Explainer
Cloudflare WAF Rules Explained: Challenge, Block, Skip, Log
Cloudflare WAF custom rule actions in Cloudflare's words, terminating vs non-terminating, plan limits, rule order, and what each action means for a bot.
By ZeroCaptcha Engineering6 min readPublished Updated
A Cloudflare WAF custom rule is an expression over request fields plus an action. The actions are
Block (“Matching requests are denied access to the site”), three challenges (Managed,
Non-Interactive and Interactive), Skip (“Allows user to dynamically skip one or more
security features or products for a request”) and Log (Enterprise only). Block and the
challenges are terminating: the first rule with a terminating action stops evaluation. Skip and Log
are not. For an automated client, a challenge can be passed, and a cf_clearance cookie at a high
enough level covers the next ones; a Block can only be changed by the site owner.
Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.
A rule is an expression plus an action
A custom rule matches requests with an expression in Cloudflare’s Rules language, built from fields
such as ip.src (the client IP), ip.src.country, http.user_agent, http.request.uri.path and
http.request.method, and operators such as eq, contains, in, and and or. For example,
an owner who wants to challenge form posts to a login page could write:
(http.request.uri.path eq "/login" and http.request.method eq "POST")and give it the Managed Challenge action. The regular-expression operator, matches, requires a
Business or Enterprise plan. What a WAF is, and why sites use one, is covered in what is a
WAF; this article is about the rules and their actions.
The actions, in Cloudflare’s words
| Action | API value | Cloudflare’s description | Terminating |
|---|---|---|---|
| Block | block |
“Matching requests are denied access to the site.” | Yes |
| Managed Challenge | managed_challenge |
“Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet.” Cloudflare picks a non-interactive or an interactive challenge per request. | Yes |
| Non-Interactive Challenge (often called JS Challenge) | js_challenge |
“The client that made the request must pass a non-interactive Cloudflare challenge before proceeding.” | Yes |
| Interactive Challenge | challenge |
“The client that made the request must pass an interactive challenge.” | Yes |
| Skip | skip |
“Allows user to dynamically skip one or more security features or products for a request.” | No |
| Log | log |
“Records matching requests in the Cloudflare Logs. Only available on Enterprise plans. Recommended for validating rules before committing to a more severe action.” | No |
Terminating means the rule ends the WAF’s evaluation of that request: “The first rule with a terminating action (such as Block, Managed Challenge, or Redirect) stops all further evaluation.” A non-terminating action lets the request continue to the next rules. There is no Allow action in the list: to exempt traffic, an owner uses Skip, which can skip the remaining custom rules, later phases such as rate limiting or managed rules, or products such as Browser Integrity Check. Skip has limits: “You cannot bypass or skip Bot Fight Mode using WAF custom rules or Page Rules.”
For a Block, the status is “403 (most security features) or 429 (for example, rate limiting
rules)”. On Pro plans and higher, an owner can set a custom response body, content type and status
for custom and rate limiting rules.
Limits per plan
Checked 1 October 2026:
| Free | Pro | Business | Enterprise | |
|---|---|---|---|---|
| Custom rules | 5 | 20 | 100 | 1,000 |
| Custom rule actions | All except Log | All except Log | All except Log | All |
Regex (matches) |
No | No | Yes | Yes |
| Rate limiting rules | 1 | 2 | 5 | 100 |
| Rate limiting counting period | 10 s | Up to 1 minute | Up to 10 minutes | Up to 65,535 s |
Custom rules, managed rules and rate limiting rules
- Custom rules are the owner’s own: an expression and one of the actions above.
- Managed rules are rulesets Cloudflare writes and maintains: the Cloudflare Managed Ruleset, the Cloudflare OWASP Core Ruleset, Exposed Credentials Check (deprecated), the Free Managed Ruleset, and Sensitive Data Detection (Enterprise). The Free plan gets only the Free Managed Ruleset, which is “Available on all Cloudflare plans”.
- Rate limiting rules match with an expression too, then count. Their actions are “
block,js_challenge(Non-Interactive Challenge),managed_challenge(Managed Challenge),challenge(Interactive Challenge), orlog.” A rate-limited block is error 1015.
The order a request meets them
Cloudflare documents this order for the WAF:
- IP Access rules
- Firewall rules (deprecated)
- Custom rules
- Rate limiting rules
- Managed rules
In ruleset-engine terms these are the phases http_request_firewall_custom, http_ratelimit and
http_request_firewall_managed, in that order, and in each phase account-level rulesets run before
the zone’s own. Super Bot Fight Mode runs in its own phase, http_request_sbfm, after all three.
Two consequences:
- A custom rule that blocks or challenges a request ends evaluation there, so rate limiting and managed rules never see it.
- An owner who allows an address in IP Access rules exempts it from what follows: Cloudflare notes that allowing an IP or ASN “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”
What each action means for an automated client
| Action | What your client meets | Does a Cloudflare Turnstile token help? | Does a cf_clearance cookie help? |
|---|---|---|---|
| Block | Usually 403 with a 1xxx code such as 1020 in the body, or the owner’s custom response |
No | No |
| Managed Challenge | A challenge page with cf-mitigated: challenge |
No | Yes, a Managed or Interactive clearance |
| Non-Interactive Challenge | A challenge page with cf-mitigated: challenge |
No | Yes, a clearance of any level |
| Interactive Challenge | A challenge page with cf-mitigated: challenge |
No | Only an Interactive clearance |
| Skip | Nothing visible: the request continues with the skipped features off | Not needed | Not needed |
| Log | Nothing visible: the request is recorded and continues | Not needed | Not needed |
Why the columns read that way:
- Clearance is about challenges. Cloudflare documents that
cf_clearance“enables visitors to bypass WAF Challenges”, at its level: Interactive clears all three challenge types, Managed clears Managed and Non-Interactive, Non-Interactive clears only its own. Nothing in the clearance docs describes lifting a Block. For rate limiting rules, “The Challenge Passage does not apply”. - A Cloudflare Turnstile token is not a WAF credential. The token goes into the site’s form and
is checked by the site’s own server with Siteverify, not by a WAF action. The one link between
the two is pre-clearance, where a site’s own Cloudflare Turnstile widget also issues a
cf_clearancecookie; see Cloudflare Turnstile pre-clearance. - Nothing helps against Block but the owner. The owner can edit the rule, add a Skip rule for your traffic, or allow your address. Changing addresses or disguising your client to slip past a Block rule defeats a decision the owner made on purpose.
For challenge actions on sites you may automate, ZeroCaptcha’s challenge task passes the challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver, the cf_clearance cookie explained, and Cloudflare challenge types for how the three challenges differ.
Sources
- Cloudflare: WAF custom rules (checked 1 October 2026)
- Cloudflare: Rules language actions (checked 1 October 2026)
- Cloudflare: Rules language fields reference and operators (checked 1 October 2026)
- Cloudflare: WAF concepts, rule execution order, WAF phases and the ruleset engine’s list of phases (checked 1 October 2026)
- Cloudflare: WAF managed rules (checked 1 October 2026)
- Cloudflare: Rate limiting rules and parameters (checked 1 October 2026)
- Cloudflare: IP Access rules (checked 1 October 2026)
- Cloudflare: Super Bot Fight Mode and Bot Fight Mode (checked 1 October 2026)
- Cloudflare: Clearance and Challenge Passage (checked 1 October 2026)
- Cloudflare Turnstile: Server-side validation (checked 1 October 2026)
The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.