Create custom rules in the dashboard
Create custom rules in Security > WAF > Custom rules.
Create a custom rule
To create a new custom rule:
Log in to the Cloudflare dashboard.
Select the Websites tab and choose the site for which you want to create a rule.
Navigate to Security > WAF > Custom rules.
Select Create custom rule.
Enter a descriptive name for the rule in Rule name.
Under If incoming requests match…, use the Field drop-down list to choose an HTTP property. For each request, the value of the property you choose for Field is compared to the value you specify for Value using the operator selected in Operator.
Select the rule action from the Choose action drop-down list. For example, selecting Block tells Cloudflare to refuse requests that match the conditions you specified.
To save and deploy your rule, select Save and Deploy. If you are not ready to deploy your rule, select Save as Draft.
Configuring a custom response for blocked requests
When you select the Block action in a custom rule you can optionally define a custom response.
The custom response has three settings:
Response type: Choose a content type or the default WAF block response from the list. The available custom response types are the following:
Dashboard value API value Custom HTML
Response code: Choose an HTTP status code for the response, in the range 400-499. The default response code is 403.
Response body: The body of the response. Configure a valid body according to the response type you selected.