Cloudflare edge web application firewall

Cloudflare WAF

A product-specific Cloudflare WAF that inspects proxied web and API requests and applies managed or custom rulesets before origin handling.

Editorial verdict

Choose Cloudflare WAF when protected traffic already traverses Cloudflare and its managed rules, custom expressions, logging, tuning, and plan boundaries fit the application.12

Best for

  • Cloudflare-proxied web and API traffic
  • Managed and custom edge rules
  • Teams prepared to tune false positives
12

Not ideal for

  • Traffic that bypasses Cloudflare
  • AWS-native or Fastly-aligned controls
  • Teams treating WAF rules as vulnerability remediation
12
Main trade-off

Edge rules can reduce exposure while introducing false positives, tuning, plan gates, provider-specific expressions, logging, and bypass considerations.12

Product boundary

Whether Cloudflare's edge placement and rule model fit the application's HTTP-layer filtering and tuning responsibility.

Cloudflare WAF is distinct from Cloudflare Rate Limiting, Turnstile, Bot Management, DDoS protection, and the broad platform. It filters HTTP requests by rulesets but does not prove the application is secure, remove vulnerable code, or eliminate origin bypass and false-positive risk.12

For: Web teams routing protected HTTP traffic through Cloudflare and willing to govern its rules and plan boundaries

  • Traffic does not traverse Cloudflare
  • Another provider is the required control plane
  • Plan gates, logging, tuning, or bypass risk do not fit

Why teams consider Cloudflare WAF

  • Edge inspectionRules inspect incoming web and API requests before the origin.12
  • Managed rulesetsCloudflare supplies managed rule packages alongside customer rules.12
  • Custom expressionsRules language supports request-property matching and plan-dependent controls.12

Pricing

Cloudflare WAF is available across application-service plans with material differences in managed rulesets, custom-rule counts, fields, analytics, logging, support, and adjacent security products.2

Current decision boundary

Free, Pro, Business, and Enterprise plan boundaries

Verified 2026-07-27: Cloudflare WAF is available on all plans, but rulesets, rule counts, fields, analytics, logging, support, and advanced features vary by plan and contract.2

Primary boundary
Cloudflare plan and enabled application-security products2
Operating variables
Rulesets, custom rules, fields, actions, logging, analytics, and support2
Security duty
Tuning, bypass prevention, monitoring, incident response, and code remediation2
Pricing checked View official pricing

Cloudflare WAF vs alternatives

AWS WAF

Choose when
Supported AWS delivery and application resources
Avoid when
Non-AWS traffic estates
Compared with Cloudflare WAF
AWS-native integration reduces handoffs while request, ACL, rule, logging, managed-rule, capacity, tuning, regional, and adjacent-service costs remain explicit.34

Fastly Next-Gen WAF

Choose when
Fastly-aligned application security
Avoid when
Small applications needing a simple cloud-native WAF
Compared with Cloudflare WAF
Managed security operations can reduce rule-program burden while adding contract, deployment, tuning, telemetry, integration, and provider dependence.56

Resources and sources

Official product, pricing, policy, and operating sources

  • Cloudflare WAF overview
    Open
  • Cloudflare application services plans
    Open
  • AWS WAF documentation
    Open
  • AWS WAF pricing
    Open
  • Fastly Next-Gen WAF documentation
    Open
  • Fastly pricing
    Open
  1. 1
    Cloudflare WAF overview

    Cloudflare · Accessed Official

  2. 2
    Cloudflare application services plans

    Cloudflare · Accessed Official

  3. 3
    AWS WAF documentation

    AWS · Accessed Official

  4. 4
    AWS WAF pricing

    AWS · Accessed Official

  5. 5
    Fastly Next-Gen WAF documentation

    Fastly · Accessed Official

  6. 6
    Fastly pricing

    Fastly · Accessed Official