Skip to content

Explainer

Cloudflare WAF Rules Explained: Challenge, Block, Skip, Log

Cloudflare WAF custom rule actions in Cloudflare's words, terminating vs non-terminating, plan limits, rule order, and what each action means for a bot.

By 6 min readPublished Updated

A Cloudflare WAF custom rule is an expression over request fields plus an action. The actions are Block (“Matching requests are denied access to the site”), three challenges (Managed, Non-Interactive and Interactive), Skip (“Allows user to dynamically skip one or more security features or products for a request”) and Log (Enterprise only). Block and the challenges are terminating: the first rule with a terminating action stops evaluation. Skip and Log are not. For an automated client, a challenge can be passed, and a cf_clearance cookie at a high enough level covers the next ones; a Block can only be changed by the site owner.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

A rule is an expression plus an action

A custom rule matches requests with an expression in Cloudflare’s Rules language, built from fields such as ip.src (the client IP), ip.src.country, http.user_agent, http.request.uri.path and http.request.method, and operators such as eq, contains, in, and and or. For example, an owner who wants to challenge form posts to a login page could write:

(http.request.uri.path eq "/login" and http.request.method eq "POST")

and give it the Managed Challenge action. The regular-expression operator, matches, requires a Business or Enterprise plan. What a WAF is, and why sites use one, is covered in what is a WAF; this article is about the rules and their actions.

The actions, in Cloudflare’s words

Action API value Cloudflare’s description Terminating
Block block “Matching requests are denied access to the site.” Yes
Managed Challenge managed_challenge “Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet.” Cloudflare picks a non-interactive or an interactive challenge per request. Yes
Non-Interactive Challenge (often called JS Challenge) js_challenge “The client that made the request must pass a non-interactive Cloudflare challenge before proceeding.” Yes
Interactive Challenge challenge “The client that made the request must pass an interactive challenge.” Yes
Skip skip “Allows user to dynamically skip one or more security features or products for a request.” No
Log log “Records matching requests in the Cloudflare Logs. Only available on Enterprise plans. Recommended for validating rules before committing to a more severe action.” No

Terminating means the rule ends the WAF’s evaluation of that request: “The first rule with a terminating action (such as Block, Managed Challenge, or Redirect) stops all further evaluation.” A non-terminating action lets the request continue to the next rules. There is no Allow action in the list: to exempt traffic, an owner uses Skip, which can skip the remaining custom rules, later phases such as rate limiting or managed rules, or products such as Browser Integrity Check. Skip has limits: “You cannot bypass or skip Bot Fight Mode using WAF custom rules or Page Rules.”

For a Block, the status is “403 (most security features) or 429 (for example, rate limiting rules)”. On Pro plans and higher, an owner can set a custom response body, content type and status for custom and rate limiting rules.

Limits per plan

Checked 1 October 2026:

Free Pro Business Enterprise
Custom rules 5 20 100 1,000
Custom rule actions All except Log All except Log All except Log All
Regex (matches) No No Yes Yes
Rate limiting rules 1 2 5 100
Rate limiting counting period 10 s Up to 1 minute Up to 10 minutes Up to 65,535 s

Custom rules, managed rules and rate limiting rules

  • Custom rules are the owner’s own: an expression and one of the actions above.
  • Managed rules are rulesets Cloudflare writes and maintains: the Cloudflare Managed Ruleset, the Cloudflare OWASP Core Ruleset, Exposed Credentials Check (deprecated), the Free Managed Ruleset, and Sensitive Data Detection (Enterprise). The Free plan gets only the Free Managed Ruleset, which is “Available on all Cloudflare plans”.
  • Rate limiting rules match with an expression too, then count. Their actions are “block, js_challenge (Non-Interactive Challenge), managed_challenge (Managed Challenge), challenge (Interactive Challenge), or log.” A rate-limited block is error 1015.

The order a request meets them

Cloudflare documents this order for the WAF:

  1. IP Access rules
  2. Firewall rules (deprecated)
  3. Custom rules
  4. Rate limiting rules
  5. Managed rules

In ruleset-engine terms these are the phases http_request_firewall_custom, http_ratelimit and http_request_firewall_managed, in that order, and in each phase account-level rulesets run before the zone’s own. Super Bot Fight Mode runs in its own phase, http_request_sbfm, after all three. Two consequences:

  • A custom rule that blocks or challenges a request ends evaluation there, so rate limiting and managed rules never see it.
  • An owner who allows an address in IP Access rules exempts it from what follows: Cloudflare notes that allowing an IP or ASN “will bypass any configured custom rules, rate limiting rules, WAF Managed Rules, and firewall rules.”

What each action means for an automated client

Action What your client meets Does a Cloudflare Turnstile token help? Does a cf_clearance cookie help?
Block Usually 403 with a 1xxx code such as 1020 in the body, or the owner’s custom response No No
Managed Challenge A challenge page with cf-mitigated: challenge No Yes, a Managed or Interactive clearance
Non-Interactive Challenge A challenge page with cf-mitigated: challenge No Yes, a clearance of any level
Interactive Challenge A challenge page with cf-mitigated: challenge No Only an Interactive clearance
Skip Nothing visible: the request continues with the skipped features off Not needed Not needed
Log Nothing visible: the request is recorded and continues Not needed Not needed

Why the columns read that way:

  • Clearance is about challenges. Cloudflare documents that cf_clearance “enables visitors to bypass WAF Challenges”, at its level: Interactive clears all three challenge types, Managed clears Managed and Non-Interactive, Non-Interactive clears only its own. Nothing in the clearance docs describes lifting a Block. For rate limiting rules, “The Challenge Passage does not apply”.
  • A Cloudflare Turnstile token is not a WAF credential. The token goes into the site’s form and is checked by the site’s own server with Siteverify, not by a WAF action. The one link between the two is pre-clearance, where a site’s own Cloudflare Turnstile widget also issues a cf_clearance cookie; see Cloudflare Turnstile pre-clearance.
  • Nothing helps against Block but the owner. The owner can edit the rule, add a Skip rule for your traffic, or allow your address. Changing addresses or disguising your client to slip past a Block rule defeats a decision the owner made on purpose.

For challenge actions on sites you may automate, ZeroCaptcha’s challenge task passes the challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver, the cf_clearance cookie explained, and Cloudflare challenge types for how the three challenges differ.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What actions can a Cloudflare WAF custom rule take?

Block, Managed Challenge, Non-Interactive Challenge, Interactive Challenge, Skip and Log. Log is only available on Enterprise plans.

In what order does Cloudflare's WAF evaluate rules?

IP Access rules, then firewall rules (deprecated), custom rules, rate limiting rules and managed rules. The first rule with a terminating action, such as Block or Managed Challenge, stops all further evaluation.

Does a cf_clearance cookie get past a Cloudflare WAF Block rule?

No. A clearance lets a visitor bypass challenge actions up to its level; Block denies matching requests, and only the owner can change the rule or skip it for your traffic.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key