Cloudflare WAF
Use this reference for managed protection, custom request policies, rate limiting, and investigation of blocked traffic. Read the relevant developer documentation before implementing; it owns schemas, expressions, ruleset IDs, phase order, and plan availability.
| Task | Start here |
|---|---|
| Choose and enable WAF protections | Get started |
| Deploy managed protection | Managed rules deployment |
| Match application-specific requests | Custom rules |
| Limit request volume | Rate limiting |
| Understand score-based detection | Attack score |
| Diagnose blocked or unmitigated requests | Managed rules troubleshooting |
Identify the target account or zone and inspect existing rules before planning a change. Keep the requested traffic scope explicit, especially for exceptions and account-wide deployments.
Reading Order
- configuration.md — deployment method and existing configuration.
- api.md — API workflows and expression references.
- patterns.md — choose a protection or exception workflow.
- gotchas.md — diagnose ordering, scope, and false positives.