跳转到内容
搜索文档

添加自定义策略

最后更新 查看 MarkdownAgent 设置

默认情况下,您最多可以创建 200 个策略。我们建议您创建 IP 地址列表,并在策略中引用它们,以简化策略管理。

添加策略

  1. Cloudflare One 仪表板中,前往 Firewall policies(防火墙策略) > Custom policies(自定义策略)
  2. 选择 Add a policy(添加策略)
  3. 填写新策略的信息。所有现有策略都适用于 IPv4。在填写 Value(值) 时,您可以使用托管的 IP 列表
  4. 完成后,选择 Add new policy(添加新策略)

创建处于禁用状态的策略

当您添加新策略时,该策略默认处于 Enabled(已启用) 状态。

要创建 Disabled(已禁用) 的策略,请遵循上面添加策略中的步骤,并将 Enabled 切换开关设为关闭。当策略处于禁用状态时,它将不会执行其操作,直到被设置为 Enabled

要禁用现有策略,请在 Custom policies(自定义策略) 选项卡中,将 Enabled 切换开关设为关闭。

更新策略

  1. Cloudflare One 仪表板中,前往 Firewall policies(防火墙策略) > Custom policies(自定义策略)
  2. 找到您要编辑的策略,选择三个点图标 > Edit(编辑)
  3. 对策略进行修改,然后选择 Save(保存)

删除现有策略

  1. 在列表中找到您要删除的策略。
  2. 在该行末尾选择 Delete(删除)
  3. 再次选择 Delete(删除) 确认。

API

以下是演示如何使用 API 执行特定操作的示例。

Skip 操作

下面的示例通过使用 skip 操作,阻止所有 TCP 端口,但允许一个端口 (8080)。

curl https://api.cloudflare.com/client/v4/accounts/{account_id}/rulesets \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "Example ruleset",
  "kind": "root",
  "phase": "magic_transit",
  "description": "Example ruleset description",
  "rules": [
    {
      "action": "skip",
      "action_parameters": { "ruleset": "current" },
      "expression": "tcp.dstport in { 8080 } ",
      "description": "Allow port 8080"
    },
    {
      "action": "block",
      "expression": "tcp.dstport in { 1..65535 }",
      "description": "Block all TCP ports"
    }
  ]
}'

阻止国家/地区

下面的示例使用以 ISO 3166-1 Alpha 2 格式表示的两位国家/地区代码,阻止源或目标 IP 地址来自巴西的所有数据包。

curl https://api.cloudflare.com/client/v4/accounts/{account_id}/rulesets \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "Example ruleset",
  "kind": "root",
  "phase": "magic_transit",
  "description": "Example ruleset description",
  "rules": [
    {
      "action": "block",
      "expression": "ip.src.country == \"BR\"",
      "description": "Block traffic from Brazil"
    }
  ]
}'

使用 IP 列表

Cloudflare Network Firewall 支持为 ip.srcip.dst 字段在表达式中使用列表。支持的列表为:

  • $cf.anonymizer - 匿名代理服务器
  • $cf.botnetcc - 僵尸网络命令与控制通道
  • $cf.malware - 恶意软件来源
  • $<IP_LIST_NAME> - 账户级 IP 列表的名称
curl https://api.cloudflare.com/client/v4/accounts/{account_id}/rulesets \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{
  "name": "Example ruleset",
  "kind": "root",
  "phase": "magic_transit",
  "description": "Example ruleset description",
  "rules": [
    {
      "action": "block",
      "expression": "ip.src in $cf.anonymizer",
      "description": "Block traffic from anonymizer proxies"
    }
  ]
}'

这篇文档对您有帮助吗?