This article gives practical starting rules for improving website protection without blocking legitimate customers.
Overview
Cloudflare WAF Custom Rules can block, challenge, or skip traffic based on request conditions. Managed Rules provide prebuilt protection against common attacks. Start with low-risk rules, monitor Security Events, then tighten gradually.
Recommended Steps
- Enable suitable Managed Rules for the website technology, such as WordPress rules for WordPress sites.
- Add a Managed Challenge for sensitive login paths such as
/wp-login.php,/admin, or/administrator. - Restrict admin paths by country or trusted IP only if it matches the business case.
- Use rate limiting for login, search, checkout, or API endpoints where supported.
- Block obvious unwanted traffic only after reviewing logs.
- Create Skip rules only for known false positives and document the reason.
- Review Cloudflare Security Events after each rule change.
Common Mistakes to Avoid
- Blocking entire countries without business approval.
- Using Block when Managed Challenge is safer.
- Skipping all WAF features for a whole site because one path had a false positive.
- Not testing checkout, login, payment callbacks, or APIs after rule changes.