Write and tune Cloudflare WAF rules on your phone.
Describe a rule in plain language and let Clouder write the expression, block an address or a whole network, and adjust rate limits and request rules on the spot.
plan Rules and security settings are free to view. Creating, editing and switching rules on or off needs Clouder Pro.
Description
Expression
Describe what to match in plain language.
Requests matching this expression get the settings below.
Action
Custom WAF rules
On the WAF screen, pick an action and describe what you want to match in plain language. Clouder generates the rule expression for you to read before you save it. If you would rather write the expression yourself, the editor has a reference of fields and operators built in.
Rules can be edited, switched on and off, and deleted. Cloudflare's managed rulesets can be switched on or off for each zone, and firewall events show what your rules and Cloudflare's protections did with recent traffic.
IP access rules
Block, challenge or allow traffic by IP address, IP range, country or ASN. Rules are listed per zone, with a filter by action and a search across values and notes, and every entry says what it matches and what happens to it.
Clouder checks the address, range, country code or ASN as you type, so a typo never reaches Cloudflare.
Rules 3/3
office
scanner
hosting provider
The IP Access Rules screen for example.com, recreated from the app with documentation addresses: an allowed office address, a blocked range and a managed challenge for one network.
Rate limits and rulesets
Rate limiting rules switch on and off from the app, and editing one keeps the counting settings it already had instead of resetting them. Individual rules inside a WAF ruleset can be switched on and off too, which helps when one rule starts blocking traffic it should not.
Cache, origin and configuration rules
Three editors on each zone handle the rules that change how requests are served.
- Cache rules
- What gets cached and for how long, with separate edge and browser settings.
- Origin rules
- Send matching requests to a different host, port or SNI.
- Configuration rules
- Override zone settings such as security level, SSL mode, Rocket Loader and email obfuscation for the requests you choose.
Anything you leave unset stays exactly as the zone has it.
Security level, SSL and Under Attack mode
Choose a zone's security level directly, not only Under Attack mode. When you switch Under Attack mode off, Clouder puts the zone back on the level it had before you turned it on.
SSL/TLS encryption mode, edge certificates and the minimum TLS version are on each zone as well, and you can manage Turnstile widgets for the forms you protect. During an incident, Under Attack mode is also one of the mitigations you can apply straight from the alert; live incidents explains how.
Free and Pro
Free
- Firewall events and the rules on each zone
- Security level, SSL/TLS and zone settings, read-only
Clouder Pro
- Create, edit, switch and delete WAF and IP access rules
- The cache, origin and configuration rule editors
- Change security level, SSL/TLS settings and Under Attack mode
IP access rules, custom WAF rules and the cache, origin and configuration editors are part of Clouder 3.2.10 for iPhone and iPad, released on September 30, 2026.