Thank you for testing and correcting me. It clarifies the actual behavior in this scenario.
------------------------------
Vivek Ghalawat
------------------------------
Original Message:
Sent: 09-02-2026 09:41
From: Piotr Kowalczyk
Subject: WAF Policy Allowlist doesn't bypass security rules.
Fortunately your answer is wrong. I've just tested and adding IP address to Allow list bypass CAPTCHA requirement set in rule.
------------------------------
Piotr Kowalczyk
Cybersecurity LEad
Applus
Barcelona
------------------------------
Original Message:
Sent: 09-02-2026 05:39
From: Vivek Ghalawat
Subject: WAF Policy Allowlist doesn't bypass security rules.
The Allowlist does not act as a global trust mechanism. It bypasses WAF Security Policy checks, but Security Rules are evaluated separately. If a request from an Allowlisted IP matches a Security Rule configured with "Require CAPTCHA", the CAPTCHA challenge will still be applied unless the rule explicitly excludes that IP.
------------------------------
Vivek Ghalawat
------------------------------