Write and tune Cloudflare WAF rules on your phone.

Describe a rule in plain language and let Clouder write the expression, block an address or a whole network, and adjust rate limits and request rules on the spot.

plan Rules and security settings are free to view. Creating, editing and switching rules on or off needs Clouder Pro.

Custom WAF rules

On the WAF screen, pick an action and describe what you want to match in plain language. Clouder generates the rule expression for you to read before you save it. If you would rather write the expression yourself, the editor has a reference of fields and operators built in.

Rules can be edited, switched on and off, and deleted. Cloudflare's managed rulesets can be switched on or off for each zone, and firewall events show what your rules and Cloudflare's protections did with recent traffic.

IP access rules

Block, challenge or allow traffic by IP address, IP range, country or ASN. Rules are listed per zone, with a filter by action and a search across values and notes, and every entry says what it matches and what happens to it.

Clouder checks the address, range, country code or ASN as you type, so a typo never reaches Cloudflare.

The IP Access Rules screen for example.com, recreated from the app with documentation addresses: an allowed office address, a blocked range and a managed challenge for one network.

Rate limits and rulesets

Rate limiting rules switch on and off from the app, and editing one keeps the counting settings it already had instead of resetting them. Individual rules inside a WAF ruleset can be switched on and off too, which helps when one rule starts blocking traffic it should not.

Cache, origin and configuration rules

Three editors on each zone handle the rules that change how requests are served.

Cache rules
What gets cached and for how long, with separate edge and browser settings.
Origin rules
Send matching requests to a different host, port or SNI.
Configuration rules
Override zone settings such as security level, SSL mode, Rocket Loader and email obfuscation for the requests you choose.

Anything you leave unset stays exactly as the zone has it.

Security level, SSL and Under Attack mode

Choose a zone's security level directly, not only Under Attack mode. When you switch Under Attack mode off, Clouder puts the zone back on the level it had before you turned it on.

SSL/TLS encryption mode, edge certificates and the minimum TLS version are on each zone as well, and you can manage Turnstile widgets for the forms you protect. During an incident, Under Attack mode is also one of the mitigations you can apply straight from the alert; live incidents explains how.

Free and Pro

Free

  • Firewall events and the rules on each zone
  • Security level, SSL/TLS and zone settings, read-only

Clouder Pro

  • Create, edit, switch and delete WAF and IP access rules
  • The cache, origin and configuration rule editors
  • Change security level, SSL/TLS settings and Under Attack mode

IP access rules, custom WAF rules and the cache, origin and configuration editors are part of Clouder 3.2.10 for iPhone and iPad, released on September 30, 2026.

Try it on your own account.

Free on iPhone, iPad and Android. Not affiliated with Cloudflare, Inc.