Hello, Recently we had a user whos Android app was fetching 2 files from users account. While CL show absolutely no load, the user had 1000+ connections to web server from DIFFERENT IPs. As it is not DDoS attack not CSF nor mod_evasive were triggered. Would be good to limit such connections, because a single user was able to crash Apache many times... Thank you