
Open
Posted
•
Ends in 1 hour
Paid on delivery
We operate a portfolio of five high-traffic real estate websites and need to evaluate and execute a migration from Imperva App Protect Professional to Cloudflare. We used Cloudflare Pro successfully for 10+ years before bot-driven performance issues pushed us to Imperva. Imperva's Core tier didn't resolve the issues; the upgrade to App Protect Professional stabilized our servers. We're now evaluating a return to Cloudflare for cost and operational reasons. This engagement is framed in two phases: Phase 1 — Evaluation (paid, fixed fee): Determine whether Cloudflare can credibly match our current Imperva protection for our specific traffic profile, and at what plan tier. If the honest answer is "no" or "only at Enterprise + Bot Management at $X," we want to know before we cancel Imperva, not after. Phase 2 — Migration (contingent on Phase 1): Execute the staged cutover, validate stability, and decommission Imperva. The core challenge is bots, not WAF basics. Anyone confident only on managed-ruleset / OWASP-style WAF work is not the right fit. We need someone who has defended public-facing data-heavy sites against persistent scraper and AI crawler traffic. Current State - WAF/CDN: Imperva App Protect Professional (20 Mbps / 20M req/mo), managed through a local MSP - 5 production sites in scope (details shared with shortlisted candidates under NDA) - Origin: Rackspace OSFC- Linux / Apache - Historical pressure: aggressive scrapers and AI crawlers; pre-Imperva we experienced server lockups Phase 1 Scope — Evaluation & Design (~1–2 weeks) 1. Audit current Imperva configuration across all 5 sites: custom rules (IncapRules), IP access control, rate limiting, bot access control, exceptions, cache rules 2. Pull and analyze 30 days of Imperva security event data — what is Imperva actually blocking, and what would Cloudflare need to replicate? 3. Baseline traffic profile per site: volume, bot/human split, top offending ASNs/UAs, geographic patterns 4. Recommend Cloudflare plan tier with explicit reasoning. We want a direct answer on whether Business is sufficient or whether Enterprise + Bot Management is required for our profile. Include pricing comparison vs current Imperva spend. 5. Audit origin exposure: are origin IPs leaked? What's the lockdown plan? How does it interact with server side modules/fail2ban(if applicable) 6. Go/no-go recommendation with risks documented Phase 1 Deliverable: Written report + 60-minute review call. If the recommendation is "stay on Imperva" or "Cloudflare can work but only at Enterprise tier — here's the cost," that is a valid and welcome outcome. Phase 2 Scope — Migration (contingent, ~3–4 weeks) 1. Build Cloudflare configuration to match the agreed design 2. Staged cutover: lowest-risk site first, then remaining four in sequence 3. Run Imperva and Cloudflare in parallel where feasible for direct comparison 4. Defined rollback criteria and procedure per site 5. Post-cutover stabilization window: monitor bot traffic, origin load, false positives; tune rules 6. Origin IP rotation and apache level lockdown to Cloudflare IP ranges 7. Clean Imperva offboarding only after stability is proven across all 5 sites 8. Documentation and knowledge transfer for our internal team Required Skills - Hands-on production migrations between enterprise WAFs (Imperva ↔ Cloudflare strongly preferred) - Deep Cloudflare expertise: WAF custom rules, Rate Limiting, Bot Management vs Super Bot Fight Mode tradeoffs, Rulesets engine, Transform Rules, cache configuration - Strong Imperva Cloud WAF admin: able to read and export an existing config, including IncapRules - Apache + Linux administration; real-client-IP handling behind a reverse proxy - Documented experience defending sites against scraper and AI crawler traffic at scale Nice to Have -Experience with real estate, classifieds, or other data-heavy public sites that are scraping targets -DNS migration experience with zero-downtime cutovers Engagement - Milestone-based fixed price preferred, broken out by phase - Phase 1 starts immediately upon selection - Phase 2 cutover targeted within 4–6 weeks of Phase 1 completion - Budget: open to proposals — please break out Phase 1 and Phase 2 separately To Apply In your proposal, please include: 1. A specific past project migrating between enterprise WAFs — with the bot mitigation outcome quantified (block rates, origin load reduction, etc.) 2. Your view on whether Cloudflare Business + Super Bot Fight Mode can match Imperva App Protect Professional for a real-estate-data property dealing with persistent scrapers, or whether Enterprise + Bot Management is required — and why 3. The single biggest risk you see in this migration and how you'd mitigate it 4. Your availability to start Phase 1 within the next 7 days Boilerplate / AI-generated proposals will be ignored. Shortlisted candidates will receive site details under NDA.
Project ID: 40470918
28 proposals
Open for bidding
Remote project
Active 24 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
28 freelancers are bidding on average $4,593 USD for this job

Hi, I understand this is not a basic WAF switch. The main goal is to confirm if Cloudflare can really handle your current bot and scraper load across 5 real estate sites before you cancel Imperva. I can review the Imperva setup, IncapRules, rate limits, bot controls, cache rules, 30 days of events, origin exposure, and traffic patterns, then give a clear go/no-go report with the right Cloudflare tier. My view is that Cloudflare Business with Super Bot Fight Mode may work for lighter noise, but for persistent scrapers and AI crawlers on data-heavy public sites, Enterprise with Bot Management is often the safer match because of stronger bot scoring, detection, and rule control. The biggest risk is under-blocking after cutover and pushing load back to Apache, so I would use staged rollout, parallel checks where possible, strict rollback points, origin lockdown to Cloudflare IPs, real IP handling, and rule tuning after each site. I can start Phase 1 within 7 days and keep Phase 1 and Phase 2 priced as separate milestones. Can you share whether Imperva logs can be exported with full security events, bot labels, rule IDs, source ASN/IP, URI, user agent, and action for the last 30 days? Do you already have a Cloudflare Enterprise quote, or should plan and cost comparison include direct Cloudflare sales input? Are the current origin IPs known publicly, and are you open to rotating them during Phase 2? Do all 5 sites share the same Apache stack and app behavior, or are there majo
$6,500 USD in 14 days
6.8
6.8

As an IT specialist with widespread experience across Cloudflare and Imperva platforms, I believe I'm the perfect fit for your WAF migration project. I have hands-on expertise in deploying and maintaining complex systems such as AWS, Amazon Web Services, Microsoft AZURE, Google Cloud (GCP), strengthening sites against bot traffic and scraper attacks - which have been consistent challenges for your real-estate sites. This experience is bolstered by deep knowledge of WAF custom rules, Rate Limiting, Bot Management vs Super Bot Fight Mode tradeoffs, Rulesets engine, Transform Rules and cache configuration on Cloudflare.
$3,000 USD in 1 day
6.9
6.9

With a deep and varied background in internet security, network security, and web security, I offer a rare blend of skills that are perfect for your WAF migration project. Not only do I have extensive experience with enterprise migrations between WAF platforms like Imperva and Cloudflare, but I also possess a comprehensive understanding of both systems – honed from years of working on complex projects like yours. Additionally, given my background and certifications, I bring a unique ability to think like an attacker when it comes to fortifying an IT infrastructure against formidable threats. Choose me, Constantin is not just meant to be an assurance through certification acronyms ', but rather represents my proven track record and ability to solve complexity - beyond automated scans or fixes done just enough for the report. Let me leverage my considerable skills, deep industry knowledge and my passion to protect businesses from breaches to ensure a seamless transition from Imperva to Cloudflare for your high-traffic real estate websites. Invest in the best. Safeguard these properties explicitly. Choose me, Constantin!
$6,000 USD in 90 days
5.5
5.5

Hi there, I will audit your Imperva App Protect Professional configs across all 5 sites, analyze 30 days of security event data, and deliver a go/no-go report with a clear Cloudflare tier recommendation — then execute the staged migration if Phase 1 supports it. On the Business vs Enterprise question — Super Bot Fight Mode lacks the granular bot scoring and custom detection rules needed for persistent real estate scrapers. For data-heavy listing sites, Enterprise + Bot Management is almost certainly required to match Imperva's behavioral detection. I will confirm this against your actual traffic data rather than assumptions. The biggest risk: origin IP exposure during cutover. Scrapers that already know your Rackspace IPs will bypass Cloudflare entirely. Ready to start whenever you are. Kamran
$2,805 USD in 30 days
4.1
4.1

Hey there, I’ve carefully reviewed your complex needs for migrating five high-traffic real estate websites from Imperva App Protect Professional back to Cloudflare, and I’m ready to tackle the bot beast head-on with you. Having successfully led enterprise WAF migrations between Imperva and Cloudflare, including rigorous bot mitigation strategies, I’ve helped clients reduce bot traffic by over 70% and significantly ease origin server load. Cloudflare Business + Super Bot Fight Mode is solid for many, but for your persistent, aggressive scrapers and AI crawlers targeting data-heavy real estate sites, my experience suggests the Enterprise tier with Bot Management is critical to match what Imperva currently delivers, especially to avoid false negatives and operational instability. I’ll deliver a detailed Phase 1 evaluation report with a clear plan and cost comparison so you can decide confidently. I’m available to start Phase 1 immediately and can wrap it within 1-2 weeks. From there, we’ll jump into a low-risk, staged Phase 2 migration ensuring stability and smooth cutover. Let’s connect soon, and I’d love to hear about the specific traffic anomalies you’ve seen that concern you most. What specific bot behaviors or patterns have caused the most significant disruptions on your sites recently? Best regards,
$4,995 USD in 12 days
2.4
2.4

Edgewater, United States
Payment method verified
Member since Jan 24, 2025
$3000-5000 USD
$3000-5000 USD
$4000-10000 USD
$25-50 USD / hour
$10-30 USD
$500-600 USD
$250-750 USD
$250-750 USD
₹750-1250 INR / hour
₹37500-75000 INR
$10-30 USD
₹600-1500 INR
$2500-6500 USD
$15-25 USD / hour
$15-25 AUD / hour
₹1500-12500 INR
₹12500-37500 INR
$15-25 USD / hour
₹12500-37500 INR
$15-25 USD / hour
$10-30 USD
$15-25 USD / hour
$12-30 SGD
$30-250 USD