Improvements to Vercel Firewall system bypass rules

Sage AbrahamSoftware Engineer

System bypass rules allow Pro and Enterprise customers to configure firewall rules to skip Vercel system mitigations, including DDoS protection, for specific IPs and CIDR ranges. Although we strongly recommend against disabling protections, customers—particularly ones that deploy a proxy in front of Vercel—may experience traffic issues that can be mitigated by deploying system bypass rules.

Improvements to the system bypass rules give customers additional control over how the rules are deployed, including:

  • Expanded support beyond production domains to preview domains

  • Added support for single domain rules for preview deployment URLs and aliases

  • Expanded project-scoped bypass rules to include all domains connected to a project

  • Increased limits for system bypass rules for Pro to 25 and Enterprise to 100 (from 3 and 5 respectively)

Learn more about the Vercel Firewall.