# Cloudflare WAF Rules Explained: Challenge, Block, Skip, Log

> Cloudflare WAF custom rule actions in Cloudflare's words, terminating vs non-terminating, plan limits, rule order, and what each action means for a bot.

- Source: https://zerocaptcha.io/blog/cloudflare-waf-rules-explained
- Published: 2026-09-30
- Updated: 2026-10-01
- Author: ZeroCaptcha Engineering

A Cloudflare WAF custom rule is an expression over request fields plus an action. The actions are
**Block** ("Matching requests are denied access to the site"), three challenges (**Managed**,
**Non-Interactive** and **Interactive**), **Skip** ("Allows user to dynamically skip one or more
security features or products for a request") and **Log** (Enterprise only). Block and the
challenges are terminating: the first rule with a terminating action stops evaluation. Skip and Log
are not. For an automated client, a challenge can be passed, and a `cf_clearance` cookie at a high
enough level covers the next ones; a Block can only be changed by the site owner.

Only automate sites you are allowed to: your own, a client's, or one whose terms permit it. See
[responsible captcha automation](https://zerocaptcha.io/guides/responsible-captcha-automation).

## A rule is an expression plus an action

A custom rule matches requests with an expression in Cloudflare's Rules language, built from fields
such as `ip.src` (the client IP), `ip.src.country`, `http.user_agent`, `http.request.uri.path` and
`http.request.method`, and operators such as `eq`, `contains`, `in`, `and` and `or`. For example,
an owner who wants to challenge form posts to a login page could write:

```text
(http.request.uri.path eq "/login" and http.request.method eq "POST")
```

and give it the Managed Challenge action. The regular-expression operator, `matches`, requires a
Business or Enterprise plan. What a WAF is, and why sites use one, is covered in [what is a
WAF](https://zerocaptcha.io/blog/what-is-a-waf); this article is about the rules and their actions.

## The actions, in Cloudflare's words

| Action | API value | Cloudflare's description | Terminating |
| --- | --- | --- | --- |
| Block | `block` | "Matching requests are denied access to the site." | Yes |
| Managed Challenge | `managed_challenge` | "Helps reduce the lifetimes of human time spent solving CAPTCHAs across the Internet." Cloudflare picks a non-interactive or an interactive challenge per request. | Yes |
| Non-Interactive Challenge (often called JS Challenge) | `js_challenge` | "The client that made the request must pass a non-interactive Cloudflare challenge before proceeding." | Yes |
| Interactive Challenge | `challenge` | "The client that made the request must pass an interactive challenge." | Yes |
| Skip | `skip` | "Allows user to dynamically skip one or more security features or products for a request." | No |
| Log | `log` | "Records matching requests in the Cloudflare Logs. Only available on Enterprise plans. Recommended for validating rules before committing to a more severe action." | No |

**Terminating** means the rule ends the WAF's evaluation of that request: "The first rule with a
terminating action (such as *Block*, *Managed Challenge*, or *Redirect*) stops all further
evaluation." A non-terminating action lets the request continue to the next rules. There is no
Allow action in the list: to exempt traffic, an owner uses Skip, which can skip the remaining
custom rules, later phases such as rate limiting or managed rules, or products such as Browser
Integrity Check. Skip has limits: "You cannot bypass or skip Bot Fight Mode using WAF custom rules
or Page Rules."

For a Block, the status is "`403` (most security features) or `429` (for example, rate limiting
rules)". On Pro plans and higher, an owner can set a custom response body, content type and status
for custom and rate limiting rules.

## Limits per plan

Checked 1 October 2026:

| | Free | Pro | Business | Enterprise |
| --- | --- | --- | --- | --- |
| Custom rules | 5 | 20 | 100 | 1,000 |
| Custom rule actions | All except Log | All except Log | All except Log | All |
| Regex (`matches`) | No | No | Yes | Yes |
| Rate limiting rules | 1 | 2 | 5 | 100 |
| Rate limiting counting period | 10 s | Up to 1 minute | Up to 10 minutes | Up to 65,535 s |

## Custom rules, managed rules and rate limiting rules

- **Custom rules** are the owner's own: an expression and one of the actions above.
- **Managed rules** are rulesets Cloudflare writes and maintains: the Cloudflare Managed Ruleset,
  the Cloudflare OWASP Core Ruleset, Exposed Credentials Check (deprecated), the Free Managed
  Ruleset, and Sensitive Data Detection (Enterprise). The Free plan gets only the Free Managed
  Ruleset, which is "Available on all Cloudflare plans".
- **Rate limiting rules** match with an expression too, then count. Their actions are "`block`,
  `js_challenge` (Non-Interactive Challenge), `managed_challenge` (Managed Challenge), `challenge`
  (Interactive Challenge), or `log`." A rate-limited block is [error
  1015](https://zerocaptcha.io/blog/cloudflare-error-1015).

## The order a request meets them

Cloudflare documents this order for the WAF:

1. IP Access rules
2. Firewall rules (deprecated)
3. Custom rules
4. Rate limiting rules
5. Managed rules

In ruleset-engine terms these are the phases `http_request_firewall_custom`, `http_ratelimit` and
`http_request_firewall_managed`, in that order, and in each phase account-level rulesets run before
the zone's own. Super Bot Fight Mode runs in its own phase, `http_request_sbfm`, after all three.
Two consequences:

- A custom rule that blocks or challenges a request ends evaluation there, so rate limiting and
  managed rules never see it.
- An owner who allows an address in IP Access rules exempts it from what follows: Cloudflare notes
  that allowing an IP or ASN "will bypass any configured custom rules, rate limiting rules, WAF
  Managed Rules, and firewall rules."

## What each action means for an automated client

| Action | What your client meets | Does a Cloudflare Turnstile token help? | Does a `cf_clearance` cookie help? |
| --- | --- | --- | --- |
| Block | Usually `403` with a 1xxx code such as [1020](https://zerocaptcha.io/blog/cloudflare-error-1020) in the body, or the owner's custom response | No | No |
| Managed Challenge | A challenge page with `cf-mitigated: challenge` | No | Yes, a Managed or Interactive clearance |
| Non-Interactive Challenge | A challenge page with `cf-mitigated: challenge` | No | Yes, a clearance of any level |
| Interactive Challenge | A challenge page with `cf-mitigated: challenge` | No | Only an Interactive clearance |
| Skip | Nothing visible: the request continues with the skipped features off | Not needed | Not needed |
| Log | Nothing visible: the request is recorded and continues | Not needed | Not needed |

Why the columns read that way:

- **Clearance is about challenges.** Cloudflare documents that `cf_clearance` "enables visitors to
  bypass WAF Challenges", at its level: Interactive clears all three challenge types, Managed clears
  Managed and Non-Interactive, Non-Interactive clears only its own. Nothing in the clearance docs
  describes lifting a Block. For rate limiting rules, "The Challenge Passage does not apply".
- **A Cloudflare Turnstile token is not a WAF credential.** The token goes into the site's form and
  is checked by the site's own server with Siteverify, not by a WAF action. The one link between
  the two is pre-clearance, where a site's own Cloudflare Turnstile widget also issues a
  `cf_clearance` cookie; see [Cloudflare Turnstile
  pre-clearance](https://zerocaptcha.io/blog/cloudflare-turnstile-pre-clearance).
- **Nothing helps against Block but the owner.** The owner can edit the rule, add a Skip rule for
  your traffic, or allow your address. Changing addresses or disguising your client to slip past a
  Block rule defeats a decision the owner made on purpose.

For challenge actions on sites you may automate,
ZeroCaptcha's challenge task passes the challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to.
See the [Cloudflare WAF and 5-second challenge solver](https://zerocaptcha.io/cloudflare-challenge-solver), [the cf_clearance cookie
explained](https://zerocaptcha.io/guides/cf-clearance-cookie-explained), and [Cloudflare challenge
types](https://zerocaptcha.io/blog/cloudflare-challenge-types) for how the three challenges differ.

## Sources

- [Cloudflare: WAF custom rules](https://developers.cloudflare.com/waf/custom-rules/) (checked 1 October 2026)
- [Cloudflare: Rules language actions](https://developers.cloudflare.com/ruleset-engine/rules-language/actions/) (checked 1 October 2026)
- [Cloudflare: Rules language fields reference](https://developers.cloudflare.com/ruleset-engine/rules-language/fields/reference/) and [operators](https://developers.cloudflare.com/ruleset-engine/rules-language/operators/) (checked 1 October 2026)
- [Cloudflare: WAF concepts, rule execution order](https://developers.cloudflare.com/waf/concepts/), [WAF phases](https://developers.cloudflare.com/waf/reference/phases/) and the [ruleset engine's list of phases](https://developers.cloudflare.com/ruleset-engine/reference/phases-list/) (checked 1 October 2026)
- [Cloudflare: WAF managed rules](https://developers.cloudflare.com/waf/managed-rules/) (checked 1 October 2026)
- [Cloudflare: Rate limiting rules](https://developers.cloudflare.com/waf/rate-limiting-rules/) and [parameters](https://developers.cloudflare.com/waf/rate-limiting-rules/parameters/) (checked 1 October 2026)
- [Cloudflare: IP Access rules](https://developers.cloudflare.com/waf/tools/ip-access-rules/) (checked 1 October 2026)
- [Cloudflare: Super Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/super-bot-fight-mode/) and [Bot Fight Mode](https://developers.cloudflare.com/bots/get-started/bot-fight-mode/) (checked 1 October 2026)
- [Cloudflare: Clearance](https://developers.cloudflare.com/cloudflare-challenges/concepts/clearance/) and [Challenge Passage](https://developers.cloudflare.com/cloudflare-challenges/challenge-types/challenge-pages/challenge-passage/) (checked 1 October 2026)
- [Cloudflare Turnstile: Server-side validation](https://developers.cloudflare.com/turnstile/get-started/server-side-validation/) (checked 1 October 2026)

## Questions

### What actions can a Cloudflare WAF custom rule take?

Block, Managed Challenge, Non-Interactive Challenge, Interactive Challenge, Skip and Log. Log is only available on Enterprise plans.

### In what order does Cloudflare's WAF evaluate rules?

IP Access rules, then firewall rules (deprecated), custom rules, rate limiting rules and managed rules. The first rule with a terminating action, such as Block or Managed Challenge, stops all further evaluation.

### Does a cf_clearance cookie get past a Cloudflare WAF Block rule?

No. A clearance lets a visitor bypass challenge actions up to its level; Block denies matching requests, and only the owner can change the rule or skip it for your traffic.
