browsing normally while a single URL is protected.

## "Image not compatible with this protection"

This message means your site's server environment is too old to support this protection. Update it from the **Server** tab, **Server environment** row, then come back to this setting.

👉 [What security protections does Faaaster offer?](https://help.faaaster.io/en-us/article/security-protections-114vcpv/) · [My site is slow](https://help.faaaster.io/en-us/article/my-site-is-slow-1ng4uql/)