Scenario ① · WAF action = Allow (no rule matches this path)
✅ Baseline — page served normally
You reached this page directly from the origin through the Cloudflare edge.
Expected: HTTP 200 · header CF-Ray present · no 403 / challenge.
Expected: HTTP 200 · header CF-Ray present · no 403 / challenge.
Audience demo: F12 → Network → click this page → Response Headers show
cf-ray: …-xxx (a real edge location) — nothing was blocked or challenged.
What you are proving
- Baseline works — traffic reaches the origin normally.
- The pages in the next scenarios are served only when their rule is off or misconfigured.