How to Configure Cloudflare WAF for Malaysian Websites
Setting up custom firewall rules to block aggressive scrapers, wp-login rate limiting, and ASN blocking.
Cloudflare's Web Application Firewall (WAF) is your first line of defense. A properly configured WAF can block 90% of malicious traffic before it ever reaches your Malaysian server.
1. Protecting the Admin Area
Your /wp-admin/ and wp-login.php URLs should never be publicly accessible to the entire world. Create a WAF custom rule:
- Field: URI Path
- Operator: contains
- Value:
wp-login.php - OR Field: URI Path contains
/wp-admin/ - Action: Managed Challenge (or Block)
To be stricter, you can add an exclusion for your specific office IP address or require a country match for "Malaysia".
2. Rate Limiting API Endpoints
Aggressive scrapers and bots target /wp-json/ and WooCommerce API endpoints. Set up a Rate Limiting rule to restrict excessive requests:
- If URI Path contains:
/wp-json/ - Rate Limit: 50 requests per 10 seconds per IP.
- Action: Block for 1 hour.
3. Blocking High-Risk ASNs
Many attacks originate from cheap cloud hosting providers rather than residential ISPs. You can block traffic originating from known bulletproof hosting ASNs or specific countries if your business is strictly local.
In the WAF, create a rule targeting ip.geoip.asnum (Autonomous System Number) or use the Threat Score feature to block IPs with a high risk rating.
Need Expert Help?
A misconfigured firewall can block legitimate customers. JagaWeb provides enterprise-grade WAF setups for brands like Trexon Energy. Get our RM5,000 Ownership & Access Review for advanced security configuration, or subscribe to our RM450/month Care Plan for 24/7 managed defense. Contact us today.
Ready to verify who owns your website?
Replace uncertainty with a decision-ready ownership and access report. The fixed Ownership & Access Review is RM1,500 before SST and includes a 30-day action plan.