Priority/Order: Managed Rules vs Firewall Rules vs Tools

I would like to know the priority set for the different firewall mechanisms to understand the order in which they are processed.

  • Managed Rules
    • Customer Requested Rules
    • Cloudflare Managed Ruleset
    • Package: OWASP ModSecurity Core Rule Set
  • Firewall Rules
  • Tools
    • IP Access Rules
    • User Agent Blocking
    • Zone Lockdown

I searched the Website, Learning Center, Support Center, Blog and Community, but I didn’t find this information.

Not 100% on this, maybe someone else (@alexcf, @cloonan, @cs-cf) can verify, but this is what I believe:

IP Access Rules
Firewall Rules
Zone Lockdown
User Agent Blocking

Not entirely sure where the various Managed Rules come in order!


This is pretty much spot on :slight_smile: - Managed Rules happen in the WAF. The Cloudflare Managed Rulesets run before OWASP, then after that comes Cloudflare Workers.


