> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/using-link11/how-do-i.../minimize-false-positives.md).

# Minimize False Positives

To minimize the blocking of legitimate traffic, do the following.

* During the initial setup of Zero Touch WAF, ensure that it is run for at least 24 hours in observation mode, so that it correctly learns traffic patterns.
* For each instance of Web DDoS, set the [Instances / General Settings / Default Policy for Bad Bots](/product-guides/web-ddos/interface/instances/general-settings.md#default-policy-for-bad-bots) to Captcha. (This ensures that if any human clients are misidentified as bad bots, they will receive a captcha challenge instead of automatically being blocked.)
* For each instance of Web DDoS, enable [Instances / DDoS Mitigation / CAPTCHA Defense](/product-guides/web-ddos/interface/instances/ddos-mitigation.md#captcha-defense) (which will subject suspicious IPs to captcha challenges).

When False Positives appear to be occurring:

* You can add the path in question to the [Web DDoS / Captcha URL](/product-guides/web-ddos/interface/captcha-url-list.md) list. This will apply captcha challenges to all visitors to that path (thus giving human clients the opportunity to pass the challenge).
* If Zero Touch WAF is causing a False Positive. check the WAF Logs to see which WAF Rule is causing the problem. To disable that rule, go to [Web DDoS / WAF Rules](/product-guides/web-ddos/interface/waf-rules.md).
