Analyst Simulate action


If someone can explain more simulate mode please ?
I received log FirewallMatchAction Log and WAFAction Simulate.

What is meaning? cloudflare only generate logs but traffic not pass to access the server. Or traffic generate log and can pass to access the server ?

The later case.
Simulating means that the traffic is analyzed against vulnerabilities but no actions are taken to stop them.

1 Like

Where I can see the action ?

In WAFAction = Simulate ( I understand that the traffic is analyzed …etc) and FirewallAction = Log !!!

I cann’t understand if traffic pass ou not if firewall action = Log !!!

Traffic with a Log action passes through, but other rules may apply to block the traffic. It is used when you want to verify what would be blocked by a particular rule.

Simulate in the WAF is essentially the same.