# Vercel Firewall

The Vercel Firewall is a robust, multi-layered security system designed to protect your applications from a wide range of threats. Every incoming request goes through the following firewall layers:

- [Platform-wide firewall](/content/docs/vercel-firewall#platform-wide-firewall/index.html): With [DDoS mitigation](/content/docs/vercel-firewall/ddos-mitigation/index.html), it protects against large-scale attacks such as DDoS and TCP floods and is available for free for all customers without any configuration required.
- [Web Application Firewall (WAF)](/content/docs/vercel-firewall#vercel-waf/index.html): A customizable layer for fine-tuning security measures with logic tailored to your needs and [observability](/content/docs/vercel-firewall#observability/index.html) into your web traffic.

### [Concepts](/content/docs/vercel-firewall#concepts/index.html)

Understand the fundamentals:

- How [Vercel protects every request](/content/docs/vercel-firewall/firewall-concepts#how-vercel-secures-requests/index.html).
- Why [DDoS](/content/docs/vercel-firewall/firewall-concepts#understanding-ddos/index.html) needs to be mitigated.
- How the firewall decides [which rule to apply first](/content/docs/vercel-firewall#rule-execution-order/index.html).
- How the firewall uses [JA3 and JA4 TLS fingerprints](/content/docs/vercel-firewall/firewall-concepts#ja3-and-ja4-tls-fingerprints/index.html) to identify and restrict malicious traffic.

## [Rule execution order](/content/docs/vercel-firewall#rule-execution-order/index.html)

The automatic rules of the platform-wide firewall and the custom rules of the WAF work together in the following execution order:

1. [DDoS mitigation rules](/content/docs/vercel-firewall/ddos-mitigation/index.html)
2. [WAF IP blocking rules](/content/docs/vercel-firewall/vercel-waf/ip-blocking/index.html)
3. [WAF custom rules](/content/docs/vercel-firewall/vercel-waf/custom-rules/index.html)
4. [WAF Managed Rulesets](/content/docs/vercel-firewall/vercel-waf/managed-rulesets/index.html)

When you have more than one custom rule, you can [customize](/content/docs/vercel-firewall/vercel-waf/custom-rules#custom-rule-configuration/index.html) their order in the Firewall section in the sidebar of the project.

## [Platform-wide firewall](/content/docs/vercel-firewall#platform-wide-firewall/index.html)

DDoS Mitigation is available on [all plans](/content/docs/plans/index.html)

Vercel provides automated [DDoS mitigation](/content/docs/vercel-firewall/ddos-mitigation/index.html) for all deployments, regardless of the plan that you are on. With this automated DDoS mitigation, we block incoming traffic if we identify abnormal or suspicious levels of incoming requests.

## [Vercel WAF](/content/docs/vercel-firewall#vercel-waf/index.html)

Vercel WAF is available on [all plans](/content/docs/plans/index.html)

Those with the [member](/content/docs/rbac/access-roles#member-role/index.html), [viewer](/content/docs/rbac/access-roles#viewer-role/index.html), [developer](/content/docs/rbac/access-roles#developer-role/index.html) and [administrator](/content/docs/rbac/access-roles#project-administrators/index.html) roles can access this feature.

The [Vercel WAF](/content/docs/vercel-firewall/vercel-waf/index.html) complements the platform-wide firewall by allowing you to define custom protection strategies using the following tools:

- [Custom Rules](/content/docs/vercel-firewall/vercel-waf/custom-rules/index.html)
- [IP Blocking](/content/docs/vercel-firewall/vercel-waf/ip-blocking/index.html)
- [WAF Managed Rulesets](/content/docs/vercel-firewall/vercel-waf/managed-rulesets/index.html)
- [Attack Mode](/content/docs/vercel-firewall/attack-mode/index.html)

You can also manage bypass rules and your WAF configuration programmatically with the [REST API](/content/docs/vercel-firewall/firewall-api/index.html) through the Vercel SDK, direct endpoint calls, or Terraform.

## [Observability](/content/docs/vercel-firewall#observability/index.html)

You can use the following tools to [monitor the internet traffic](/content/docs/vercel-firewall/firewall-observability/index.html) at your team or project level:

- The [Monitoring](/content/docs/query/monitoring/index.html) feature at the team level allows you to create [queries](/content/docs/query/monitoring/monitoring-reference#example-queries/index.html) to visualize the traffic across your Vercel projects.
- Firewall in the Vercel dashboard sidebar on every project allows you to monitor the internet traffic to your deployments with a [traffic monitoring view](/content/docs/vercel-firewall/firewall-observability#traffic/index.html) that includes a live traffic window.
- [Firewall alerts](/content/docs/vercel-firewall/firewall-observability#firewall-alerts/index.html) allow you to react quickly to potential security threats.
- Use [Log Drains](/content/docs/drains/using-drains/index.html) to send your application logs to a Security Information and Event Management (SIEM) system.

Last updated September 10, 2026.
