# Azion CLI firewall-rule

The Azion CLI `firewall-rule` commands create, list, describe, update, order, and delete the rules of a [firewall](/en/documentation/platform/firewall/), which [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) runs on the requests the firewall takes. A rule pairs criteria, which match a request, with behaviors, which act on it, and you pass both in a JSON file. Every command takes the `--firewall-id` of the firewall that holds the rules. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create firewall-rule` creates a rule on a firewall from a JSON file:

```bash
azion create firewall-rule [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                                                                                                  |
| --------------- | ----- | ------ | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--file`        | —     | string | —       | **Required.** Path to a JSON file with the attributes of the rule. Use `-` to read the JSON from standard input. Without it, the command asks for the path to the JSON file. |
| `--firewall-id` | —     | int    | —       | ID of the firewall that holds the rule.                                                                                                                                      |

This file describes a rule named `my-rule` that denies every request whose URI starts with `/private`:

```json
{
  "name": "my-rule",
  "active": true,
  "criteria": [
    [
      {
        "variable": "${request_uri}",
        "operator": "starts_with",
        "conditional": "if",
        "argument": "/private"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "deny"
    }
  ]
}
```

This command creates the rule from the file `rule.json` on the firewall with ID `12353`:

```bash
azion create firewall-rule --firewall-id 12353 --file rule.json
```

The command prints the ID of the rule:

```text
Created Firewall Rule with ID 123483
```

When the platform refuses the file, the command prints `400 Bad Request` and one `Error:` line per problem before the summary line. Each line names the field that failed by its JSON pointer, after `Source:`. A file with an unknown behavior type and a name another rule of the firewall already uses fails with this output:

```text
400 Bad Request
Error: Invalid Choice - Source: /data/behaviors/0/type - Message: "explode" is not a valid choice.
Error: Firewall Rule Name Already In Use - Source: /data/name - Message: Firewall already have a rule with this name.

Error: failed to create the Firewall Rule: ["\"explode\" is not a valid choice.","Firewall already have a rule with this name."]
```

---

## List

`azion list firewall-rule` lists the rules of one firewall, 50 to a page:

```bash
azion list firewall-rule [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                                  |
| --------------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------------------ |
| `--details`     | —     | —      | —       | Adds the `LAST EDITOR` and `LAST MODIFIED` columns to the `ID`, `NAME`, `ACTIVE`, and `DESCRIPTION` columns. |
| `--filter`      | —     | string | —       | Name to filter the list by.                                                                                  |
| `--firewall-id` | —     | int    | —       | ID of the firewall whose rules to list.                                                                      |
| `--order-by`    | —     | string | —       | Field to sort the list by.                                                                                   |
| `--page`        | —     | int    | `1`     | Number of the page to return.                                                                                |
| `--page-size`   | —     | int    | `50`    | Number of rules on each page.                                                                                |

This command lists the rules of the firewall with ID `12353`:

```bash
azion list firewall-rule --firewall-id 12353
```

The command prints one row per rule:

```text
ID      NAME                  ACTIVE  DESCRIPTION
123483  my-rule               true
123484  my-rule-2             true
```

---

## Describe

`azion describe firewall-rule` prints the settings of one rule:

```bash
azion describe firewall-rule [flags]
```

| Flag            | Short | Type | Default | Description                             |
| --------------- | ----- | ---- | ------- | --------------------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall that holds the rule. |
| `--rule-id`     | —     | int  | —       | ID of the rule to describe.             |

This command describes the rule with ID `123483` on the firewall with ID `12353`:

```bash
azion describe firewall-rule --firewall-id 12353 --rule-id 123483
```

The command prints the ID, the name, the last change, and the state of the rule:

```text
ID:              123483
Name:            my-rule
Last Editor:     you@example.com
Last Modified:   "2026-01-01T12:00:00.366524Z"
Active:          true
Description:
```

With `--format json`, the command prints the full object: `active`, `behaviors`, `created_at`, `criteria`, `description`, `id`, `last_editor`, `last_modified`, `name`, and `order`. The `order` value is the position of the rule on the firewall: the first rule created carries `0`, and the second carries `1`. A `description` the file did not send comes back as an empty string.

A rule ID that does not exist on the firewall fails with `Error: failed to describe the Firewall Rule: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct`.

---

## Update

`azion update firewall-rule` changes a rule with the attributes of a JSON file:

```bash
azion update firewall-rule [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                      |
| --------------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------ |
| `--file`        | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input. |
| `--firewall-id` | —     | int    | —       | ID of the firewall that holds the rule.                                                          |
| `--rule-id`     | —     | int    | —       | ID of the rule to update.                                                                        |

This file renames the rule to `my-rule-renamed` and turns it off:

```json
{
  "name": "my-rule-renamed",
  "active": false
}
```

This command applies the file `rule-update.json` to the rule with ID `123483`:

```bash
azion update firewall-rule --firewall-id 12353 --rule-id 123483 --file rule-update.json
```

The command prints the ID of the updated rule:

```text
Updated Firewall Rule with ID 123483
```

The attributes the file leaves out keep their values. After this update, the rule still carries its `deny` behavior.

---

## Order rules

`azion update firewall-rule-order` sets the order in which the rules of a firewall run, from a list of rule IDs:

```bash
azion update firewall-rule-order [flags]
```

| Flag            | Short | Type   | Default | Description                                                                                              |
| --------------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------- |
| `--firewall-id` | —     | int    | —       | ID of the firewall whose rules to order.                                                                 |
| `--rule-ids`    | —     | string | —       | Comma-separated list of rule IDs, in the order the rules run. The list holds every rule of the firewall. |

This command makes the rule with ID `123484` run before the rule with ID `123483`:

```bash
azion update firewall-rule-order --firewall-id 12353 --rule-ids "123484,123483"
```

The command confirms the new order:

```text
Ordered Rules Engine of Firewall with ID 12353
```

After the command, `azion list firewall-rule` prints the rules in the new order. A list that leaves out a rule of the firewall fails with this error:

```text
Error: Failed to order the rules in Rules Engine of the Firewall: ["When ordering you should provide the order for all rules."]. Check your settings and try again. If the error persists, contact Azion support.
```

---

## Delete

`azion delete firewall-rule` deletes a rule from a firewall:

```bash
azion delete firewall-rule [flags]
```

| Flag            | Short | Type | Default | Description                             |
| --------------- | ----- | ---- | ------- | --------------------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall that holds the rule. |
| `--rule-id`     | —     | int  | —       | ID of the rule to delete.               |

This command deletes the rule with ID `123484` from the firewall with ID `12353`:

```bash
azion delete firewall-rule --firewall-id 12353 --rule-id 123484 -y
```

The command confirms the deletion:

```text
Firewall Rule 123484 was successfully deleted
```

---

## Use a JSON file

`azion create firewall-rule` and `azion update firewall-rule` read the attributes of a rule only from a JSON file with `--file`. These commands have no flag for a name, a criterion, or a behavior. The file holds the keys below, which the create example above sends:

| Key         | Type                       | Description                                                                                                                                                                   |
| ----------- | -------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `name`      | string                     | Name of the rule. Another rule of the same firewall cannot use it.                                                                                                            |
| `active`    | boolean                    | Turns the rule on (`true`) or off (`false`).                                                                                                                                  |
| `criteria`  | array of arrays of objects | The conditions a request must meet. Each object carries `variable`, `operator`, `conditional`, and `argument`, such as `${request_uri}`, `starts_with`, `if`, and `/private`. |
| `behaviors` | array of objects           | What the rule does to a request that matches. Each object carries a `type`, such as `deny`.                                                                                   |

On update, the file carries only the keys to change, and the rule keeps the values of the keys the file leaves out. For every variable, operator, conditional, and behavior a rule accepts, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/).

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine.md): Every criterion variable, operator, and behavior the JSON file of a rule can carry.
- [Azion CLI firewall](/en/documentation/devtools/cli/resources/firewall.md): The commands that create and manage the firewall whose ID every rule command takes.
- [Azion CLI network-list](/en/documentation/devtools/cli/resources/network-list.md): The commands that manage the lists a rule's criteria can match a request against.
