Azion CLI firewall-rule
Azion CLI commands that create, list, describe, update, order, and delete firewall rules, with every flag, its type, and its default.
The Azion CLI firewall-rule commands create, list, describe, update, order, and delete the rules of a firewall, which Rules Engine for Firewall runs on the requests the firewall takes. A rule pairs criteria, which match a request, with behaviors, which act on it, and you pass both in a JSON file. Every command takes the --firewall-id of the firewall that holds the rules. The options every command accepts, such as --format, --out, and -y, are on Global options.
Create
azion create firewall-rule creates a rule on a firewall from a JSON file:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--file | — | string | — | Required. Path to a JSON file with the attributes of the rule. Use - to read the JSON from standard input. Without it, the command asks for the path to the JSON file. |
--firewall-id | — | int | — | ID of the firewall that holds the rule. |
This file describes a rule named my-rule that denies every request whose URI starts with /private:
This command creates the rule from the file rule.json on the firewall with ID 12353:
The command prints the ID of the rule:
When the platform refuses the file, the command prints 400 Bad Request and one Error: line per problem before the summary line. Each line names the field that failed by its JSON pointer, after Source:. A file with an unknown behavior type and a name another rule of the firewall already uses fails with this output:
List
azion list firewall-rule lists the rules of one firewall, 50 to a page:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--details | — | — | — | Adds the LAST EDITOR and LAST MODIFIED columns to the ID, NAME, ACTIVE, and DESCRIPTION columns. |
--filter | — | string | — | Name to filter the list by. |
--firewall-id | — | int | — | ID of the firewall whose rules to list. |
--order-by | — | string | — | Field to sort the list by. |
--page | — | int | 1 | Number of the page to return. |
--page-size | — | int | 50 | Number of rules on each page. |
This command lists the rules of the firewall with ID 12353:
The command prints one row per rule:
Describe
azion describe firewall-rule prints the settings of one rule:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--firewall-id | — | int | — | ID of the firewall that holds the rule. |
--rule-id | — | int | — | ID of the rule to describe. |
This command describes the rule with ID 123483 on the firewall with ID 12353:
The command prints the ID, the name, the last change, and the state of the rule:
With --format json, the command prints the full object: active, behaviors, created_at, criteria, description, id, last_editor, last_modified, name, and order. The order value is the position of the rule on the firewall: the first rule created carries 0, and the second carries 1. A description the file did not send comes back as an empty string.
A rule ID that does not exist on the firewall fails with Error: failed to describe the Firewall Rule: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct.
Update
azion update firewall-rule changes a rule with the attributes of a JSON file:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--file | — | string | — | Path to a JSON file with the attributes to change. Use - to read the JSON from standard input. |
--firewall-id | — | int | — | ID of the firewall that holds the rule. |
--rule-id | — | int | — | ID of the rule to update. |
This file renames the rule to my-rule-renamed and turns it off:
This command applies the file rule-update.json to the rule with ID 123483:
The command prints the ID of the updated rule:
The attributes the file leaves out keep their values. After this update, the rule still carries its deny behavior.
Order rules
azion update firewall-rule-order sets the order in which the rules of a firewall run, from a list of rule IDs:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--firewall-id | — | int | — | ID of the firewall whose rules to order. |
--rule-ids | — | string | — | Comma-separated list of rule IDs, in the order the rules run. The list holds every rule of the firewall. |
This command makes the rule with ID 123484 run before the rule with ID 123483:
The command confirms the new order:
After the command, azion list firewall-rule prints the rules in the new order. A list that leaves out a rule of the firewall fails with this error:
Delete
azion delete firewall-rule deletes a rule from a firewall:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--firewall-id | — | int | — | ID of the firewall that holds the rule. |
--rule-id | — | int | — | ID of the rule to delete. |
This command deletes the rule with ID 123484 from the firewall with ID 12353:
The command confirms the deletion:
Use a JSON file
azion create firewall-rule and azion update firewall-rule read the attributes of a rule only from a JSON file with --file. These commands have no flag for a name, a criterion, or a behavior. The file holds the keys below, which the create example above sends:
| Key | Type | Description |
|---|---|---|
name | string | Name of the rule. Another rule of the same firewall cannot use it. |
active | boolean | Turns the rule on (true) or off (false). |
criteria | array of arrays of objects | The conditions a request must meet. Each object carries variable, operator, conditional, and argument, such as ${request_uri}, starts_with, if, and /private. |
behaviors | array of objects | What the rule does to a request that matches. Each object carries a type, such as deny. |
On update, the file carries only the keys to change, and the rule keeps the values of the keys the file leaves out. For every variable, operator, conditional, and behavior a rule accepts, refer to Rules Engine for Firewall.