Skip to content
← Back to Changelog

Thursday, May 23rd 2024

Block, rate limit, and challenge traffic with the Vercel Firewall

Posted by

Avatar for andrewbarba

Andrew Barba

Software Engineer

Avatar for josephcollins

Joseph Collins

Software Engineer

Avatar for danyvolk-vercelcom

Dany Volk

Software Engineer

Avatar for sueplex

Sage Abraham

Software Engineer

Avatar for naaltman

Natalie Altman

Staff Product Manager

Avatar for kevinrupert

Kevin Rupert

Product Designer

Avatar for ismaelrumzan

Ismael Rumzan

Content Developer

Avatar for danfein

Dan Fein

Sr. Technical Product Marketer

The Vercel Firewall now allows you to create custom rules to log, block, challenge, or rate limit (beta) traffic. The Firewall is available on all plans for free.

You can define custom rules to handle incoming traffic:

  • Rules can be based on 15+ fields including request path, user agent, IP address, JA4 fingerprint, geolocation, HTTP headers, and even target path.
  • Firewall configuration changes propagate within 300ms globally. If you make a mistake, you can instantly rollback to previous rules.

You can now see requests automatically protected by the Firewall, as well as managed custom rules for the WAF. You can also access managed rulesets, included our first ruleset available for Enterprise to mitigate the OWASP core risks.

Learn more about the WAF and available configuration options. Contact us if you want to try our private beta for rate limiting.

Post