Cloudflare WAF

Block the latest attacks with our industry-leading web application firewall (WAF)

The Cloudflare WAF uses threat intelligence and machine learning powered by platform intelligence from the Cloudflare connectivity cloud to stop the newest threats, including zero-days.

WAF - Hero image

Benefits of Cloudflare WAF

icon - internet globe
Global threat intelligence

The Cloudflare global network processes 106 million HTTP requests per second at peak, providing unparalleled protection against the latest attacks, including zero-day exploits.

Ddos ransom icon
Machine learning-based detection

The Cloudflare WAF uses machine learning to automatically block emerging threats in real time.

Performance acceleration bolt
Fast deployment and easy management

Customers can set up the WAF with just a few clicks, and our WAF integrates with the rest of our application security for full coverage. No training or professional services needed.

Icon Tile Cloudflare ruleset engine
Managed and custom rulesets

On top of OWASP rules, Cloudflare-managed rules offer fast zero-day protection, and custom rulesets enable organizations to tailor their WAF to implement organization-specific policies.

WAF content scanning - Image

How it works

The Cloudflare WAF runs on the Cloudflare global network and sits in front of web applications to stop a wide range of real-time attacks using powerful rulesets, advanced rate limiting, exposed credential checks, uploaded content scanning, and other security measures.

The WAF integrates with our analyst-recognized, industry-leading application security portfolio for comprehensive protection.

What our customers are saying

AI Crawl
State of Arizona - Logo

“With the Cloudflare platform, we're getting very high-powered, very technical [application security] detection and protections that take little to no effort to deploy — that's especially important for our organizations that already struggle with limited resources.”

Deputy Director and Interim State CISO

Top WAF use cases

Traffic attack browser - Tile
Block common attacks like SQL injection and cross-site scripting

Cloudflare uses core OWASP Top 10 rules to block the most widespread layer 7 attacks.

Security shield protection checkmark - Icon
Stop credential stuffing attacks

Our WAF prevents account takeover by detecting and blocking the use of stolen or exposed user login credentials.

Icon Tile Page Shield
Detect malware in uploaded files

WAF content scanning protects your web servers and enterprise network from malware by scanning files as they are uploaded to your application.

Helping enterprises all over the world protect their applications

Pricing

Upgrade your website security and performance with WAF and so much more

Pro

$20

per user / month (paid annually)

When billed annually or $25 / mo if billed monthly

For professional websites that aren't business-critical.

Business

$200

per user / month (paid annually)

When billed annually or $250 / mo if billed monthly

For small businesses operating online.

Contract

Custom

Billed annually

For mission-critical applications that are core to your business.

New Externa packages available

Web Application Firewall (WAF)
Web Application Firewall (WAF)

Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting millions of websites. Suspicious requests can be blocked, challenged, or logged per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premises or in the cloud.

Unmetered DDoS Protection
Unmetered DDoS Protection

Cloudflare DDoS protection secures websites and applications while ensuring the performance of legitimate traffic is not compromised.

Accelerated Mobile Pages (AMP)
Accelerated Mobile Pages (AMP)

Mirage automatically optimizes image loading through virtualized and lazyloaded images. It detects the browser type of a visitor and optimizes performance for the particular device, improving the performance of images on a mobile connection.

Lossless Image Optimization
Lossless Image Optimization

Polish applies "lossless" or optional "lossy" image optimization to reduce your image sizes by 35% on average.

Support Options
Bot Mitigation
Bot Mitigation

Manage good and bad bots in real time with speed and accuracy by harnessing the data from the millions of Internet properties on Cloudflare.

Uptime SLA
Network Prioritization

Resources

Whitepaper image

Whitepaper

Doing more with less: Cost-effective application security and performance strategies
Get whitepaper
Thumbnail - Insight - Template 1 Lightbulb

Product brief

WAF product brief
Get product brief
Security signals

Article

Website security guide: A 10-step checklist
Learn more

FAQs

Pictogram Security Shield Protection

Get Cloudflare WAF for your enterprise

Talk to an expert

Selecteer je functieniveau... *
C-Level
Directeur
Individuele medewerker
Manager
Overige
Student
VP
Selecteer je functie... *
DevOps
Financiën/Inkoop
Infrastructuur
IT
Leidinggevende
Netwerk
Overige
Pers/media
Product
Student
Techniek
Veiligheid
Verkoop/Marketing
Selecteer uw land...
Afganistan
Aland-eilanden
Albanië
Algerije
Andorra
Angola
Anguilla
Antigua en Barbuda
Argentinië
Armenië
Aruba
Australië
Azerbajdzjan
Bahama's
Bahrein
Bangladesh
Barbados
België
Belize
Benin
Bermuda
Bhutan
Bolivia, Plurinationale Staat van
Bonaire, Sint Eustatius en Saba
Bosnië en Herzegovina
Botswana
Bouveteiland
Brazilië
Brits Indische Oceaanterritorium
Britse Maagdeneilanden
Brunei Darussalam
Bulgarije
Burkina Faso
Burundi
Cambodja
Canada
Centraal-Afrikaanse Republiek
Chili
China
Cocos (Keeling) Eilanden
Colombia
Comoren
Congo
Congo, de Democratische Republiek van
Cookeilanden
Costa Rica
Cuba
Curaçao
Cyprus
Democratische Volksrepubliek Laos
Denemarken
Djibouti
Dominica
Dominicaanse Republiek
Duitsland
Ecuador
Egypte
El Salvador
Equatoriaal-Guinea
Eritrea
Estland
Ethiopië
Faeröer
Falklandeilanden
Fiji
Filippijnen
Finland
Frankrijk
Frans-Guyana
Frans-Polynesië
Franse zuidelijke gebieden
Gabon
Gambia
Georgia
Ghana
Gibraltar
Grenada
Griekenland
Groenland
Guadeloupe
Guatemala
Guernsey
Guinea
Guinee-Bissau
Guyana
Haïti
Heard- en McDonaldeilanden
Honduras
Hongarije
Hongkong
Ierland
Ijsland
India
Indonesië
Irak
Iran
Israël
Italië
Ivoorkust
Jamaica
Japan
Jemen
Jersey
Jordanië
Kaaimaneilanden
Kaapverdië
Kameroen
Katar
Kazachstan
Kenia
Kersteiland
Kirgizië
Kiribati
Koeweit
Kroatië
Lesotho
Letland
Libanon
Liberia
Libië
Liechtenstein
Litouwen
Luxemburg
Macau
Macedonië, de Voormalige Joegoslavische Republiek
Madagaskar
Malawi
Maldiven
Maleisië
Mali
Malta
Man-eiland
Marokko
Martinique
Mauritanië
Mauritius
Mayotte
Mexico
Moldavië, Republiek
Monaco
Mongolië
Montenegro
Montserrat
Mozambique
Myanmar
Namibië
Nauru
Nederland
Nepal
Nicaragua
Nieuw-Caledonië
Nieuw-Zeeland
Niger
Nigeria
Niue
Noord-Korea
Noorwegen
Norfolkeiland
Oekraïne
Oezbekistan
Oman
Oostenrijk
Pakistan
Palestina
Panama
Papoea-Nieuw-Guinea
Paraguay
Peru
Pitcairn
Polen
Portugal
Puerto Rico
Reunion
Roemenië
Rusland
Rwanda
Saint Barthélemy
Saint Kitts en Nevis
Saint Martin (Frans deel)
Saint Pierre en Miquelon
Saint Vincent en de Grenadines
Salomonseilanden
Samoa
San Marino
Sao Tomé en Principe
Saoedi-Arabië
Senegal
Servië
Seychellen
Sierra Leone
Singapore
Sint Lucia
Sint-Helena, Ascension en Tristan da Cunha
Sint-Maarten (Nederlands deel)
Slovenië
Slowakije
Soedan
Somalië
Spanje
Sri Lanka
Suriname
Svalbard en Jan Mayen
Swaziland
Syrië
Tadzjikistan
Taiwan
Tanzania, Verenigde Republiek
Thailand
Timor-Leste
Togo
Tokelau
Tonga
Trinidad en Tobago
Tsjaad
Tsjechië
Tunesië
Turkije
Turkmenistan
Turks- en Caicoseilanden
Tuvalu
Uganda
Uruguay
Vanuatu
Vaticaanstad
Venezuela, Bolivariaanse Republiek
Verenigd Koninkrijk
Verenigde Arabische Emiraten
Verenigde Staten
Vietnam
Wallis en Futuna
West-Sahara
Wit-Rusland
Zambia
Zimbabwe
Zuid-Afrika
Zuid-Georgië en de Zuidelijke Sandwicheilanden
Zuid-Korea
Zuid-Soedan
Zuidpoolgebied
Zweden
Zwitserland