---
title: Update a firewall rule
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[Firewall](https://developers.cloudflare.com/api/go/resources/firewall)

[Rules](https://developers.cloudflare.com/api/go/resources/firewall/subresources/rules)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Update a firewall rule

Deprecated: The Firewall Rules API is deprecated in favour of using the Ruleset Engine. See https://developers.cloudflare.com/fundamentals/api/reference/deprecations/#firewall-rules-api-and-filters-api for full details.

client.Firewall.Rules.Update(ctx, ruleID, params) (\*[FirewallRule](<https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)>), error)

PUT/zones/{zone\_id}/firewall/rules/{rule\_id}

**This endpoint has been deprecated and returns 410 Gone. Please use the [Rulesets API](https://developers.cloudflare.com/ruleset-engine/) instead.**

Updates an existing firewall rule.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Firewall Services Write`

##### ParametersExpand Collapse

ruleID string

The unique identifier of the firewall rule.

maxLength32

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20rule_id%20%3E%20(schema)>)

<details>

<summary>

params RuleUpdateParams

</summary>

ZoneID param.Field\[string]

Path param: Defines an identifier.

maxLength32

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20zone_id">Link to this property</a>

<details>

<summary>

Action param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/firewall/subresources/rules/methods/update#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)">RuleUpdateParamsAction</a>]

Body param: The action to perform when the threshold of matched traffic within the configured period is exceeded.

</summary>

<details>

<summary>

Mode RuleUpdateParamsActionModeOptional

The action to perform.

</summary>

One of the following:

const RuleUpdateParamsActionModeSimulate RuleUpdateParamsActionMode = "simulate"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

const RuleUpdateParamsActionModeBan RuleUpdateParamsActionMode = "ban"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

const RuleUpdateParamsActionModeChallenge RuleUpdateParamsActionMode = "challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%202">Link to this property</a>

const RuleUpdateParamsActionModeJSChallenge RuleUpdateParamsActionMode = "js\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%203">Link to this property</a>

const RuleUpdateParamsActionModeManagedChallenge RuleUpdateParamsActionMode = "managed\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode">Link to this property</a>

<details>

<summary>

Response RuleUpdateParamsActionResponseOptional

A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional. Notes: If you omit this object, Cloudflare will use the default HTML error page. If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone challenge pages and you should not provide the “response” object.

</summary>

Body stringOptional

The response body to return. The value must conform to the configured content type.

maxLength10240

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response%20%3E%20(property)%20body">Link to this property</a>

ContentType stringOptional

The content type of the body. Must be one of the following: <code>text/plain</code>, <code>text/xml</code>, or <code>application/json</code>.

maxLength50

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response%20%3E%20(property)%20content_type">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response">Link to this property</a>

Timeout float64Optional

The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period. Notes: If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone’s Challenge Passage time and you should not provide this value.

maximum86400

minimum1

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20timeout">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20action">Link to this property</a>

Filter param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/filters#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)">FirewallFilter</a>]

Body param

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default%20%3E%20(param)%20filter">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(method)%20update%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type FirewallRule struct{…}

</summary>

ID stringOptional

The unique identifier of the firewall rule.

maxLength32

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Action <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a>Optional

The action to apply to a matched request. The <code>log</code> action is only available on an Enterprise plan.

</summary>

One of the following:

const ActionBlock <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "block"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ActionChallenge <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const ActionJSChallenge <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "js\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const ActionManagedChallenge <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "managed\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const ActionAllow <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "allow"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const ActionLog <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "log"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const ActionBypass <a href="https://developers.cloudflare.com/api/go/resources/rate_limits#(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)">Action</a> = "bypass"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

Description stringOptional

An informative summary of the firewall rule.

maxLength500

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

Filter FirewallRuleFilterOptional

</summary>

One of the following:

<details>

<summary>

type FirewallFilter struct{…}

</summary>

ID stringOptional

The unique identifier of the filter.

maxLength32

minLength32

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Description stringOptional

An informative summary of the filter.

maxLength500

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

Expression stringOptional

The filter expression. For more information, refer to <a href="https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/">Expressions</a>.

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20expression">Link to this property</a>

Paused boolOptional

When true, indicates that the filter is currently paused.

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20paused">Link to this property</a>

Ref stringOptional

A short reference tag. Allows you to select related filters.

maxLength50

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20ref">Link to this property</a>

</details>

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

type DeletedFilter struct{…}

</summary>

ID string

The unique identifier of the filter.

maxLength32

minLength32

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

Deleted bool

When true, indicates that the firewall rule was deleted.

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)%20%3E%20(property)%20deleted">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

Paused boolOptional

When true, indicates that the firewall rule is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20paused">Link to this property</a>

Priority float64Optional

The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority.

maximum2147483647

minimum0

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

Products \[]<a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a>Optional

</summary>

One of the following:

const ProductZoneLockdown <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "zoneLockdown"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const ProductUABlock <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "uaBlock"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

const ProductBIC <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "bic"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

const ProductHot <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "hot"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

const ProductSecurityLevel <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "securityLevel"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

const ProductRateLimit <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "rateLimit"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

const ProductWAF <a href="https://developers.cloudflare.com/api/go/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a> = "waf"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20products">Link to this property</a>

Ref stringOptional

A short reference tag. Allows you to select related firewall rules.

maxLength50

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)>)

### Update a firewall rule

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/filters"
  "github.com/cloudflare/cloudflare-go/firewall"
  "github.com/cloudflare/cloudflare-go/option"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  firewallRule, err := client.Firewall.Rules.Update(
    context.TODO(),
    "372e67954025e0ba6aaa6d586b9e0b60",
    firewall.RuleUpdateParams{
      ZoneID: cloudflare.F("023e105f4ecef8ad9ca31a8372d0c353"),
      Action: cloudflare.F(firewall.RuleUpdateParamsAction{

      }),
      Filter: cloudflare.F(filters.FirewallFilterParam{

      }),
    },
  )
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", firewallRule.ID)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "372e67954025e0ba6aaa6d586b9e0b60",
    "action": "block",
    "description": "Blocks traffic identified during investigation for MIR-31",
    "filter": {
      "id": "372e67954025e0ba6aaa6d586b9e0b61",
      "description": "Restrict access from these browsers on this address range.",
      "expression": "(http.request.uri.path ~ \".*wp-login.php\" or http.request.uri.path ~ \".*xmlrpc.php\") and ip.addr ne 172.16.22.155",
      "paused": false,
      "ref": "FIL-100"
    },
    "paused": false,
    "priority": 50,
    "products": [
      "waf"
    ],
    "ref": "MIR-31"
  },
  "success": true
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": {
    "id": "372e67954025e0ba6aaa6d586b9e0b60",
    "action": "block",
    "description": "Blocks traffic identified during investigation for MIR-31",
    "filter": {
      "id": "372e67954025e0ba6aaa6d586b9e0b61",
      "description": "Restrict access from these browsers on this address range.",
      "expression": "(http.request.uri.path ~ \".*wp-login.php\" or http.request.uri.path ~ \".*xmlrpc.php\") and ip.addr ne 172.16.22.155",
      "paused": false,
      "ref": "FIL-100"
    },
    "paused": false,
    "priority": 50,
    "products": [
      "waf"
    ],
    "ref": "MIR-31"
  },
  "success": true
}
```