Cloudflare Docs
Visit WAF on GitHub
Set theme to dark (⇧+D)

Cloudflare Web Application Firewall

The Cloudflare Web Application Firewall (WAF) provides both automatic protection from vulnerabilities and the flexibility to create custom rules.

Learn more WAF Managed Rulesets Managed Rulesets changelog

​​ Main features

  • Custom rules: Create your own custom rules to protect your website and your APIs from malicious incoming traffic.
  • Rate limiting rules: Define rate limits for incoming requests matching an expression, and the action to take when those rate limits are reached.
  • WAF Managed Rulesets: Enable the pre-configured Managed Rulesets to get immediate protection. These rulesets are regularly updated, offering advanced zero-day vulnerability protections. Adjust the behavior of managed rules, choosing from several possible actions.
  • Exposed Credential Checks: Monitor and block use of stolen/exposed credentials for account takeover.
  • Security Events: Identify and investigate security threats using an intuitive interface. Tailor your security configurations based on the activity log.

​​ Availability

The new Cloudflare WAF announced in March 2021 is available on all plans. The exact features and limits depend on your current plan.

For more information on the previous WAF implementation, also known as WAF managed rules, refer to Understanding WAF managed rules in the Support KB.

For more information on firewall rules, refer to Cloudflare Firewall Rules.