Cloudflare WAF

Block the latest attacks with our industry-leading web application firewall (WAF)

The Cloudflare WAF uses threat intelligence and machine learning powered by platform intelligence from the Cloudflare connectivity cloud to stop the newest threats, including zero-days.

WAF - Hero image

Benefits of Cloudflare WAF

icon - internet globe
Global threat intelligence

The Cloudflare global network processes 106 million HTTP requests per second at peak, providing unparalleled protection against the latest attacks, including zero-day exploits.

Ddos ransom icon
Machine learning-based detection

The Cloudflare WAF uses machine learning to automatically block emerging threats in real time.

Performance acceleration bolt
Fast deployment and easy management

Customers can set up the WAF with just a few clicks, and our WAF integrates with the rest of our application security for full coverage. No training or professional services needed.

Icon Tile Cloudflare ruleset engine
Managed and custom rulesets

On top of OWASP rules, Cloudflare-managed rules offer fast zero-day protection, and custom rulesets enable organizations to tailor their WAF to implement organization-specific policies.

WAF content scanning - Image

How it works

The Cloudflare WAF runs on the Cloudflare global network and sits in front of web applications to stop a wide range of real-time attacks using powerful rulesets, advanced rate limiting, exposed credential checks, uploaded content scanning, and other security measures.

The WAF integrates with our analyst-recognized, industry-leading application security portfolio for comprehensive protection.

What our customers are saying

AI Crawl
State of Arizona - Logo

“With the Cloudflare platform, we're getting very high-powered, very technical [application security] detection and protections that take little to no effort to deploy — that's especially important for our organizations that already struggle with limited resources.”

Deputy Director and Interim State CISO

Top WAF use cases

Traffic attack browser - Tile
Block common attacks like SQL injection and cross-site scripting

Cloudflare uses core OWASP Top 10 rules to block the most widespread layer 7 attacks.

Security shield protection checkmark - Icon
Stop credential stuffing attacks

Our WAF prevents account takeover by detecting and blocking the use of stolen or exposed user login credentials.

Icon Tile Page Shield
Detect malware in uploaded files

WAF content scanning protects your web servers and enterprise network from malware by scanning files as they are uploaded to your application.

Helping enterprises all over the world protect their applications

Pricing

Upgrade your website security and performance with WAF and so much more

Pro

$20

per user / month (paid annually)

When billed annually or $25 / mo if billed monthly

For professional websites that aren't business-critical.

Business

$200

per user / month (paid annually)

When billed annually or $250 / mo if billed monthly

For small businesses operating online.

Contract

Custom

Billed annually

For mission-critical applications that are core to your business.

New Externa packages available

Web Application Firewall (WAF)
Web Application Firewall (WAF)

Cloudflare Web Application Firewall's intuitive dashboard enables users to build powerful rules through easy clicks and also provides Terraform integration. Every request to the WAF is inspected against the rule engine and the threat intelligence curated from protecting millions of websites. Suspicious requests can be blocked, challenged, or logged per the needs of the user while legitimate requests are routed to the destination, agnostic of whether it lives on-premises or in the cloud.

Unmetered DDoS Protection
Unmetered DDoS Protection

Cloudflare DDoS protection secures websites and applications while ensuring the performance of legitimate traffic is not compromised.

Accelerated Mobile Pages (AMP)
Accelerated Mobile Pages (AMP)

Mirage automatically optimizes image loading through virtualized and lazyloaded images. It detects the browser type of a visitor and optimizes performance for the particular device, improving the performance of images on a mobile connection.

Lossless Image Optimization
Lossless Image Optimization

Polish applies "lossless" or optional "lossy" image optimization to reduce your image sizes by 35% on average.

Support Options
Bot Mitigation
Bot Mitigation

Manage good and bad bots in real time with speed and accuracy by harnessing the data from the millions of Internet properties on Cloudflare.

Uptime SLA
Network Prioritization

Resources

Whitepaper image

Whitepaper

Doing more with less: Cost-effective application security and performance strategies
Get whitepaper
Thumbnail - Insight - Template 1 Lightbulb

Product brief

WAF product brief
Get product brief
Security signals

Article

Website security guide: A 10-step checklist
Learn more

FAQs

Security Shield Protection Icon

Get Cloudflare WAF for your enterprise

Talk to an expert

Välj din jobbnivå … *
Annat
C-nivå
Chef
Direktör
Individuell medverkande
Student
VP
Välj din jobbroll … *
Annat
Chef
DevOps
Finans/anskaffning
Försäljning/marknadsföring
Infrastruktur
IT
Nätverk
Press/Media
Produkt
Student
Säkerhet
Teknik
Välj land …
Afghanistan
Albanien
Algeriet
Andorra
Angola
Anguilla
Antarktis
Antigua och Barbuda
Argentina
Armenien
Aruba
Australien
Azerbajdzjan
Bahamas
Bahrain
Bangladesh
Barbados
Belarus
Belgien
Belize
Benin
Bermuda
Bhutan
Bolivia
Bonaire, Sint Eustatius och Saba
Bosnien och Hercegovina
Botswana
Bouvetön
Brasilien
Brittiska Jungfruöarna
Brittiska territoriet i Indiska oceanen
Brunei
Bulgarien
Burkina Faso
Burundi
Caymanöarna
Centralafrikanska republiken
Chile
Colombia
Cooköarna
Costa Rica
Curaçao
Cypern
Danmark
Djibouti
Dominica
Dominikanska republiken
Ecuador
Egypten
Ekvatorialguinea
El Salvador
Elfenbenskusten
Eritrea
Estland
Etiopien
Falklandsöarna
Fiji
Filippinerna
Finland
Frankrike
Franska Guyana
Franska Polynesien
Franska sydterritorierna
Färöarna
Förenade arabemiraten
Gabon
Gambia
Georgien
Ghana
Gibraltar
Grekland
Grenada
Grönland
Guadeloupe
Guatemala
Guernsey
Guinea
Guinea-Bissau
Guyana
Haiti
Heard- och McDonaldöarna
Heliga stolen (Vatikanstaten)
Honduras
Hongkong
Indien
Indonesien
Irak
Iran
Irland
Island
Isle of Man
Israel
Italien
Jamaica
Japan
Jemen
Jersey
Jordanien
Julön
Kambodja
Kamerun
Kanada
Kap Verde
Kazakstan
Kenya
Kina
Kirgizistan
Kiribati
Kokosöarna
Komorerna
Kongo
Kongo-Kinshasa
Kroatien
Kuba
Kuwait
Laos
Lesotho
Lettland
Libanon
Liberia
Libyen
Liechtenstein
Litauen
Luxemburg
Macao
Madagaskar
Malawi
Malaysia
Maldiverna
Mali
Malta
Marocko
Martinique
Mauretanien
Mauritius
Mayotte
Mexiko
Moldavien
Monaco
Mongoliet
Montenegro
Montserrat
Mozambique
Myanmar
Namibia
Nauru
Nederländerna
Nepal
Nicaragua
Niger
Nigeria
Niue
Nordkorea
Nordmakedonien
Norfolkön
Norge
Nya Kaledonien
Nya Zeeland
Oman
Pakistan
Palestina
Panama
Papua Nya Guinea
Paraguay
Peru
Pitcairnöarna
Polen
Portugal
Puerto Rico
Qatar
Réunion
Rumänien
Rwanda
Ryska federationen
Saint Kitts och Nevis
Saint Lucia
Saint Vincent och Grenadinerna
Saint-Barthélemy
Saint-Martin (franska delen)
Saint-Pierre och Miquelon
Salomonöarna
Samoa
San Marino
Sankta Helena, Ascension och Tristan da Cunha
São Tomé och Príncipe
Saudiarabien
Schweiz
Senegal
Serbien
Seychellerna
Sierra Leone
Singapore
Sint Maarten (nederländska delen)
Slovakien
Slovenien
Somalia
Spanien
Sri Lanka
Storbritannien
Sudan
Surinam
Svalbard och Jan Mayen
Sverige
Swaziland
Sydafrika
Sydgeorgien och Sydsandwichöarna
Sydkorea
Sydsudan
Syrien
Tadzjikistan
Taiwan
Tanzania
Tchad
Thailand
Tjeckien
Togo
Tokelau
Tonga
Trinidad och Tobago
Tunisien
Turkiet
Turkmenistan
Turks- och Caicosöarna
Tuvalu
Tyskland
Uganda
Ukraina
Ungern
Uruguay
USA
Uzbekistan
Vanuatu
Venezuela
Vietnam
Västsahara
Wallis- och Futunaöarna
Zambia
Zimbabwe
Åland
Österrike
Östtimor