Good Bot Managment
Good Bots let you allow known and trusted bots, search engine crawlers, AI assistants, and other legitimate automated clients, to bypass Anti-Bot enforcement. Good bots are allowed on the same URIs configured in your Anti-Bot rules.
This exemption applies only to the Anti-Bot engine, traffic from an allowed good bot is still evaluated by your other security engines (e.g., IPS, WAF).
Mode
The Mode toggle at the top of the Good Bots section turns the feature Enabled or Disabled. When disabled, no good bot allowances (custom rules or providers) are applied, and all traffic is evaluated normally by your Anti-Bot rules.
Add a Custom Good Bot Rule

Go to the Good Bots Sub practice under Anti-Bot.
Click the list icon in the toolbar above the table to add a rule.
Fill in the rule fields:
Name — a label to identify the rule (e.g.,
Good Bot Example).Category — the type of bot (e.g.,
Search Engine).Match — the condition used to identify the bot's traffic. Choose one:
Source IP
Source Identifier
User Agent (e.g.,
Goodbot)Custom Header — either
<Header Name>:<Header Value>or just<Header Name>
Notes (optional) — free-text comments about the rule.
Save the rule.
To edit a rule, select it and click the pencil icon. To remove a rule, select it and click the trash icon.
Source IP is not supported for WAF SaaS, Source Identifier can be used instead.
Providers
Below the custom rules table, Providers lets you automatically allow good bots from known providers without defining a custom rule for each one:
All — enables/disables every provider at once.
Individual providers: Google, Microsoft, Apple, OpenAI, Anthropic, Meta, LinkedIn.
Each provider has its own Enabled checkbox. When a provider is enabled, its known good bots (e.g., Googlebot, Bingbot) are automatically allowed on the URIs covered by your Anti-Bot rules — no custom Match rule needed.
Notes
Custom rules and enabled providers work together — a bot only needs to match one of them to be allowed.
Good Bots only affects Anti-Bot enforcement; it does not exempt traffic from other security engines.
Last updated
Was this helpful?