Cloudflare WAF

Block the latest attacks with our industry-leading web application firewall (WAF)

The Cloudflare WAF uses threat intelligence and machine learning powered by platform intelligence from the Cloudflare connectivity cloud to stop the newest threats, including zero-days.

WAF - Hero image

Benefits of Cloudflare WAF

icon - internet globe
Global threat intelligence

The Cloudflare global network processes 106 million HTTP requests per second at peak, providing unparalleled protection against the latest attacks, including zero-day exploits.

Ddos ransom icon
Machine learning-based detection

The Cloudflare WAF uses machine learning to automatically block emerging threats in real time.

Performance wrench - Icon
Fast deployment and easy management

Customers can set up the WAF with just a few clicks, and our WAF integrates with the rest of our application security for full coverage. No training or professional services needed.

Icon Tile Cloudflare ruleset engine
Managed and custom rulesets

On top of OWASP rules, Cloudflare-managed rules offer fast zero-day protection, and custom rulesets enable organizations to tailor their WAF to implement organization-specific policies.

WAF content scanning - Image

How it works

The Cloudflare WAF runs on the Cloudflare global network and sits in front of web applications to stop a wide range of real-time attacks using powerful rulesets, advanced rate limiting, exposed credential checks, uploaded content scanning, and other security measures.

The WAF integrates with our analyst-recognized, industry-leading application security portfolio for comprehensive protection.

What our customers are saying

AI Crawl
State of Arizona - Logo

“With the Cloudflare platform, we're getting very high-powered, very technical [application security] detection and protections that take little to no effort to deploy — that's especially important for our organizations that already struggle with limited resources.”

Deputy Director and Interim State CISO

Top WAF use cases

Traffic attack browser - Tile
Block common attacks like SQL injection and cross-site scripting

Cloudflare uses core OWASP Top 10 rules to block the most widespread layer 7 attacks.

Security shield protection checkmark - Icon
Stop credential stuffing attacks

Our WAF prevents account takeover by detecting and blocking the use of stolen or exposed user login credentials.

Icon Tile Page Shield
Detect malware in uploaded files

WAF content scanning protects your web servers and enterprise network from malware by scanning files as they are uploaded to your application.

Helping enterprises all over the world protect their applications

Pricing

Upgrade your website security and performance with WAF and so much more

Pro

$20

per user / month (paid annually)

When billed annually or $25 / mo if billed monthly

For professional websites that aren't business-critical.

Business

$200

per user / month (paid annually)

When billed annually or $250 / mo if billed monthly

For small businesses operating online.

Contract

Custom

Billed annually

For mission-critical applications that are core to your business.

New Externa packages available

Web Application Firewall (WAF)
Web Application Firewall (WAF)

Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting millions of websites. Suspicious requests can be blocked, challenged, or logged per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premises or in the cloud.

Unmetered DDoS Protection
Unmetered DDoS Protection

Cloudflare DDoS protection secures websites and applications while ensuring the performance of legitimate traffic is not compromised.

Accelerated Mobile Pages (AMP)
Accelerated Mobile Pages (AMP)

Mirage automatically optimizes image loading through virtualized and lazyloaded images. It detects the browser type of a visitor and optimizes performance for the particular device, improving the performance of images on a mobile connection.

Lossless Image Optimization
Lossless Image Optimization

Polish applies "lossless" or optional "lossy" image optimization to reduce your image sizes by 35% on average.

Support Options
Bot Mitigation
Bot Mitigation

Manage good and bad bots in real time with speed and accuracy by harnessing the data from the millions of Internet properties on Cloudflare.

Uptime SLA
Network Prioritization

Resources

Whitepaper image

Whitepaper

Doing more with less: Cost-effective application security and performance strategies
Get whitepaper
Thumbnail - Insight - Template 1 Lightbulb

Product brief

WAF product brief
Get product brief
Security signals

Article

Website security guide: A 10-step checklist
Learn more
Thumbnail - Insight - Template 5 Graphs

Explore

Find the right Cloudflare plan for your small business
Explore now
Insight thumbnail - rocket

Explore

Get free protection and acceleration for your personal website
Explore now

FAQs

Security Shield Protection Icon

Get Cloudflare WAF for your enterprise

Talk to an expert

选择您的职位级别……*
个人贡献者
其他
副总裁
学生
总监
经理
首席高管
选择您的工作职能……*
DevOps
IT
产品
其他
基础设施
学生
安全
工程
新闻/媒体
网络
财务/采购
销售/营销
高管
选择您的国家/地区...
不丹
东帝汶
中国大陆
中国澳门特别行政区
中国香港特别行政区
中非共和国
丹麦
乌克兰
乌兹别克斯坦
乌干达
乌拉圭
乍得
也门
亚美尼亚
以色列
伊拉克
伊朗
伯利兹
佛得角
俄罗斯联邦
保加利亚
克罗地亚
冈比亚
冰岛
几内亚
几内亚比绍
列支敦士登
刚果
刚果民主共和国
利比亚
利比里亚
前南斯拉夫马其顿共和国
加拿大
加纳
加蓬
匈牙利
南乔治亚和南德桑威奇群岛
南极洲
南苏丹
南非
博内尔岛、圣尤斯特歇斯和萨巴岛
博茨瓦纳
卡塔尔
卢旺达
卢森堡
印度
印度尼西亚
危地马拉
厄瓜多尔
厄立特里亚
叙利亚
古巴
台湾地区
吉尔吉斯斯坦
吉布提
哈萨克斯坦
哥伦比亚
哥斯达黎加
喀麦隆
图瓦卢
土库曼斯坦
土耳其
圣卢西亚
圣基茨和尼维斯
圣多美和普林西比
圣巴泰勒米
圣文森特和格林纳丁斯
圣皮埃尔和密克隆群岛
圣诞岛
圣赫勒拿、阿森松和特里斯坦达昆哈
圣马丁(法属)
圣马丁(荷属)
圣马力诺
圭亚那
坦桑尼亚联合共和国
埃及
埃塞俄比亚
基里巴斯
塔吉克斯坦
塞内加尔
塞尔维亚
塞拉利昂
塞浦路斯
塞舌尔
墨西哥
多哥
多米尼加
多米尼加共和国
奥地利
委内瑞拉玻利瓦尔共和国
孟加拉国
安哥拉
安圭拉
安提瓜和巴布达
安道尔
尼加拉瓜
尼日利亚
尼日尔
尼泊尔
巴勒斯坦
巴哈马
巴基斯坦
巴巴多斯
巴布亚新几内亚
巴拉圭
巴拿马
巴林
巴西
布基纳法索
布维岛
布隆迪
希腊
库克群岛
库拉索
开曼群岛
德国
意大利语
所罗门群岛
托克劳
拉脱维亚
挪威
捷克共和国
摩尔多瓦共和国
摩洛哥
摩纳哥
文莱达鲁萨兰国
斐济
斯威士兰
斯洛伐克
斯洛文尼亚
斯瓦尔巴岛和扬马延岛
斯里兰卡
新加坡
新喀里多尼亚
新泽西
新西兰
日本
智利
朝鲜
柬埔寨
格恩西岛
格林纳达
格陵兰
格鲁吉亚
梵蒂冈(教区)
比利时
毛里塔尼亚
毛里求斯
汤加
沙特阿拉伯
法国
法属南部领土
法属圭亚那
法属波利尼西亚
法罗群岛
波兰
波多黎各
波斯尼亚和黑塞哥维那
泰国
津巴布韦
洪都拉斯
海地
澳大利亚
爱尔兰
爱沙尼亚
牙买加
特克斯和凯科斯群岛
特立尼达和多巴哥
玻利维亚多民族国
瑙鲁
瑞典
瑞士
瓜德罗普岛
瓦利斯和富图纳
瓦努阿图
留尼旺
白俄罗斯
百慕大
皮特凯恩
直布罗陀
福克兰群岛(马尔维纳斯)
科威特
科摩罗
科特迪瓦
科科斯(基林)群岛
秘鲁
突尼斯
立陶宛
索马里
约旦
纳米比亚
纽埃
缅甸
罗马尼亚
美国
老挝人民民主共和国
肯尼亚
芬兰
苏丹
苏里南
英国
英属印度洋领地
英属维尔京群岛
荷兰
莫桑比克
莱索托
菲律宾
萨尔瓦多
萨摩亚
葡萄牙
蒙古
蒙特塞拉特
西撒哈拉
西班牙
诺福克岛
贝宁
赞比亚
赤道几内亚
赫德和麦克唐纳群岛
越南
阿兰群岛
阿塞拜疆
阿富汗
阿尔及利亚
阿尔巴尼亚
阿拉伯联合酋长国
阿曼
阿根廷
阿鲁巴
韩国
马尔代夫
马恩岛
马拉维
马提尼克
马来西亚
马约特
马耳他
马达加斯加
马里
黎巴嫩
黑山

 
In submitting this form, you agree to receive information from Cloudflare related to our products, events, and special offers. You can unsubscribe from such messages at any time. We never sell your data, and we value your privacy choices. Please see our Privacy Policy for information.