Firewall rule set to Simulate but see "Block" action on Activity Log


I configured the WAF mode to “Simulate” mode on Cloudflare:

However, when I checked the activity log, I found that the action taken was “Block”:

Please help to explain the difference here.


I believe you configured this:

This only applies to “OWASP ModSecurity Core Rule Set” but not “Cloudflare Managed Ruleset”.

The rule ID 100202 belongs to Cloudflare Managed Ruleset, so you have to search the rule ID instead:

Hi @erictung, yes you’re correct. Thank you for the useful information!

