> For the complete documentation index, see [llms.txt](https://corey-bui.gitbook.io/cloudflare-guides/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://corey-bui.gitbook.io/cloudflare-guides/waf-web-application-firewall/guides/rate-limiting-guide.md).

# Rate Limiting Guide

## Overview&#x20;

Cloudflare Rate Limiting automatically will identify and stop excessive requests from specific URLs or entire domains. Common uses for Rate Limiting are for DDoS protection, Brute-force protection, API calls, or any resources that make intensive database operations at your origin.

## Analytics&#x20;

You can view the analytics for Rate Limiting in Analytics > Security.&#x20;

## Getting Started

### Rule Setting

Start your first rate limiting rule by setting rule settings.

Rule- Name your rule with something that reflects the fields.

Matching the URL- Match the URL that you with the Rate Limiting rule to apply to and add how many requests per 'unit of time'.

![](https://374896401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV6MMrAUfaxxHHZ312kIp%2Fuploads%2FdH9Pn4V5Cu2OybmvrsgX%2Frule%20settings%20rate%20limiting.png?alt=media\&token=3c373412-e648-4a0f-8627-eb1dd0bfc9ab)

### Advanced Rule Setting

**Choose a method**-&#x20;

**HTTP methods**

GET- Get method requests a representation of the specified source. Get only retrieves data.&#x20;

PUT- Put method replaces all current representations of the target resources with the request payload.

DELETE- Deletes the specified resource.

PATCH- Applies partial modifications to the resource.

HEAD- Method asks for a response identical to GET, but without the response body.

HTTP Header- Headers ensure that the correct data is returned to the browser.

Headers contain "Content-Type" which tells the browser the type of content that is returned. Another common one is "Server:" which contains info about the software that is used to handle the HTTP requests.

![](https://374896401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV6MMrAUfaxxHHZ312kIp%2Fuploads%2FgXhbNpzp480FuX6eD5iS%2Fadvanced%20criteria%20rate%20limiting.png?alt=media\&token=b979760b-33aa-4f14-822a-321d4536a270)

**Choose Response-**

The options for responses are: Managed Challenge, Block, Legacy CAPTCHA, Log, and JS Challenge.

![](https://374896401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV6MMrAUfaxxHHZ312kIp%2Fuploads%2FkaqVF4l6umE610Y0NyKo%2Fresponseratelimiting.PNG?alt=media\&token=988509df-e387-47e1-a26a-d80c29d2b95e)

**Bypass Rule-**

Select URLs that you don't want the response to apply to.

![](https://374896401-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FV6MMrAUfaxxHHZ312kIp%2Fuploads%2F37ZT95mRSnZG5SCJfqyb%2Fbypass%20rule%20rate%20limiting.PNG?alt=media\&token=6e7c6eba-ce95-4c36-9aad-2116e1538561)

##
