Cloudflare WAF

Block the latest attacks with our industry-leading web application firewall (WAF)

The Cloudflare WAF uses threat intelligence and machine learning powered by platform intelligence from the Cloudflare connectivity cloud to stop the newest threats, including zero-days.

WAF - Hero image

Benefits of Cloudflare WAF

icon - internet globe
Global threat intelligence

The Cloudflare global network processes 106 million HTTP requests per second at peak, providing unparalleled protection against the latest attacks, including zero-day exploits.

Ddos ransom icon
Machine learning-based detection

The Cloudflare WAF uses machine learning to automatically block emerging threats in real time.

Performance acceleration bolt
Fast deployment and easy management

Customers can set up the WAF with just a few clicks, and our WAF integrates with the rest of our application security for full coverage. No training or professional services needed.

Icon Tile Cloudflare ruleset engine
Managed and custom rulesets

On top of OWASP rules, Cloudflare-managed rules offer fast zero-day protection, and custom rulesets enable organizations to tailor their WAF to implement organization-specific policies.

WAF content scanning - Image

How it works

The Cloudflare WAF runs on the Cloudflare global network and sits in front of web applications to stop a wide range of real-time attacks using powerful rulesets, advanced rate limiting, exposed credential checks, uploaded content scanning, and other security measures.

The WAF integrates with our analyst-recognized, industry-leading application security portfolio for comprehensive protection.

What our customers are saying

AI Crawl
State of Arizona - Logo

“With the Cloudflare platform, we're getting very high-powered, very technical [application security] detection and protections that take little to no effort to deploy — that's especially important for our organizations that already struggle with limited resources.”

Deputy Director and Interim State CISO

Top WAF use cases

Traffic attack browser - Tile
Block common attacks like SQL injection and cross-site scripting

Cloudflare uses core OWASP Top 10 rules to block the most widespread layer 7 attacks.

Security shield protection checkmark - Icon
Stop credential stuffing attacks

Our WAF prevents account takeover by detecting and blocking the use of stolen or exposed user login credentials.

Icon Tile Page Shield
Detect malware in uploaded files

WAF content scanning protects your web servers and enterprise network from malware by scanning files as they are uploaded to your application.

Helping enterprises all over the world protect their applications

Pricing

Upgrade your website security and performance with WAF and so much more

Pro

$20

per user / month (paid annually)

When billed annually or $25 / mo if billed monthly

For professional websites that aren't business-critical.

Business

$200

per user / month (paid annually)

When billed annually or $250 / mo if billed monthly

For small businesses operating online.

Contract

Custom

Billed annually

For mission-critical applications that are core to your business.

New Externa packages available

Web Application Firewall (WAF)
Web Application Firewall (WAF)

Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting millions of websites. Suspicious requests can be blocked, challenged, or logged per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premises or in the cloud.

Unmetered DDoS Protection
Unmetered DDoS Protection

Cloudflare DDoS protection secures websites and applications while ensuring the performance of legitimate traffic is not compromised.

Accelerated Mobile Pages (AMP)
Accelerated Mobile Pages (AMP)

Mirage automatically optimizes image loading through virtualized and lazyloaded images. It detects the browser type of a visitor and optimizes performance for the particular device, improving the performance of images on a mobile connection.

Lossless Image Optimization
Lossless Image Optimization

Polish applies "lossless" or optional "lossy" image optimization to reduce your image sizes by 35% on average.

Support Options
Bot Mitigation
Bot Mitigation

Manage good and bad bots in real time with speed and accuracy by harnessing the data from the millions of Internet properties on Cloudflare.

Uptime SLA
Network Prioritization

Resources

Whitepaper image

Whitepaper

Doing more with less: Cost-effective application security and performance strategies
Get whitepaper
Thumbnail - Insight - Template 1 Lightbulb

Product brief

WAF product brief
Get product brief
Security signals

Article

Website security guide: A 10-step checklist
Learn more
Find the right Cloudflare plan for your small business - Thumbnail

Explore

Find the right Cloudflare plan for your small business
Explore now
Get free protection and acceleration for your personal website - Thumbnail

Explore

Get free protection and acceleration for your personal website
Explore now

FAQs

Security Shield Protection Icon

Get Cloudflare WAF for your enterprise

Talk to an expert

Chọn cấp độ công việc của bạn... *
Cấp C
Giám đốc
Khác
Người đóng góp cá nhân
Quản lý
Sinh viên
VP
Chọn chức năng công việc của bạn... *
Bán hàng / Tiếp thị
Báo chí / Truyền thông
Bảo mật
CNTT
Cơ sở hạ tầng
DevOps
Điều hành
Khác
Kỹ thuật
Mạng
Sản phẩm
Sinh viên
Tài chính/ Thu mua
Chọn quốc gia của bạn...
Ả Rập Xê Út
Afghanistan
Ai Cập
Albania
Algeria
Andorra
Angola
Anguilla
Antigua and Barbuda
Áo
Argentina
Armenia
Aruba
Azerbaijan
Ấn Độ
Ba Lan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belize
Benin
Bermuda
Bhutan
Bỉ
Bonaire, Sint Eustatius và Saba
Bosnia và Herzegovina
Botswana
Bồ Đào Nha
Bờ Biển Ngà
Brazil
Bulgaria
Burkina Faso
Burundi
Các Tiểu Vương Quốc Ả Rập Thống Nhất
Cameroon
Campuchia
Canada
Cape Verde
Chad
Chile
Colombia
Comoros
Congo
Costa Rica
Cộng hòa Bolivia
Cộng hòa Dân chủ Congo
Cộng hòa Dân chủ Nhân dân Lào
Cộng hòa Dominica
Cộng hòa Séc
Cộng hòa Síp
Cộng hòa Trung Phi
Croatia
Cuba
Curaçao
Djibouti
Dominica
Đài Loan
Đan Mạch
Đảo Bouvet
Đảo Christmas
Đảo Heard và Quần đảo McDonald
Đảo Man
Đảo Norfolk
Đảo Saint Helena, Ascension và Tristan da Cunha
Đông Timor
Ecuador
El Salvador
Eritrea
Estonia
Ethiopia
Fiji
Gabon
Gambia
Georgia
Ghana
Gibraltar
Greenland
Grenada
Guadeloupe
Guatemala
Guernsey
Guiana thuộc Pháp
Guinea
Guinea Xích đạo
Guinea-Bissau
Guyana
Hà Lan
Haiti
Hàn Quốc
Hoa Kỳ
Honduras
Hồng Kông
Hungary
Hy Lạp
Iceland
Indonesia
Iran
Iraq
Ireland
Israel
Jamaica
Jersey
Jordan
Kazakhstan
Kenya
Kiribati
Kuwait
Kyrgyzstan
Lãnh thổ Ấn Độ Dương thuộc Anh
Latvia
Lebanon
Lesotho
Liberia
Libya
Liechtenstein
Liên bang Nga
Lithuania
Luxembourg
Ma Cao
Ma Rốc
Macedonia, Cộng hòa Nam Tư cũ
Madagascar
Malawi
Malaysia
Maldives
Mali
Malta
Martinique
Mauritania
Mauritius
Mayotte
Mexico
Moldova, Cộng hòa
Monaco
Montenegro
Montserrat
Mozambique
Mông Cổ
Myanmar
Na Uy
Nam Cực
Nam Georgia và Quần đảo Nam Sandwich
Nam Phi
Nam Sudan
Namibia
Nauru
Nepal
New Caledonia
New Zealand
Nhật Bản
Nicaragua
Niger
Nigeria
Niue
Oman
Pakistan
Palestine
Panama
Papua New Guinea
Paraguay
Peru
Pháp
Phần Lan
Philippines
Pitcairn
Polynesia thuộc Pháp
Puerto Rico
Qatar
Quần đảo Aland
Quần đảo Cayman
Quần đảo Cocos (Keeling)
Quần đảo Cook
Quần đảo Falkland (Malvinas)
Quần đảo Faroe
Quần đảo Solomon
Quần đảo Turks và Caicos
Quần đảo Virgin thuộc Anh
Reunion
Romania
Rwanda
Saint Barthélemy
Saint Kitts và Nevis
Saint Lucia
Saint Martin (phần Pháp)
Saint Pierre và Miquelon
Saint Vincent và Grenadines
Samoa
San Marino
Sao Tome và Principe
Senegal
Serbia
Seychelles
Sierra Leone
Singapore
Sint Maarten (phần Hà Lan)
Slovakia
Slovenia
Somalia
Sri Lanka
Sudan
Suriname
Svalbard và Jan Mayen
Swaziland
Syria
Tajikistan
Tanzania, Cộng hòa Thống nhất
Tây Ban Nha
Tây Sahara
Thái Lan
Thổ Nhĩ Kỳ
Thụy Điển
Thụy Sỹ
Tiếng Đức
Tòa thánh (Thành Vatican)
Togo
Tokelau
Tonga
Triều Tiên
Trinidad và Tobago
Trung Quốc
Tunisia
Turkmenistan
Tuvalu
Úc
Uganda
Ukraine
Uruguay
Uzbekistan
Vanuatu
Venezuela, Cộng hòa Bolivar
Việt Nam
Vùng đất phía Nam thuộc Pháp
Vương quốc Anh
Vương quốc Brunei
Wallis và Futuna
Ý
Yemen
Zambia
Zimbabwe

 
In submitting this form, you agree to receive information from Cloudflare related to our products, events, and special offers. You can unsubscribe from such messages at any time. We never sell your data, and we value your privacy choices. Please see our Privacy Policy for information.