Thank you for sharing the screenshot. That confirms you are on a plan (likely the Free plan) where the WAF Custom Rules feature is not enabled by default, which is why it's prompting you to "Purchase add-on."
However, you can still block traffic by ASN using the dedicated, free tool called IP Access Rules. Cloudflare sometimes hides the menu item when you don't have an active rule, but you can usually find it under the Tools tab of the WAF section.
Here is the revised, correct navigation path to find and use IP Access Rules to block Tencent:
1. Find the IP Access Rules Tool
Log in to your Cloudflare dashboard and select your domain.
In the left-hand menu, navigate to Security.
Under the Security menu, look for WAF or Security $\rightarrow$ WAF.
Once on the WAF page, look for a tab or sub-menu named Tools.
- If you are using the older dashboard style, the path is usually Security $\rightarrow$ IP Access Rules.
- If you are in the newer dashboard style (which your screenshot suggests), you should look for the Tools tab/sub-menu under WAF.
2. Create the Blocking Rules
Once you are on the IP Access Rules page (or Tools tab), you will see a section where you can add new rules.
You will need to create a separate rule for each Tencent ASN (Autonomous System Number). Use the following ASNs for Tencent:
- AS45090 (TENCENT-NET-AP)
- AS132203 (TENCENT-NET-AP-CN)
Field |
Value |
Action |
Zone |
Notes |
---|
Value: |
AS45090 |
Block or Challenge |
This website |
Block Tencent Bots |
Value: |
AS132203 |
Block or Challenge |
This website |
Block Tencent Cloud |
Recommended Action:
- Start with Challenge (Managed). This will force the bots to solve a challenge (like a CAPTCHA) without blocking legitimate users who might coincidentally be using a Tencent-hosted VPN or service.
- If you still see abuse, you can change the action to Block.
After you enter the details for each ASN, click Add to deploy the rule immediately.
Alternative Free Protection
If you still can't find the IP Access Rules tool, make sure you have the following general security features enabled, which are available on the Free plan:
- Security Level: Go to Security $\rightarrow$ Settings and set the Security Level to High or "I'm Under Attack!". This will automatically challenge visitors with a high Threat Score, which often catches malicious bots.
- Bot Fight Mode: Go to Security $\rightarrow$ Bots and make sure Bot Fight Mode is ON. This blocks a substantial amount of simple bot traffic.