Cloudflare Network Firewall rules can behave differently depending on whether your account uses Legacy Routing or Unified Routing. Review the following changes before you upgrade to Unified Routing.
The ip.geoip.country field is no longer supported on Unified Routing. Before upgrading you must either remove these rules or rewrite any rule that uses ip.geoip.country with the ip.src.country and ip.dst.country fields instead.
| Match type | Rule using ip.geoip.country |
Equivalent rule |
|---|---|---|
| Equals | ip.geoip.country eq "US" |
ip.src.country eq "US" or ip.dst.country eq "US" |
| Does not equal | ip.geoip.country ne "US" |
ip.src.country ne "US" and ip.dst.country ne "US" |
| In a list | ip.geoip.country in {"UK" "FR"} |
ip.src.country in {"UK" "FR"} or ip.dst.country in {"UK" "FR"} |
| Not in a list | not ip.geoip.country in {"UK" "FR"} |
not ip.src.country in {"UK" "FR"} and not ip.dst.country in {"UK" "FR"} |
Legacy Routing has limited support for Layer 3 protocols. IPv6 support is limited to the ip.src and ip.dst fields. A rule is either exclusively applied to IPv4 packets or exclusively applied to IPv6 packets, based on the address family of the literal used in the rule.
On Unified Routing, as a first step to supporting IPv6 more broadly, a rule that only matched IPv6 traffic in Legacy Routing may also be evaluated against IPv4 traffic.
| Rule | Routing mode | Behavior for IPv4 | Behavior for IPv6 |
|---|---|---|---|
ip.src ne fe80::/64 |
Legacy | IPv4 packets skip this rule | Matches for all traffic not sourced from fe80::/64 |
ip.src ne fe80::/64 |
Unified | Matches for all traffic | Matches for all traffic not sourced from fe80::/64 |
To restrict the rule to only match IPv6 traffic, update the expression to ip.src in {::/0} and ip.src ne fe80::/64.
IPv6 behavior is unchanged from Legacy Routing.
On Legacy Routing, the Layer 4 protocol is inferred from the expression and only applied to packets of that protocol. tcp.srcport eq 80 and tcp.srcport ne 80 both apply only to TCP traffic. Packets of other protocols, for example UDP, will not match the expression.
On Unified Routing, Cloudflare Network Firewall does not infer the protocol, and rules must specify a protocol in the expression explicitly. tcp.srcport eq 80 still only applies to TCP traffic, but tcp.srcport ne 80 now matches both TCP and UDP traffic. To restrict the rule to only match TCP traffic, update the expression to ip.proto eq "tcp" and tcp.srcport eq 80.