---
source_url: "https://waf-doc.inext.checkpoint.com/additional-security-engines/anti-bot-challenge-rules"
title: "Anti-Bot Challenge Rules | Check Point WAF"
mirrored_at: 2026-08-04T12:31:44.083Z
host: waf-doc.inext.checkpoint.com
cited_in_42a: true
mirror_canonical: "https://index.42a.ai/waf-doc.inext.checkpoint.com/additional-security-engines/anti-bot-challenge-rules"
---

> **Original source:** https://waf-doc.inext.checkpoint.com/additional-security-engines/anti-bot-challenge-rules

⌘Ctrlk

1.  [Additional Security Engines](https://waf-doc.inext.checkpoint.com/additional-security-engines)

## Anti-Bot Challenge Rules

### Overview

Anti-Bot rules allow you to **Detect, Challenge, or Prevent** traffic that matches specific criteria in order to mitigate automated abuse such as:

-   Credential stuffing
    
-   Brute-force attacks
    
-   Account enumeration
    
-   Bot Driven DDoS
    

#### Action Modes

-   **Detect** – Logs matching traffic only. _Recommended first step to validate impact before enforcement._
    
-   **Challenge (captcha)** – Requires the client to pass a browser challenge before access is granted. Use to stop automation while allowing legitimate users.
    
-   **Prevent** – Blocks matching requests. Use after validation or during active attacks.
    

**Best practice:** Start with **Detect**, then move to **Challenge**

### How to Configure Anti Bot Rules

#### Add Rules

1.  Navigate to **Anti-Bot Tab → Challenge Rules SubPractice → Add Rule**
    

![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FZA74PCerf5v7oHSa6G8d%252Fimage.png%3Falt%3Dmedia%26token%3Dc84f3474-58ce-40df-8ada-2f2f838146b7&width=768&dpr=3&quality=100&sign=b4da4e36&sv=2)

1.  Select the desired **Action** (Detect, Challenge, or Prevent).
    
2.  Enter the target **URI** (e.g., `/login`).
    
3.  (Optional) Add **Additional Conditions** to narrow the scope. You may choose one of the following:
    
    -   Source Identifier
        
    -   Source IP
        
    -   URI
        
    -   Country Code
        
    -   Country Name
        
    
4.  Save the rule.
    

![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FTTYC9GRMLGGT3vk1rR7N%252Fimage.png%3Falt%3Dmedia%26token%3D0fb270f3-42b9-4acc-bd01-0021e0d964c4&width=768&dpr=3&quality=100&sign=88fe3311&sv=2)

#### Add a Captcha Challenge

1.  Navigate to the "Behaviors" Tab and create a new captcha object
    

![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FSUutmE2EoqM0K70pAHJa%252Fimage.png%3Falt%3Dmedia%26token%3Df55f4b0d-bca2-4de5-954c-c31e6fbfcf88&width=768&dpr=3&quality=100&sign=d13214ae&sv=2)

1.  Configure the Captcha object that will be used when a rule triggers a challenge:
    
    -   **Name**: Enter a friendly name for the Captcha object, or keep the default.
        
    -   **Captcha Type**: Select the challenge mechanism. _(Currently set by default to_ _**Proof of Work**__.)_
        
    -   **TTL**: The time-to-live (in minutes) for the successful challenge. During this period, the user will not be required to complete a new challenge.
        
    -   **Message Title (optional)**: The title shown on the challenge HTML page presented to the end user.
        
    -   **Message Body (optional)**: The text displayed on the challenge HTML page presented to the end user.
        
    
    ![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FaVSYytcGu7vctq1FGMkc%252Fimage.png%3Falt%3Dmedia%26token%3Dea7bb2b4-dc93-450a-b055-9a092f648915&width=768&dpr=3&quality=100&sign=8daeb87c&sv=2)
    

![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FoCJLObJ2THssuGgtzzY7%252Fimage.png%3Falt%3Dmedia%26token%3D1776bea1-62fc-45b8-8e9d-c058415ac741&width=768&dpr=3&quality=100&sign=d16aa4c1&sv=2)

Example of a page challenge page displayed to the user

1.  Connect the Captcha object to the practice:
    

![](https://waf-doc.inext.checkpoint.com/~gitbook/image?url=https%3A%2F%2F2760087783-files.gitbook.io%2F%7E%2Ffiles%2Fv0%2Fb%2Fgitbook-x-prod.appspot.com%2Fo%2Fspaces%252FEWA4nfgNrSRL8dA6Kap7%252Fuploads%252FjsooPXUNBNvCB0uGXtpW%252Fimage.png%3Falt%3Dmedia%26token%3Dc5926c00-a419-4403-9d21-f9b8cce59118&width=768&dpr=3&quality=100&sign=50edd9bd&sv=2)

1.  Enforce policy
    

Last updated 4 months ago

Was this helpful?

-   [Overview](#overview)
-   [How to Configure Anti Bot Rules](#how-to-configure-anti-bot-rules)

Was this helpful?