Cloudflare WAF Rule Builder
Build Cloudflare WAF custom rule expressions for bot blocking, geo blocking, and security — copy the expression or export it as JSON.
Advertisement
Important — Use at Your Own Risk
This tool generates configuration for reference and learning purposes only.
Before applying any generated config to a production server:
- Test in a staging/development environment first
- Understand each option before applying
- Take a full backup of existing configuration
- Verify compatibility with your OS version
- Wrong security settings can lock you out of your server
SysAdmin Tools is not responsible for server outages, data loss or security issues caused by applying generated configurations.
Rule Name: My Custom Rule
Action: Block (returns 403)
(lower(http.user_agent) contains "scrapy")
How to apply
Cloudflare Dashboard → Security → WAF → Custom Rules → Create Rule
Paste the expression into the Edit Expression box
Set Action to Block (returns 403)
Save and Deploy
Advertisement
Advertisement
This Cloudflare WAF rule builder generates the exact firewall rule expression you paste into Cloudflare's Custom Rules editor. Combine conditions on IP, country, ASN, user agent, URI path, HTTP method, referrer, headers and hostname with AND/OR logic, pick an action, and copy a valid expression — no need to memorise Cloudflare's expression syntax.
Cloudflare's WAF (Web Application Firewall) custom rules use a wire-filter expression language like (ip.geoip.country eq "CN") or (lower(http.user_agent) contains "scrapy"). Writing these by hand is error-prone. This Cloudflare custom firewall rule generator gives you quick presets — block bad bots, block a country, rate-limit an API path, block scanners, allow only your IP, protect wp-admin — and a visual condition builder for anything custom.
Everything is generated in your browser. Copy the expression or export it as JSON, then paste it into Security → WAF → Custom Rules in the Cloudflare dashboard and choose your action (Block, Managed Challenge, JS Challenge, Allow or Skip).
How to Use the Cloudflare WAF Rule Builder
- 1
Start from a preset (optional)
Click a preset like Block Bad Bots, Block Country or Block wp-admin to pre-fill the conditions, or choose Custom to build from scratch.
- 2
Add and configure conditions
Add one or more condition rows. For each, pick a field (IP, Country, User Agent, URI Path, ASN, method and more), an operator (equals, contains, matches, is in…), and a value.
- 3
Combine with AND / OR
Choose whether all conditions must match (AND) or any condition matches (OR). The builder wraps the expression correctly for Cloudflare.
- 4
Pick an action
Select Block, Managed Challenge, JS Challenge, Challenge (CAPTCHA), Allow or Skip — the action Cloudflare takes when the expression matches.
- 5
Copy and deploy
Copy the expression (or the JSON), open Cloudflare → Security → WAF → Custom Rules → Create Rule, paste it into Edit Expression, set the action, then Save and Deploy.
Understanding Cloudflare WAF Expressions
ip.src, ip.geoip.country, http.user_agent or http.request.uri.path), operators (eq, contains, matches, in, ne…), and values in quotes or braces.
Multiple conditions are joined with logical and / or and grouped with parentheses. For case-insensitive text matching, Cloudflare's convention is to wrap the field in lower() and compare against a lowercase value, e.g. lower(http.user_agent) contains "curl". Set membership uses braces: ip.geoip.country in {"CN" "RU"}. The matches operator takes a regular expression.
The action determines the response. Block returns a 403; Managed Challenge lets Cloudflare decide the friction; JS Challenge and Challenge (Interactive/CAPTCHA) verify the visitor; Allow (Skip) lets the request bypass remaining rules. Rules run in order, so an Allow/Skip rule placed above stricter rules can whitelist trusted traffic.| Field | Description |
|---|---|
| ip.src | The client IP address, e.g. ip.src eq 203.0.113.5. |
| ip.geoip.country | Two-letter country code of the client, e.g. ip.geoip.country eq "US". |
| ip.src.asnum | The autonomous system number the request originates from. |
| http.user_agent | The User-Agent header; often wrapped in lower() for case-insensitive bot matching. |
| http.request.uri.path | The URL path, e.g. starts_with for /wp-admin or /api. |
| http.request.method | The HTTP method such as GET, POST, PUT or DELETE. |
| http.host | The requested hostname, useful for multi-domain zones. |
| and / or | Logical operators that join conditions; parentheses group them. |
| Action | What Cloudflare does on a match: Block, Managed Challenge, JS Challenge, Challenge, Allow or Skip. |
Advertisement
Common Cloudflare WAF Rule Use Cases
Block scrapers and bad bots
Match known bad user agents (scrapy, wget, curl, python-requests) with lower() and contains, then Block or Managed Challenge them to cut automated scraping and content theft.
Geo-block or challenge countries
Use ip.geoip.country with the in operator to block or challenge traffic from regions you do not serve, reducing attack noise and fraud.
Protect admin and login paths
Challenge or restrict /wp-admin, /wp-login.php or custom admin paths so only trusted IPs can reach them, blunting brute-force and credential-stuffing attempts.
Allow only your IP to sensitive areas
Build an Allow/Skip rule for ip.src eq YOUR_IP on an admin path, combined with a Block rule for everyone else, to lock down staging or admin endpoints.
Cloudflare WAF Rule Builder — Frequently Asked Questions
What is Cloudflare WAF?
How to create a custom Cloudflare WAF rule?
What is Cloudflare WAF expression syntax?
How to block a country in Cloudflare?
How to block bad bots with Cloudflare WAF?
What is the difference between Block and Challenge in Cloudflare?
How to block an IP address in Cloudflare?
What is a managed challenge in Cloudflare?
How many WAF rules can I have in Cloudflare?
How to test a Cloudflare WAF rule?
Can I import the generated expression as JSON?
Related Tools
Security Headers
Audit the HTTP security headers your site returns behind Cloudflare.
Fail2ban Generator
Add origin-server banning to complement edge WAF rules.
IP Location
Look up the country and ASN of an IP before writing a geo or ASN rule.
Redirect Checker
Confirm how requests resolve through Cloudflare to your origin.