A firewall rule blocked the request.
WHAT IT MEANS
One of your Cloudflare firewall rules matched the request and blocked it.
WHERE TO LOOK
Cloudflare's security events log. It shows the blocked request and names the rule responsible.
That identifies the cause in seconds.
THE COMMON CAUSES
A rule matching more broadly than intended A country block catching a legitimate visitor A rate limit triggered by normal use A rule blocking a path a service legitimately needs
THE PAYMENT GATEWAY CASE
A gateway sending a payment confirmation to your site is an automated request from an unfamiliar address.
A rule blocking it means payments succeed and orders stay unpaid.
Add a rule allowing requests to the callback path.
IF IT AFFECTS YOU
Your own address may be caught. Add an allow rule for it.
FIXING IT
Adjust the specific rule rather than removing protection generally.
TESTING AFTER ANY RULE CHANGE
From another network, and with a real transaction if it is a shop.
Rules are easy to write slightly too broadly.