Cloudflare Consolidates Security Controls Under a New WAF
Cloudflare has reorganized its security products in the dashboard. The goal, according to the company, is to make the Web Application Firewall (WAF) a clearer, single destination for separating malicious traffic from clean traffic. The change comes after a user research effort involving almost 500 customers.
Previously, firewall rules, managed rules, and rate limiting rules lived in separate parts of the dashboard. User research, which included card sorting, tree testing, design evaluation, and surveys, showed that customers viewed these as related functions. The new structure reflects that mental model.
What changes in the navigation
Effective today, the dashboard navigation is updated as follows:
- The Firewall tab is renamed Security.
- Under Security, the WAF section now contains the firewall’s core features.
- Firewall rules, managed rules, and rate limiting rules now appear under WAF.
The new Security category also includes Bots, DDoS, API Shield, and Page Shield. Cloudflare states that the term WAF now refers specifically to the three aforementioned rule types.
The new WAF layout
All customers, regardless of plan, will now see the WAF products organized in this structure:
- Firewall rules let you create custom logic that blocks or allows traffic based on any HTTP request component or dynamic fields computed by Cloudflare, such as Bot score.
- Rate limiting rules include both the traditional IP-based product from 2018 and the newer Advanced Rate Limiting for Enterprise customers on the Advanced plan, which is rolling out during Security Week.
- Managed rules let customers deploy rulesets maintained by Cloudflare’s analyst team. This includes the “Cloudflare Free Managed Ruleset” for all plans, plus Cloudflare Managed, the OWASP implementation, and Exposed Credentials Check for paying plans.
- Tools provides access to IP Access Rules, Zone Lockdown, and User Agent Blocking. These remain supported for convenience and can also be implemented using firewall rules.
The WAF homepage design
The WAF page itself was redesigned around the research findings. Customers made clear it needed to show each rule type, display usage counts, support adding and managing rules, and preserve the drag-and-drop reprioritization behavior. The layout also had to leave room for future features.
The team considered vertical layouts, table-based pages, and accordion interfaces before settling on horizontal tabs. The final design groups each rule type into its own tab to avoid duplicating controls, which the alternatives would have required.

What comes next
In addition to the new interface and the upcoming Advanced Rate Limiting launch, every customer will also receive access to a free managed ruleset for protection against high profile vulnerabilities. Firewall rules are also slated to move to the Ruleset Engine in the coming months, which will bring new capabilities via the Ruleset API.
Cloudflare says further changes are planned to shorten the path from detecting a threat in Security Overview to deploying the appropriate mitigating rule.



