---
title: Create firewall rules
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/python)

[Firewall](https://developers.cloudflare.com/api/python/resources/firewall)

[Rules](https://developers.cloudflare.com/api/python/resources/firewall/subresources/rules)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Create firewall rules

Deprecated: The Firewall Rules API is deprecated in favour of using the Ruleset Engine. See https://developers.cloudflare.com/fundamentals/api/reference/deprecations/#firewall-rules-api-and-filters-api for full details.

firewall.rules.create(RuleCreateParams\*\*kwargs) -> SyncSinglePage\[[FirewallRule](<https://developers.cloudflare.com/api/python/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)>)]

POST/zones/{zone\_id}/firewall/rules

**This endpoint has been deprecated and returns 410 Gone. Please use the [Rulesets API](https://developers.cloudflare.com/ruleset-engine/) instead.**

Create one or more firewall rules.

##### Security

<details>

<summary>API Token</summary>



The preferred authorization scheme for interacting with the Cloudflare API. <a href="https://developers.cloudflare.com/fundamentals/api/get-started/create-token/">Create a token</a>.

**Example:**<code>Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY</code>

</details>

<details>

<summary>API Email + API Key</summary>



The previous authorization scheme for interacting with the Cloudflare API, used in conjunction with a Global API key.

**Example:**<code>X-Auth-Email: user@example.com</code>

The previous authorization scheme for interacting with the Cloudflare API. When possible, use API tokens instead of Global API keys.

**Example:**<code>X-Auth-Key: 144c9defac04969c7bfad8efaa8ea194</code>

</details>

##### Accepted Permissions (at least one required)

`Firewall Services Write`

##### ParametersExpand Collapse

zone\_id: str

Defines an identifier.

maxLength32

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20zone_id%20%3E%20(schema)>)

<details>

<summary>

action: <a href="https://developers.cloudflare.com/api/python/resources/firewall/subresources/rules/methods/create#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)">Action</a>

The action to perform when the threshold of matched traffic within the configured period is exceeded.

</summary>

<details>

<summary>

mode: Optional\[Literal\["simulate", "ban", "challenge", 2 more]]

The action to perform.

</summary>

One of the following:

"simulate"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%200">Link to this property</a>

"ban"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%201">Link to this property</a>

"challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%202">Link to this property</a>

"js\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%203">Link to this property</a>

"managed\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode%20%3E%20(member)%204">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20mode">Link to this property</a>

<details>

<summary>

response: Optional\[ActionResponse]

A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional. Notes: If you omit this object, Cloudflare will use the default HTML error page. If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone challenge pages and you should not provide the “response” object.

</summary>

body: Optional\[str]

The response body to return. The value must conform to the configured content type.

maxLength10240

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response%20%3E%20(property)%20body">Link to this property</a>

content\_type: Optional\[str]

The content type of the body. Must be one of the following: <code>text/plain</code>, <code>text/xml</code>, or <code>application/json</code>.

maxLength50

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response%20%3E%20(property)%20content_type">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20response">Link to this property</a>

timeout: Optional\[float]

The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period. Notes: If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone’s Challenge Passage time and you should not provide this value.

maximum86400

minimum1

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)%20%3E%20(property)%20timeout">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20action%20%3E%20(schema)>)

<details>

<summary>

filter: <a href="https://developers.cloudflare.com/api/python/resources/filters#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)">FirewallFilterParam</a>

</summary>

id: Optional\[str]

The unique identifier of the filter.

maxLength32

minLength32

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)%20%2B%20(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

description: Optional\[str]

An informative summary of the filter.

maxLength500

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)%20%2B%20(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

expression: Optional\[str]

The filter expression. For more information, refer to <a href="https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/">Expressions</a>.

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)%20%2B%20(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20expression">Link to this property</a>

paused: Optional\[bool]

When true, indicates that the filter is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)%20%2B%20(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20paused">Link to this property</a>

ref: Optional\[str]

A short reference tag. Allows you to select related filters.

maxLength50

<a href="#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)%20%2B%20(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(method)%20create%20%3E%20(params)%20default%20%3E%20(param)%20filter%20%3E%20(schema)>)

##### ReturnsExpand Collapse

<details>

<summary>

class FirewallRule: …

</summary>

id: Optional\[str]

The unique identifier of the firewall rule.

maxLength32

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

action: Optional\[Action]

The action to apply to a matched request. The <code>log</code> action is only available on an Enterprise plan.

</summary>

One of the following:

"block"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"js\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"managed\_challenge"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"allow"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"log"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"bypass"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action%20%2B%20(resource)%20rate_limits%20%3E%20(model)%20action%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20action">Link to this property</a>

description: Optional\[str]

An informative summary of the firewall rule.

maxLength500

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

<details>

<summary>

filter: Optional\[Filter]

</summary>

One of the following:

<details>

<summary>

class FirewallFilter: …

</summary>

id: Optional\[str]

The unique identifier of the filter.

maxLength32

minLength32

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

description: Optional\[str]

An informative summary of the filter.

maxLength500

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20description">Link to this property</a>

expression: Optional\[str]

The filter expression. For more information, refer to <a href="https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/">Expressions</a>.

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20expression">Link to this property</a>

paused: Optional\[bool]

When true, indicates that the filter is currently paused.

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20paused">Link to this property</a>

ref: Optional\[str]

A short reference tag. Allows you to select related filters.

maxLength50

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)%20%3E%20(property)%20ref">Link to this property</a>

</details>

<a href="#(resource)%20filters%20%3E%20(model)%20firewall_filter%20%3E%20(schema)">Link to this property</a>

<details>

<summary>

class DeletedFilter: …

</summary>

id: str

The unique identifier of the filter.

maxLength32

minLength32

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

deleted: bool

When true, indicates that the firewall rule was deleted.

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)%20%3E%20(property)%20deleted">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20deleted_filter%20%3E%20(schema)">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20filter">Link to this property</a>

paused: Optional\[bool]

When true, indicates that the firewall rule is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20paused">Link to this property</a>

priority: Optional\[float]

The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority.

maximum2147483647

minimum0

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20priority">Link to this property</a>

<details>

<summary>

products: Optional\[List\[<a href="https://developers.cloudflare.com/api/python/resources/firewall#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)">Product</a>]]

</summary>

One of the following:

"zoneLockdown"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

"uaBlock"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

"bic"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%202">Link to this property</a>

"hot"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%203">Link to this property</a>

"securityLevel"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%204">Link to this property</a>

"rateLimit"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%205">Link to this property</a>

"waf"

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20product%20%3E%20(schema)%20%3E%20(member)%206">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20products">Link to this property</a>

ref: Optional\[str]

A short reference tag. Allows you to select related firewall rules.

maxLength50

<a href="#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)%20%3E%20(property)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(model)%20firewall_rule%20%3E%20(schema)>)

### Create firewall rules

Python

HTTPTypeScriptPythonGoTerraform

```
import os
from cloudflare import Cloudflare

client = Cloudflare(
    api_token=os.environ.get("CLOUDFLARE_API_TOKEN"),  # This is the default and can be omitted
)
page = client.firewall.rules.create(
    zone_id="023e105f4ecef8ad9ca31a8372d0c353",
    action={},
    filter={},
)
page = page.result[0]
print(page.id)
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "372e67954025e0ba6aaa6d586b9e0b60",
      "action": "block",
      "description": "Blocks traffic identified during investigation for MIR-31",
      "filter": {
        "id": "372e67954025e0ba6aaa6d586b9e0b61",
        "description": "Restrict access from these browsers on this address range.",
        "expression": "(http.request.uri.path ~ \".*wp-login.php\" or http.request.uri.path ~ \".*xmlrpc.php\") and ip.addr ne 172.16.22.155",
        "paused": false,
        "ref": "FIL-100"
      },
      "paused": false,
      "priority": 50,
      "products": [
        "waf"
      ],
      "ref": "MIR-31"
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "result": [
    {
      "id": "372e67954025e0ba6aaa6d586b9e0b60",
      "action": "block",
      "description": "Blocks traffic identified during investigation for MIR-31",
      "filter": {
        "id": "372e67954025e0ba6aaa6d586b9e0b61",
        "description": "Restrict access from these browsers on this address range.",
        "expression": "(http.request.uri.path ~ \".*wp-login.php\" or http.request.uri.path ~ \".*xmlrpc.php\") and ip.addr ne 172.16.22.155",
        "paused": false,
        "ref": "FIL-100"
      },
      "paused": false,
      "priority": 50,
      "products": [
        "waf"
      ],
      "ref": "MIR-31"
    }
  ],
  "success": true,
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```