Access to Custom Cloudflare Firewall (WAF) Rules for Enterprise Users
Feature Request: Access to Custom Cloudflare Firewall (WAF) Rules for Enterprise Users
Cloudways’ Cloudflare Enterprise Add-on currently does not allow users to create custom Cloudflare Firewall / WAF rules (Firewall Expressions).
This is a major limitation.
Important use cases such as country-based blocking, bot filtering, ASN blocking, and advanced rate limiting cannot be handled at the Cloudflare edge level.
Server-level blocking (Cloudways Firewall) is not a replacement for Cloudflare Firewall:
Traffic still reaches the server
Server resources are consumed
Performance and stability are impacted
Suggesting users manage rules in their own Cloudflare account is also not a viable solution, as enabling the Cloudflare proxy creates a double proxy / double firewall and breaks the Cloudways Enterprise integration.
Requested Solutions:
Expose Cloudflare Custom Firewall / WAF rules in the Cloudways UI
or
Allow Cloudways support to apply Cloudflare firewall rules on behalf of Enterprise users
Cloudflare Enterprise includes these capabilities, and users expect access to them.
-
Henry Collins commented
I agree that giving Enterprise users more control over Cloudflare's edge-level security rules would be useful.
For smaller websites and web tools, being able to filter unwanted traffic before it reaches the origin server can help reduce unnecessary resource usage. Rules for specific countries, ASNs, bots and rate limits would give site owners more control without having to manage separate proxy configurations.
It would be especially useful if Cloudways could provide a simplified WAF rule builder in the dashboard, while still handling the underlying Cloudflare Enterprise configuration.
I recently built a lightweight https://tallycounts.com website, and having straightforward control over traffic filtering and security at the edge would be valuable as these types of sites grow.
Even allowing Enterprise customers to submit custom rules to Cloudways support for implementation would be a good alternative.
-
Clone 43 Job commented
Fully agree edge-level WAF customization is crucial for blocking unwanted traffic before it reaches the server.
Edit by https://survivalrace.io -
UAE Weekly News commented
This is a critical gap for Enterprise users. We manage https://uaeweeklynews.com/, a high-traffic news platform on Cloud ways Enterprise, and the absence of custom Cloudflare WAF/Firewall rules is a serious security limitation.
Server-level blocking is not a viable alternative traffic still reaches the server, consuming resources and impacting performance. The separate Cloudflare account workaround is also not feasible, as it creates a double-proxy conflict that breaks the Enterprise integration entirely.
Cloudflare Enterprise is a premium add-on and custom WAF rules are a core part of that product. Users deserve full access to these capabilities either through the Cloud ways dashboard or via Cloud ways support upon request.
-
Betty Bell
commented
Thank you for this detailed feedback. Enabling edge-level WAF rules is essential to prevent server resource exhaustion and fully unlock the value of the https://www.e-zpassKY.com Cloudflare Enterprise integration.