Skip to content

Explainer

What Is a WAF? And What a Cloudflare WAF Challenge Means

A web application firewall filters HTTP traffic by rules. How Cloudflare's WAF is built, and what a scraper sees when one of its rules blocks or challenges it.

By 5 min readPublished Updated

A WAF, or web application firewall, “helps protect web applications by filtering and monitoring HTTP traffic between a web application and the Internet”, in the words of Cloudflare’s Learning Center. It works at layer 7, sits in front of the server as a reverse proxy, and decides what to do with each request using a set of rules, often called policies. Cloudflare’s WAF runs such rules on every plan. When one of them matches a scraper’s request, the scraper gets either a block page, such as error 1020 or 1015, or a challenge page that a browser has to pass.

Only automate sites you are allowed to: your own, a client’s, or one whose terms permit it. See responsible captcha automation.

What a WAF does

Cloudflare’s Learning Center (checked 1 October 2026) describes a WAF in five parts:

  • What it stops. A WAF “typically protects web applications from attacks such as cross-site forgery, cross-site-scripting (XSS), file inclusion, and SQL injection, among others.”
  • Where it works. “A WAF is a protocol layer 7 defense (in the OSI model), and is not designed to defend against all types of attacks.” It judges HTTP traffic, not lower-level network traffic.
  • How it sits in the path. “a WAF is a type of reverse-proxy, protecting the server from exposure by having clients pass through the WAF before reaching the server.”
  • How it decides. “A WAF operates through a set of rules often called policies.” A WAF that blocks what matches a list of known-bad patterns follows a negative security model (a blocklist). One that admits only what matches a list of known-good traffic follows a positive security model (an allowlist). Many WAFs combine the two.
  • Where it runs. The Learning Center names three kinds: network-based WAFs, “generally hardware-based”; host-based WAFs; and cloud-based WAFs, whose setup can be “as simple as a change in DNS to redirect traffic.”

Cloudflare’s WAF is a cloud service: it runs on Cloudflare’s network, in front of the site, and a request meets its rules before it reaches the site’s server.

How Cloudflare’s WAF is built

Cloudflare’s WAF “checks incoming web and API requests and filters undesired traffic based on sets of rules called rulesets”, and it is “Available on all plans”. Its main parts:

  • Managed rules: rulesets Cloudflare writes and updates, such as the Cloudflare Managed Ruleset, the Cloudflare OWASP Core Ruleset, and the Free Managed Ruleset, the one “Available on all Cloudflare plans”. The Free plan gets only that last one.
  • Custom rules: rules the site owner writes, each an expression over request fields (address, country, path, user agent, headers and more) plus an action such as Block or Managed Challenge. From 5 rules on the Free plan to 1,000 on Enterprise.
  • Rate limiting rules: rules that count matching requests and act when a client sends too many, from 1 rule on Free to 100 on Enterprise.

Around them sit tools such as IP Access rules (allow, block or challenge by address, ASN or country), Browser Integrity Check (headers “abused most commonly by spammers” and missing or non-standard user agents) and Under Attack mode (a Managed Challenge for every visitor). How the rules are ordered, and what each action does, is the subject of Cloudflare WAF rules explained.

What an automated client sees

When a Cloudflare WAF rule matches a request, the response depends on the rule’s action. For a block, Cloudflare puts the HTTP status in the status line and a 1xxx code in the HTML body; the status is “403 (most security features) or 429 (for example, rate limiting rules)”.

What you receive What it means What ends it
Error 1020, “Access denied” A firewall rule the owner wrote blocked you Only the site owner
Error 1015, “You are being rate limited” A rate limiting rule’s limit was reached Time: slow down and wait
Error 1010 Browser Integrity Check refused your client’s signature A normal, consistent user agent, or the owner
Error 1009 The owner banned your address’s country or region The owner, or a permitted region
Errors 1006, 1007, 1008 The owner banned your IP address Only the site owner
A “Just a moment…” page with cf-mitigated: challenge A challenge action A supported browser passing it, which earns a cf_clearance cookie

The last row is the Cloudflare WAF challenge. Cloudflare documents that every Challenge Page response has “the cf-mitigated header present and set to challenge”, so a client can tell a challenge from a block without parsing HTML. The three challenge types, Managed, Non-Interactive (often called JS Challenge, after its API value js_challenge) and Interactive, are compared in Cloudflare challenge types.

Where CAPTCHA solving fits, and where it doesn’t

  • Blocks: nothing fits. A block is a decision about your request that only the owner can change, and a token or cookie from a solver doesn’t alter it. Don’t rotate addresses or disguise your client to get around one.
  • Challenge pages: a challenge can be passed, and the clearance it earns is what later requests need. For sites you may automate, ZeroCaptcha’s challenge task passes a challenge page through your proxy and returns the cf_clearance cookie with the user agent it is bound to. See the Cloudflare WAF and 5-second challenge solver and the cf_clearance cookie explained.
  • Cloudflare Turnstile widgets: not part of the WAF at all. Cloudflare Turnstile is a widget a site embeds in its own pages, and it “can be embedded into any website without sending traffic through Cloudflare”. Its token goes into a form, not past a firewall. See what is Cloudflare Turnstile and Cloudflare challenge page vs Cloudflare Turnstile.

Sources

The team that builds and runs the ZeroCaptcha API. Articles are drafted with AI tools, then checked against the API's code and the primary sources each one cites.

Questions

What is a WAF in simple terms?

A web application firewall sits in front of a web application and filters and monitors the HTTP traffic between it and the internet, using a set of rules often called policies. It works at layer 7 and acts as a reverse proxy.

What is a Cloudflare WAF challenge?

A WAF rule whose action is a challenge instead of a block. The visitor gets an interstitial challenge page that a supported browser can pass, and passing it earns a cf_clearance cookie.

Can a scraper get past a WAF block?

No, and it shouldn't try. A Block action denies matching requests, and only the site owner can change the rule or allow your address. A challenge is different: a supported browser can pass it.

Read next

This article is part of the Cloudflare WAF and 5-second challenge solver hub. Every task is charged only when a token is ready.

Get an API key