Cloudflare WAF

Block the latest attacks with our industry-leading web application firewall (WAF)

The Cloudflare WAF uses threat intelligence and machine learning powered by platform intelligence from the Cloudflare connectivity cloud to stop the newest threats, including zero-days.

WAF - Hero image

Benefits of Cloudflare WAF

icon - internet globe
Global threat intelligence

The Cloudflare global network processes 126 million HTTP requests per second at peak, providing unparalleled protection against the latest attacks, including zero-day exploits.

Ddos ransom icon
Machine learning-based detection

The Cloudflare WAF uses machine learning to automatically block emerging threats in real time.

Performance wrench - Icon
Fast deployment and easy management

Customers can set up the WAF with just a few clicks, and our WAF integrates with the rest of our application security for full coverage. No training or professional services needed.

Icon Tile Cloudflare ruleset engine
Managed and custom rulesets

On top of OWASP rules, Cloudflare-managed rules offer fast zero-day protection, and custom rulesets enable organizations to tailor their WAF to implement organization-specific policies.

WAF content scanning - Image

How it works

The Cloudflare WAF runs on the Cloudflare global network and sits in front of web applications to stop a wide range of real-time attacks using powerful rulesets, advanced rate limiting, exposed credential checks, uploaded content scanning, and other security measures.

The WAF integrates with our analyst-recognized, industry-leading application security portfolio for comprehensive protection.

What our customers are saying

AI Crawl
State of Arizona - Logo

“With the Cloudflare platform, we're getting very high-powered, very technical [application security] detection and protections that take little to no effort to deploy — that's especially important for our organizations that already struggle with limited resources.”

Deputy Director and Interim State CISO

Top WAF use cases

Traffic attack browser - Tile
Block common attacks like SQL injection and cross-site scripting

Cloudflare uses core OWASP Top 10 rules to block the most widespread layer 7 attacks.

Security shield protection checkmark - Icon
Stop credential stuffing attacks

Our WAF prevents account takeover by detecting and blocking the use of stolen or exposed user login credentials.

Icon Tile Page Shield
Detect malware in uploaded files

WAF content scanning protects your web servers and enterprise network from malware by scanning files as they are uploaded to your application.

Helping enterprises all over the world protect their applications

Pricing

Upgrade your website security and performance with WAF and so much more

Pro

$20

per user / month (paid annually)

When billed annually or $25 / mo if billed monthly

For professional websites that aren't business-critical.

Business

$200

per user / month (paid annually)

When billed annually or $250 / mo if billed monthly

For small businesses operating online.

Contract

Custom

Billed annually

For mission-critical applications that are core to your business.

New Externa packages available

Web Application Firewall (WAF)
Web Application Firewall (WAF)

Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting millions of websites. Suspicious requests can be blocked, challenged, or logged per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premises or in the cloud.

Unmetered DDoS Protection
Unmetered DDoS Protection

Cloudflare DDoS protection secures websites and applications while ensuring the performance of legitimate traffic is not compromised.

Accelerated Mobile Pages (AMP)
Accelerated Mobile Pages (AMP)

Mirage automatically optimizes image loading through virtualized and lazyloaded images. It detects the browser type of a visitor and optimizes performance for the particular device, improving the performance of images on a mobile connection.

Lossless Image Optimization
Lossless Image Optimization

Polish applies "lossless" or optional "lossy" image optimization to reduce your image sizes by 35% on average.

Support Options
Bot Mitigation
Bot Mitigation

Manage good and bad bots in real time with speed and accuracy by harnessing the data from the millions of Internet properties on Cloudflare.

Uptime SLA
Network Prioritization

Resources

Whitepaper image

Whitepaper

Doing more with less: Cost-effective application security and performance strategies
Get whitepaper
Thumbnail - Insight - Template 1 Lightbulb

Product brief

WAF product brief
Get product brief
Security signals

Article

Website security guide: A 10-step checklist
Learn more
Thumbnail - Insight - Template 5 Graphs

Explore

Find the right Cloudflare plan for your small business
Explore now
Insight thumbnail - rocket

Explore

Get free protection and acceleration for your personal website
Explore now

FAQs

Security Shield Protection Icon

Get Cloudflare WAF for your enterprise

Talk to an expert

选择您的职位级别……*
首席高管
副总裁
总监
经理
个人贡献者
学生
其他
选择您的工作职能……*
IT
安全
网络
基础设施
工程
DevOps
高管
产品
财务/采购
销售/营销
学生
新闻/媒体
其他
选择您的国家/地区...
阿富汗
阿兰群岛
阿尔巴尼亚
阿尔及利亚
安道尔
安哥拉
安圭拉
南极洲
安提瓜和巴布达
阿根廷
亚美尼亚
阿鲁巴
澳大利亚
奥地利
阿塞拜疆
巴哈马
巴林
孟加拉国
巴巴多斯
白俄罗斯
比利时
伯利兹
贝宁
百慕大
不丹
玻利维亚多民族国
博内尔岛、圣尤斯特歇斯和萨巴岛
波斯尼亚和黑塞哥维那
博茨瓦纳
布维岛
巴西
英属印度洋领地
文莱达鲁萨兰国
保加利亚
布基纳法索
布隆迪
柬埔寨
喀麦隆
加拿大
佛得角
开曼群岛
中非共和国
乍得
智利
中国大陆
圣诞岛
科科斯(基林)群岛
哥伦比亚
科摩罗
刚果民主共和国
刚果
库克群岛
哥斯达黎加
科特迪瓦
克罗地亚
古巴
库拉索
塞浦路斯
捷克共和国
丹麦
吉布提
多米尼加
多米尼加共和国
厄瓜多尔
埃及
萨尔瓦多
赤道几内亚
厄立特里亚
爱沙尼亚
埃塞俄比亚
福克兰群岛(马尔维纳斯)
法罗群岛
斐济
芬兰
法国
法属圭亚那
法属波利尼西亚
法属南部领土
加蓬
冈比亚
格鲁吉亚
德国
加纳
直布罗陀
希腊
格陵兰
格林纳达
瓜德罗普岛
危地马拉
格恩西岛
几内亚比绍
几内亚
圭亚那
海地
赫德和麦克唐纳群岛
梵蒂冈(教区)
洪都拉斯
中国香港特别行政区
匈牙利
冰岛
印度
印度尼西亚
伊朗
伊拉克
爱尔兰
马恩岛
以色列
意大利语
牙买加
日本
新泽西
约旦
哈萨克斯坦
肯尼亚
基里巴斯
科威特
吉尔吉斯斯坦
老挝人民民主共和国
拉脱维亚
黎巴嫩
莱索托
利比里亚
利比亚
列支敦士登
立陶宛
卢森堡
中国澳门特别行政区
前南斯拉夫马其顿共和国
马达加斯加
马拉维
马来西亚
马尔代夫
马里
马耳他
马提尼克
毛里塔尼亚
毛里求斯
马约特
墨西哥
摩尔多瓦共和国
摩纳哥
蒙古
黑山
蒙特塞拉特
摩洛哥
莫桑比克
缅甸
纳米比亚
瑙鲁
尼泊尔
荷兰
新喀里多尼亚
新西兰
尼加拉瓜
尼日尔
尼日利亚
纽埃
诺福克岛
朝鲜
挪威
阿曼
巴基斯坦
巴勒斯坦
巴拿马
巴布亚新几内亚
巴拉圭
秘鲁
菲律宾
皮特凯恩
波兰
葡萄牙
波多黎各
卡塔尔
留尼旺
罗马尼亚
俄罗斯联邦
卢旺达
圣巴泰勒米
圣赫勒拿、阿森松和特里斯坦达昆哈
圣基茨和尼维斯
圣卢西亚
圣马丁(法属)
圣皮埃尔和密克隆群岛
圣文森特和格林纳丁斯
萨摩亚
圣马力诺
圣多美和普林西比
沙特阿拉伯
塞内加尔
塞尔维亚
塞舌尔
塞拉利昂
新加坡
圣马丁(荷属)
斯洛伐克
斯洛文尼亚
所罗门群岛
索马里
南非
南乔治亚和南德桑威奇群岛
韩国
南苏丹
西班牙
斯里兰卡
苏丹
苏里南
斯瓦尔巴岛和扬马延岛
斯威士兰
瑞典
瑞士
叙利亚
台湾地区
塔吉克斯坦
坦桑尼亚联合共和国
泰国
东帝汶
多哥
托克劳
汤加
特立尼达和多巴哥
突尼斯
土耳其
土库曼斯坦
特克斯和凯科斯群岛
图瓦卢
乌干达
乌克兰
阿拉伯联合酋长国
英国
美国
乌拉圭
乌兹别克斯坦
瓦努阿图
委内瑞拉玻利瓦尔共和国
越南
英属维尔京群岛
瓦利斯和富图纳
西撒哈拉
也门
赞比亚
津巴布韦

 
In submitting this form, you agree to receive information from Cloudflare related to our products, events, and special offers. You can unsubscribe from such messages at any time. We never sell your data, and we value your privacy choices. Please see our Privacy Policy for information.