SysAdmin Tools

Cloudflare WAF Rule Builder

Build Cloudflare WAF custom rule expressions for bot blocking, geo blocking, and security — copy the expression or export it as JSON.


Advertisement

Important — Use at Your Own Risk

This tool generates configuration for reference and learning purposes only.

Before applying any generated config to a production server:

  • Test in a staging/development environment first
  • Understand each option before applying
  • Take a full backup of existing configuration
  • Verify compatibility with your OS version
  • Wrong security settings can lock you out of your server

SysAdmin Tools is not responsible for server outages, data loss or security issues caused by applying generated configurations.

1. Rule Purpose (presets)
2. Conditions
Matchof the conditions
3. Action
4. Rule Name

Rule Name: My Custom Rule

Action: Block (returns 403)

Expression
(lower(http.user_agent) contains "scrapy")

How to apply

Cloudflare Dashboard → Security → WAF → Custom Rules → Create Rule

Paste the expression into the Edit Expression box

Set Action to Block (returns 403)

Save and Deploy

Advertisement

Advertisement

This Cloudflare WAF rule builder generates the exact firewall rule expression you paste into Cloudflare's Custom Rules editor. Combine conditions on IP, country, ASN, user agent, URI path, HTTP method, referrer, headers and hostname with AND/OR logic, pick an action, and copy a valid expression — no need to memorise Cloudflare's expression syntax.

Cloudflare's WAF (Web Application Firewall) custom rules use a wire-filter expression language like (ip.geoip.country eq "CN") or (lower(http.user_agent) contains "scrapy"). Writing these by hand is error-prone. This Cloudflare custom firewall rule generator gives you quick presets — block bad bots, block a country, rate-limit an API path, block scanners, allow only your IP, protect wp-admin — and a visual condition builder for anything custom.

Everything is generated in your browser. Copy the expression or export it as JSON, then paste it into Security → WAF → Custom Rules in the Cloudflare dashboard and choose your action (Block, Managed Challenge, JS Challenge, Allow or Skip).

How to Use the Cloudflare WAF Rule Builder

  1. 1

    Start from a preset (optional)

    Click a preset like Block Bad Bots, Block Country or Block wp-admin to pre-fill the conditions, or choose Custom to build from scratch.

  2. 2

    Add and configure conditions

    Add one or more condition rows. For each, pick a field (IP, Country, User Agent, URI Path, ASN, method and more), an operator (equals, contains, matches, is in…), and a value.

  3. 3

    Combine with AND / OR

    Choose whether all conditions must match (AND) or any condition matches (OR). The builder wraps the expression correctly for Cloudflare.

  4. 4

    Pick an action

    Select Block, Managed Challenge, JS Challenge, Challenge (CAPTCHA), Allow or Skip — the action Cloudflare takes when the expression matches.

  5. 5

    Copy and deploy

    Copy the expression (or the JSON), open Cloudflare → Security → WAF → Custom Rules → Create Rule, paste it into Edit Expression, set the action, then Save and Deploy.

Understanding Cloudflare WAF Expressions

A Cloudflare custom rule is an expression plus an action. The expression is evaluated for every request; if it returns true, the action runs. Expressions are built from fields (request attributes such as ip.src, ip.geoip.country, http.user_agent or http.request.uri.path), operators (eq, contains, matches, in, ne…), and values in quotes or braces. Multiple conditions are joined with logical and / or and grouped with parentheses. For case-insensitive text matching, Cloudflare's convention is to wrap the field in lower() and compare against a lowercase value, e.g. lower(http.user_agent) contains "curl". Set membership uses braces: ip.geoip.country in {"CN" "RU"}. The matches operator takes a regular expression. The action determines the response. Block returns a 403; Managed Challenge lets Cloudflare decide the friction; JS Challenge and Challenge (Interactive/CAPTCHA) verify the visitor; Allow (Skip) lets the request bypass remaining rules. Rules run in order, so an Allow/Skip rule placed above stricter rules can whitelist trusted traffic.
FieldDescription
ip.srcThe client IP address, e.g. ip.src eq 203.0.113.5.
ip.geoip.countryTwo-letter country code of the client, e.g. ip.geoip.country eq "US".
ip.src.asnumThe autonomous system number the request originates from.
http.user_agentThe User-Agent header; often wrapped in lower() for case-insensitive bot matching.
http.request.uri.pathThe URL path, e.g. starts_with for /wp-admin or /api.
http.request.methodThe HTTP method such as GET, POST, PUT or DELETE.
http.hostThe requested hostname, useful for multi-domain zones.
and / orLogical operators that join conditions; parentheses group them.
ActionWhat Cloudflare does on a match: Block, Managed Challenge, JS Challenge, Challenge, Allow or Skip.

Advertisement

Common Cloudflare WAF Rule Use Cases

Block scrapers and bad bots

Match known bad user agents (scrapy, wget, curl, python-requests) with lower() and contains, then Block or Managed Challenge them to cut automated scraping and content theft.

Geo-block or challenge countries

Use ip.geoip.country with the in operator to block or challenge traffic from regions you do not serve, reducing attack noise and fraud.

Protect admin and login paths

Challenge or restrict /wp-admin, /wp-login.php or custom admin paths so only trusted IPs can reach them, blunting brute-force and credential-stuffing attempts.

Allow only your IP to sensitive areas

Build an Allow/Skip rule for ip.src eq YOUR_IP on an admin path, combined with a Block rule for everyone else, to lock down staging or admin endpoints.

Cloudflare WAF Rule Builder — Frequently Asked Questions

What is Cloudflare WAF?
Cloudflare WAF (Web Application Firewall) inspects incoming HTTP requests at Cloudflare's edge and applies rules before traffic reaches your origin server. It includes managed rulesets (maintained by Cloudflare for known vulnerabilities and OWASP categories) and custom rules you write yourself. Custom rules use an expression language to match requests on attributes like IP, country, user agent and URL, then take an action such as Block or Challenge.
How to create a custom Cloudflare WAF rule?
In the Cloudflare dashboard, go to your domain → Security → WAF → Custom Rules → Create Rule. Give the rule a name, build an expression (either with the visual builder or by pasting one into Edit Expression), choose an action like Block or Managed Challenge, then Save and Deploy. This tool generates the expression for you so you can paste it straight into the Edit Expression box.
What is Cloudflare WAF expression syntax?
Cloudflare expressions use fields, operators and values — for example (http.request.uri.path contains "/admin" and ip.src ne 203.0.113.5). Fields describe the request (ip.src, ip.geoip.country, http.user_agent, http.request.uri.path, etc.), operators include eq, ne, contains, matches, in, and conditions are joined with and / or and grouped with parentheses. Text is quoted and set membership uses braces like {"CN" "RU"}.
How to block a country in Cloudflare?
Create a custom rule with an expression such as (ip.geoip.country in {"CN" "RU" "KP"}) and set the action to Block (or Managed Challenge if you want to allow legitimate users to pass). Deploy the rule. All requests whose source country matches one in the set will receive a 403 or a challenge. Use this builder's "Block Country" preset to generate the expression quickly.
How to block bad bots with Cloudflare WAF?
Match suspicious user agents case-insensitively, e.g. (lower(http.user_agent) contains "scrapy" or lower(http.user_agent) contains "python-requests" or lower(http.user_agent) contains "wget"), and set the action to Block or Managed Challenge. For broader coverage, combine this with Cloudflare's Bot Fight Mode and the cf.client.bot field. The "Block Bad Bots" preset in this tool gives you a starting expression.
What is the difference between Block and Challenge in Cloudflare?
Block immediately rejects the request with a 403 and the visitor cannot proceed. Challenge presents a verification step — an Interactive Challenge (CAPTCHA-like), a JS Challenge (runs a JavaScript check), or a Managed Challenge (Cloudflare automatically picks the lightest effective challenge). Challenges let genuine users through while stopping most bots, which is useful when a rule might catch some legitimate traffic. Block is best when you are certain the traffic is unwanted.
How to block an IP address in Cloudflare?
You can add a single IP under Security → WAF → Tools (IP Access Rules), or write a custom rule like (ip.src eq 203.0.113.5) with the Block action. To block a range, use CIDR notation with the in operator: (ip.src in {203.0.113.0/24}). Custom rules are more flexible because you can combine the IP with other conditions such as a specific path.
What is a managed challenge in Cloudflare?
A Managed Challenge is Cloudflare's recommended challenge action. Instead of always showing a CAPTCHA, Cloudflare dynamically chooses the most appropriate verification — which may be a non-interactive check, a JavaScript challenge, or an interactive challenge — based on the request's risk signals. This reduces friction for real users while still stopping automated traffic, and it adapts over time without you changing the rule.
How many WAF rules can I have in Cloudflare?
The number of custom rules depends on your Cloudflare plan. Free plans allow a small number of custom rules (typically up to 5), while Pro, Business and Enterprise plans allow progressively more. Rules are evaluated in order, so prioritise them carefully — place Allow/Skip rules for trusted traffic above your Block rules. Check your plan's current limits in the dashboard, as Cloudflare updates them over time.
How to test a Cloudflare WAF rule?
Before deploying broadly, set the action to Log (on plans that support it) to see what the expression would match without affecting traffic, or use a narrow condition such as your own test IP. After deploying, use Security → Events (the firewall activity log) to confirm the rule is matching the right requests, then widen or tighten the expression as needed. Always verify legitimate traffic is not being caught.
Can I import the generated expression as JSON?
Yes. This builder provides both a plain expression (to paste into the Edit Expression box) and a JSON object containing the rule name, action and expression. The JSON is convenient when working with the Cloudflare API or Terraform, where custom rules are defined programmatically. For the dashboard, copying just the expression and selecting the action manually is usually quickest.

Related Tools