1 min read


The Vercel Firewall now allows you to create custom rules to log, block, challenge, or rate limit (beta) traffic. The Firewall is available on all plans for free.
You can define custom rules to handle incoming traffic:
- Rules can be based on 15+ fields including request path, user agent, IP address, JA4 fingerprint, geolocation, HTTP headers, and even target path. 
- Firewall configuration changes propagate within 300ms globally. If you make a mistake, you can instantly rollback to previous rules. 
You can now see requests automatically protected by the Firewall, as well as managed custom rules for the WAF. You can also access managed rulesets, included our first ruleset available for Enterprise to mitigate the OWASP core risks.
Learn more about the WAF and available configuration options. Contact us if you want to try our private beta for rate limiting.







