---
title: Firewall
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/terraform)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# Firewall

#### FirewallLockdowns

#### resource cloudflare\_zone\_lockdown

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

urls: Set\[String]

The URLs to include in the current WAF override. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20urls>)

<details>

<summary>

configurations: List\[Attributes]

A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of <code>ip</code> or <code>ip_range</code> configurations.

</summary>

target?: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the Zone Lockdown rule.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20target">Link to this property</a>

value?: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configurations>)

##### optional Expand Collapse

description?: String

An informative summary of the rule. This value is sanitized and any tags will be removed.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

priority?: Float64

The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20priority>)

paused?: Bool

When true, indicates that the rule is currently paused.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20paused>)

##### computed Expand Collapse

id: String

The unique identifier of the Zone Lockdown rule.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_on: Time

The timestamp of when the rule was created.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_on>)

modified\_on: Time

The timestamp of when the rule was last modified.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

### cloudflare\_zone\_lockdown

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_zone_lockdown" "example_zone_lockdown" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  configurations = [{
    target = "ip"
    value = "198.51.100.4"
  }]
  urls = ["shop.example.com/*"]
  description = "Prevent multiple login failures to mitigate brute force attacks"
  paused = false
  priority = 5
}
```

#### data cloudflare\_zone\_lockdown

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

lock\_downs\_id?: String

The unique identifier of the Zone Lockdown rule.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20lock_downs_id>)

<details>

<summary>

filter?: Attributes

</summary>

created\_on?: Time

The timestamp of when the rule was created.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20created_on">Link to this property</a>

description?: String

A string to search for in the description of existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20description">Link to this property</a>

description\_search?: String

A string to search for in the description of existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20description_search">Link to this property</a>

ip?: String

A single IP address to search for in existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip">Link to this property</a>

ip\_range\_search?: String

A single IP address range to search for in existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip_range_search">Link to this property</a>

ip\_search?: String

A single IP address to search for in existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ip_search">Link to this property</a>

modified\_on?: Time

The timestamp of when the rule was last modified.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20modified_on">Link to this property</a>

priority?: Float64

The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20priority">Link to this property</a>

uri\_search?: String

A single URI to search for in the list of URLs of existing rules.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20uri_search">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The unique identifier of the Zone Lockdown rule.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_on: Time

The timestamp of when the rule was created.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_on>)

description: String

An informative summary of the rule.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

modified\_on: Time

The timestamp of when the rule was last modified.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

paused: Bool

When true, indicates that the rule is currently paused.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20paused>)

urls: Set\[String]

The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20urls>)

<details>

<summary>

configurations: List\[Attributes]

A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of <code>ip</code> or <code>ip_range</code> configurations.

</summary>

target: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the Zone Lockdown rule.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configurations>)

### cloudflare\_zone\_lockdown

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zone_lockdown" "example_zone_lockdown" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  lock_downs_id = "372e67954025e0ba6aaa6d586b9e0b59"
}
```

#### data cloudflare\_zone\_lockdowns

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

created\_on?: Time

The timestamp of when the rule was created.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20created_on>)

description?: String

A string to search for in the description of existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20description>)

description\_search?: String

A string to search for in the description of existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20description_search>)

ip?: String

A single IP address to search for in existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip>)

ip\_range\_search?: String

A single IP address range to search for in existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip_range_search>)

ip\_search?: String

A single IP address to search for in existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20ip_search>)

modified\_on?: Time

The timestamp of when the rule was last modified.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20modified_on>)

priority?: Float64

The priority of the rule to control the processing order. A lower number indicates higher priority. If not provided, any rules with a configured priority will be processed before rules without a priority.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20priority>)

uri\_search?: String

A single URI to search for in the list of URLs of existing rules.

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20uri_search>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier of the Zone Lockdown rule.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

configurations: List\[Attributes]

A list of IP addresses or CIDR ranges that will be allowed to access the URLs specified in the Zone Lockdown rule. You can include any number of <code>ip</code> or <code>ip_range</code> configurations.

</summary>

target: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the Zone Lockdown rule.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configurations%20%3E%20(attribute)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configurations">Link to this property</a>

created\_on: Time

The timestamp of when the rule was created.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_on">Link to this property</a>

description: String

An informative summary of the rule.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

modified\_on: Time

The timestamp of when the rule was last modified.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_on">Link to this property</a>

paused: Bool

When true, indicates that the rule is currently paused.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20paused">Link to this property</a>

urls: Set\[String]

The URLs to include in the rule definition. You can use wildcards. Each entered URL will be escaped before use, which means you can only use simple wildcard patterns.

<a href="#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20urls">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.lockdowns%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_zone\_lockdowns

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_zone_lockdowns" "example_zone_lockdowns" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  created_on = "2014-01-01T05:20:00.12345Z"
  description = "endpoints"
  description_search = "endpoints"
  ip = "1.2.3.4"
  ip_range_search = "1.2.3.0/16"
  ip_search = "1.2.3.4"
  modified_on = "2014-01-01T05:20:00.12345Z"
  priority = 5
  uri_search = "/some/path"
}
```

#### FirewallRules

#### resource cloudflare\_firewall\_rule

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

<details>

<summary>

action: Attributes

The action to perform when the threshold of matched traffic within the configured period is exceeded.

</summary>

mode?: String

The action to perform.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action%20%3E%20(attribute)%20mode">Link to this property</a>

<details>

<summary>

response?: Attributes

A custom content type and reponse to return when the threshold is exceeded. The custom response configured in this object will override the custom error for the zone. This object is optional. Notes: If you omit this object, Cloudflare will use the default HTML error page. If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone challenge pages and you should not provide the “response” object.

</summary>

body?: String

The response body to return. The value must conform to the configured content type.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action%20%3E%20(attribute)%20response%20%3E%20(attribute)%20body">Link to this property</a>

content\_type?: String

The content type of the body. Must be one of the following: <code>text/plain</code>, <code>text/xml</code>, or <code>application/json</code>.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action%20%3E%20(attribute)%20response%20%3E%20(attribute)%20content_type">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action%20%3E%20(attribute)%20response">Link to this property</a>

timeout?: Float64

The time in seconds during which Cloudflare will perform the mitigation action. Must be an integer value greater than or equal to the period. Notes: If “mode” is “challenge”, “managed\_challenge”, or “js\_challenge”, Cloudflare will use the zone’s Challenge Passage time and you should not provide this value.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action%20%3E%20(attribute)%20timeout">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20action>)

<details>

<summary>

filter: Attributes

</summary>

id: String

The unique identifier of the filter.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20id">Link to this property</a>

description?: String

An informative summary of the filter.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20description">Link to this property</a>

expression?: String

The filter expression. For more information, refer to <a href="https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/">Expressions</a>.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20expression">Link to this property</a>

paused?: Bool

When true, indicates that the filter is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20paused">Link to this property</a>

ref?: String

A short reference tag. Allows you to select related filters.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The unique identifier of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

description: String

An informative summary of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

paused: Bool

When true, indicates that the firewall rule is currently paused.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20paused>)

priority: Float64

The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20priority>)

ref: String

A short reference tag. Allows you to select related firewall rules.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20ref>)

products: List\[String]

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20products>)

### cloudflare\_firewall\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_firewall_rule" "example_firewall_rule" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  action = {
    mode = "challenge"
    response = {
      body = "<error>This request has been rate-limited.</error>"
      content_type = "text/xml"
    }
    timeout = 86400
  }
  filter = {
    description = "Restrict access from these browsers on this address range."
    expression = "(http.request.uri.path ~ \".*wp-login.php\" or http.request.uri.path ~ \".*xmlrpc.php\") and ip.addr ne 172.16.22.155"
    paused = false
    ref = "FIL-100"
  }
}
```

#### data cloudflare\_firewall\_rule

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

rule\_id?: String

The unique identifier of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20rule_id>)

##### computed Expand Collapse

id: String

The unique identifier of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

action: String

The action to apply to a matched request. The `log` action is only available on an Enterprise plan.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20action>)

description: String

An informative summary of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

paused: Bool

When true, indicates that the firewall rule is currently paused.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20paused>)

priority: Float64

The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20priority>)

ref: String

A short reference tag. Allows you to select related firewall rules.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ref>)

products: List\[String]

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20products>)

### cloudflare\_firewall\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_firewall_rule" "example_firewall_rule" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  rule_id = "372e67954025e0ba6aaa6d586b9e0b60"
}
```

#### data cloudflare\_firewall\_rules

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

action?: String

The action to search for. Must be an exact match.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20action>)

description?: String

A case-insensitive string to find in the description.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20description>)

id?: String

The unique identifier of the firewall rule.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20id>)

paused?: Bool

When true, indicates that the firewall rule is currently paused.

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20paused>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier of the firewall rule.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

action: String

The action to apply to a matched request. The <code>log</code> action is only available on an Enterprise plan.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20action">Link to this property</a>

description: String

An informative summary of the firewall rule.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

<details>

<summary>

filter: Attributes

</summary>

id: String

The unique identifier of the filter.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20id">Link to this property</a>

description: String

An informative summary of the filter.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20description">Link to this property</a>

expression: String

The filter expression. For more information, refer to <a href="https://developers.cloudflare.com/ruleset-engine/rules-language/expressions/">Expressions</a>.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20expression">Link to this property</a>

paused: Bool

When true, indicates that the filter is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20paused">Link to this property</a>

ref: String

A short reference tag. Allows you to select related filters.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20ref">Link to this property</a>

deleted: Bool

When true, indicates that the firewall rule was deleted.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20deleted">Link to this property</a>

</details>

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20filter">Link to this property</a>

paused: Bool

When true, indicates that the firewall rule is currently paused.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20paused">Link to this property</a>

priority: Float64

The priority of the rule. Optional value used to define the processing order. A lower number indicates a higher priority. If not provided, rules with a defined priority will be processed before rules without a priority.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20priority">Link to this property</a>

products: List\[String]

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20products">Link to this property</a>

ref: String

A short reference tag. Allows you to select related firewall rules.

<a href="#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20ref">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_firewall\_rules

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_firewall_rules" "example_firewall_rules" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  id = "372e67954025e0ba6aaa6d586b9e0b60"
  action = "block"
  description = "mir"
  paused = false
}
```

#### FirewallAccess Rules

#### resource cloudflare\_access\_rule

##### required Expand Collapse

mode: String

The action to apply to a matched request.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mode>)

<details>

<summary>

configuration: Attributes

The rule configuration.

</summary>

target?: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value?: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration>)

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

notes?: String

An informative summary of the rule, typically used as a reminder or explanation.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20notes>)

##### computed Expand Collapse

id: String

The unique identifier of the IP Access rule.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

created\_on: Time

The timestamp of when the rule was created.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20created_on>)

modified\_on: Time

The timestamp of when the rule was last modified.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20modified_on>)

allowed\_modes: List\[String]

The available actions that a rule can apply to a matched request.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20allowed_modes>)

<details>

<summary>

scope: Attributes

All zones owned by the user will have the rule applied.

</summary>

id: String

Defines an identifier.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20id">Link to this property</a>

email: String

The contact email address of the user.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20email">Link to this property</a>

type: String

Defines the scope of the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20scope>)

### cloudflare\_access\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_access_rule" "example_access_rule" {
  configuration = {
    target = "ip"
    value = "198.51.100.4"
  }
  mode = "challenge"
  zone_id = "zone_id"
  notes = "This rule is enabled because of an event that occurred on date X."
}
```

#### data cloudflare\_access\_rule

##### optional Expand Collapse

rule\_id?: String

Unique identifier for a rule.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20rule_id>)

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

<details>

<summary>

filter?: Attributes

</summary>

<details>

<summary>

configuration?: Attributes

</summary>

target?: String

Defines the target to search in existing rules.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value?: String

Defines the target value to search for in existing rules: an IP address, an IP address range, or a country code, depending on the provided <code>configuration.target</code>. Notes: You can search for a single IPv4 address, an IP address range with a subnet of ‘/16’ or ‘/24’, or a two-letter ISO-3166-1 alpha-2 country code.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20configuration">Link to this property</a>

direction?: String

Defines the direction used to sort returned rules.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20direction">Link to this property</a>

match?: String

Defines the search requirements. When set to <code>all</code>, all the search requirements must match. When set to <code>any</code>, only one of the search requirements has to match.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20match">Link to this property</a>

mode?: String

The action to apply to a matched request.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20mode">Link to this property</a>

notes?: String

Defines the string to search for in the notes of existing IP Access rules. Notes: For example, the string ‘attack’ would match IP Access rules with notes ‘Attack 26/02’ and ‘Attack 27/02’. The search is case insensitive.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20notes">Link to this property</a>

order?: String

Defines the field used to sort returned rules.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20order">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

Unique identifier for a rule.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

created\_on: Time

The timestamp of when the rule was created.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20created_on>)

mode: String

The action to apply to a matched request.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mode>)

modified\_on: Time

The timestamp of when the rule was last modified.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20modified_on>)

notes: String

An informative summary of the rule, typically used as a reminder or explanation.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20notes>)

allowed\_modes: List\[String]

The available actions that a rule can apply to a matched request.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20allowed_modes>)

<details>

<summary>

configuration: Attributes

The rule configuration.

</summary>

target: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration>)

<details>

<summary>

scope: Attributes

All zones owned by the user will have the rule applied.

</summary>

id: String

Defines an identifier.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20id">Link to this property</a>

email: String

The contact email address of the user.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20email">Link to this property</a>

type: String

Defines the scope of the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20type">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20scope>)

### cloudflare\_access\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_access_rule" "example_access_rule" {
  rule_id = "023e105f4ecef8ad9ca31a8372d0c353"
  account_id = "account_id"
  zone_id = "zone_id"
}
```

#### data cloudflare\_access\_rules

##### optional Expand Collapse

account\_id?: String

The Account ID to use for this endpoint. Mutually exclusive with the Zone ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20account_id>)

zone\_id?: String

The Zone ID to use for this endpoint. Mutually exclusive with the Account ID.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

direction?: String

Defines the direction used to sort returned rules.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20direction>)

mode?: String

The action to apply to a matched request.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20mode>)

notes?: String

Defines the string to search for in the notes of existing IP Access rules. Notes: For example, the string ‘attack’ would match IP Access rules with notes ‘Attack 26/02’ and ‘Attack 27/02’. The search is case insensitive.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20notes>)

order?: String

Defines the field used to sort returned rules.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20order>)

<details>

<summary>

configuration?: Attributes

</summary>

target?: String

Defines the target to search in existing rules.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value?: String

Defines the target value to search for in existing rules: an IP address, an IP address range, or a country code, depending on the provided <code>configuration.target</code>. Notes: You can search for a single IPv4 address, an IP address range with a subnet of ‘/16’ or ‘/24’, or a two-letter ISO-3166-1 alpha-2 country code.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20configuration>)

match?: String

Defines the search requirements. When set to `all`, all the search requirements must match. When set to `any`, only one of the search requirements has to match.

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20match>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier of the IP Access rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

allowed\_modes: List\[String]

The available actions that a rule can apply to a matched request.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20allowed_modes">Link to this property</a>

<details>

<summary>

configuration: Attributes

The rule configuration.

</summary>

target: String

The configuration target. You must set the target to <code>ip</code> when specifying an IP address in the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The IP address to match. This address will be compared to the IP address of incoming requests.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration">Link to this property</a>

mode: String

The action to apply to a matched request.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20mode">Link to this property</a>

created\_on: Time

The timestamp of when the rule was created.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20created_on">Link to this property</a>

modified\_on: Time

The timestamp of when the rule was last modified.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20modified_on">Link to this property</a>

notes: String

An informative summary of the rule, typically used as a reminder or explanation.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20notes">Link to this property</a>

<details>

<summary>

scope: Attributes

All zones owned by the user will have the rule applied.

</summary>

id: String

Defines an identifier.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20id">Link to this property</a>

email: String

The contact email address of the user.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20email">Link to this property</a>

type: String

Defines the scope of the rule.

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scope%20%3E%20(attribute)%20type">Link to this property</a>

</details>

<a href="#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20scope">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.access_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_access\_rules

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_access_rules" "example_access_rules" {
  account_id = "account_id"
  zone_id = "zone_id"
  configuration = {
    target = "ip"
    value = "198.51.100.4"
  }
  direction = "desc"
  mode = "challenge"
  notes = "my note"
  order = "mode"
}
```

#### FirewallUA Rules

#### resource cloudflare\_user\_agent\_blocking\_rule

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20zone_id>)

mode: String

The action to apply to a matched request.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20mode>)

<details>

<summary>

configuration: Attributes

</summary>

target?: String

The configuration target. You must set the target to <code>ua</code> when specifying a user agent in the rule.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value?: String

the user agent to exactly match

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20configuration>)

##### optional Expand Collapse

description?: String

An informative summary of the rule. This value is sanitized and any tags will be removed.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20description>)

paused?: Bool

When true, indicates that the rule is currently paused.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20paused>)

##### computed Expand Collapse

id: String

The unique identifier of the User Agent Blocking rule.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20resource)%20%3E%20(attribute)%20id>)

### cloudflare\_user\_agent\_blocking\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
resource "cloudflare_user_agent_blocking_rule" "example_user_agent_blocking_rule" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  configuration = {
    target = "ua"
    value = "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
  }
  mode = "challenge"
  description = "Prevent multiple login failures to mitigate brute force attacks"
  paused = false
}
```

#### data cloudflare\_user\_agent\_blocking\_rule

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

ua\_rule\_id?: String

The unique identifier of the User Agent Blocking rule.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20ua_rule_id>)

<details>

<summary>

filter?: Attributes

</summary>

description?: String

A string to search for in the description of existing rules.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20description">Link to this property</a>

paused?: Bool

When true, indicates that the rule is currently paused.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20paused">Link to this property</a>

user\_agent?: String

A string to search for in the user agent values of existing rules.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter%20%3E%20(attribute)%20user_agent">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20filter>)

##### computed Expand Collapse

id: String

The unique identifier of the User Agent Blocking rule.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20id>)

description: String

An informative summary of the rule.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20description>)

mode: String

The action to apply to a matched request.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20mode>)

paused: Bool

When true, indicates that the rule is currently paused.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20paused>)

<details>

<summary>

configuration: Attributes

The configuration object for the current rule.

</summary>

target: String

The configuration target for this rule. You must set the target to <code>ua</code> for User Agent Blocking rules.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The exact user agent string to match. This value will be compared to the received <code>User-Agent</code> HTTP header value.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-single)%20%3E%20(attribute)%20configuration>)

### cloudflare\_user\_agent\_blocking\_rule

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_user_agent_blocking_rule" "example_user_agent_blocking_rule" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  ua_rule_id = "372e67954025e0ba6aaa6d586b9e0b59"
}
```

#### data cloudflare\_user\_agent\_blocking\_rules

##### required Expand Collapse

zone\_id: String

Defines an identifier.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20zone_id>)

##### optional Expand Collapse

description?: String

A string to search for in the description of existing rules.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20description>)

paused?: Bool

When true, indicates that the rule is currently paused.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20paused>)

user\_agent?: String

A string to search for in the user agent values of existing rules.

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20user_agent>)

max\_items?: Int64

Max items to fetch, default: 1000

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20max_items>)

##### computed Expand Collapse

<details>

<summary>

result: List\[Attributes]

The items returned by the data source

</summary>

id: String

The unique identifier of the User Agent Blocking rule.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20id">Link to this property</a>

<details>

<summary>

configuration: Attributes

The configuration object for the current rule.

</summary>

target: String

The configuration target for this rule. You must set the target to <code>ua</code> for User Agent Blocking rules.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20target">Link to this property</a>

value: String

The exact user agent string to match. This value will be compared to the received <code>User-Agent</code> HTTP header value.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration%20%3E%20(attribute)%20value">Link to this property</a>

</details>

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20configuration">Link to this property</a>

description: String

An informative summary of the rule.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20description">Link to this property</a>

mode: String

The action to apply to a matched request.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20mode">Link to this property</a>

paused: Bool

When true, indicates that the rule is currently paused.

<a href="#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result%20%3E%20(attribute)%20paused">Link to this property</a>

</details>

[Link to this property](<#(resource)%20firewall.ua_rules%20%3E%20(terraform%20datasource-plural)%20%3E%20(attribute)%20result>)

### cloudflare\_user\_agent\_blocking\_rules

Terraform

HTTPTypeScriptPythonGoTerraform

```
data "cloudflare_user_agent_blocking_rules" "example_user_agent_blocking_rules" {
  zone_id = "023e105f4ecef8ad9ca31a8372d0c353"
  description = "abusive"
  paused = false
  user_agent = "Safari"
}
```