Skip to content

Account-level WAF configuration

Last updated View as MarkdownAgent setup

The account-level Web Application Firewall (WAF) configuration allows you to define a configuration once and apply it to multiple Enterprise zones in your account. Instead of configuring each zone individually, you create rulesets at the account level and use expressions to control which zones and traffic they apply to.

For example, you can deploy a single ruleset that applies to /admin/* URI paths across both example.com and example.net. Rulesets can target all incoming traffic or a specific subset.

At the account level, WAF rules are grouped into rulesets. You can perform the following operations:

Availability

Account-level WAF configuration requires an Enterprise plan.

Custom rulesets Rate limiting rulesets Managed rulesets
Availability Yes Yes Yes
Maximum number of rulesets 10 10 Not applicable
Maximum number of rules per ruleset 100 10 Not applicable

The values in the table are the default limits. Your limits may vary based on the terms of your Enterprise contract.

Custom rulesets also have a total quota of 1,000 rules across all rulesets that a request traverses.

Was this helpful?