# Azion CLI firewall

The Azion CLI `firewall` commands create, list, describe, update, and delete firewalls. A [firewall](/en/documentation/platform/firewall/) inspects the requests of a workload before its application does, and these commands turn its WAF, Network Shield, and Functions switches on or off. A firewall inspects no request until a workload deployment names it, through the `--firewall-id` flag of `azion create workload-deployment`. The options every command accepts, such as `--format`, `--out`, and `-y`, are on [Global options](/en/documentation/devtools/cli/globals/).

---

## Create

`azion create firewall` creates a firewall with the name and settings you pass:

```bash
azion create firewall [flags]
```

| Flag                   | Short | Type   | Default | Description                                                                                                                                                          |
| ---------------------- | ----- | ------ | ------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `--active`             | —     | string | —       | Turns the firewall on (`true`) or off (`false`).                                                                                                                     |
| `--debug-rules`        | —     | string | —       | Takes `true` or `false`. With `true`, you can check whether the firewall's [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rules ran. |
| `--file`               | —     | string | —       | Path to a JSON file with the attributes of the firewall. Use `-` to read the JSON from standard input.                                                               |
| `--functions-enabled`  | —     | string | —       | Turns [Functions for Firewall](/en/documentation/platform/firewall/functions/) on (`true`) or off (`false`) for the firewall.                                        |
| `--name`               | —     | string | —       | **Required** unless `--file` is set. Name of the firewall. Without it, the command asks for the name.                                                                |
| `--network-protection` | —     | string | —       | Turns [Network Shield](/en/documentation/platform/firewall/#network-shield) on (`true`) or off (`false`) for the firewall.                                           |
| `--waf-enabled`        | —     | string | —       | Turns [WAF](/en/documentation/platform/firewall/#waf) on (`true`) or off (`false`) for the firewall.                                                                 |

This command creates an active firewall named `my-firewall` with Functions and WAF turned on:

```bash
azion create firewall --name my-firewall --active true --functions-enabled true --waf-enabled true
```

The command prints the ID of the firewall:

```text
Created Firewall with ID 12353
```

---

## List

`azion list firewall` lists the firewalls of your account, 50 to a page:

```bash
azion list firewall [flags]
```

| Flag          | Short | Type   | Default | Description                                                                                             |
| ------------- | ----- | ------ | ------- | ------------------------------------------------------------------------------------------------------- |
| `--details`   | —     | —      | —       | Adds the `DEBUG`, `LAST EDITOR`, and `LAST MODIFIED` columns to the `ID`, `NAME`, and `ACTIVE` columns. |
| `--filter`    | —     | string | —       | Name to filter the list by.                                                                             |
| `--order-by`  | —     | string | —       | Field to sort the list by.                                                                              |
| `--page`      | —     | int    | `1`     | Number of the page to return.                                                                           |
| `--page-size` | —     | int    | `50`    | Number of firewalls on each page.                                                                       |

This command lists the firewalls of the account:

```bash
azion list firewall
```

The command prints one row per firewall:

```text
ID     NAME                     ACTIVE
12350  my-blog-firewall         true
12351  my-store-firewall        true
12352  my-api-firewall          true
12353  my-firewall              true
12354  my-site-firewall         true
```

---

## Describe

`azion describe firewall` prints the settings of one firewall:

```bash
azion describe firewall [flags]
```

| Flag            | Short | Type | Default | Description                     |
| --------------- | ----- | ---- | ------- | ------------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall to describe. |

This command describes the firewall with ID `12353`:

```bash
azion describe firewall --firewall-id 12353
```

The command prints the name, the switches, and the state of the firewall:

```text
ID:            12353
Name:          my-firewall
Modules:       {"ddos_protection":{"enabled":true},"functions":{"enabled":true},"network_protection":{"enabled":true},"waf":{"enabled":true}}
Debug:         false
Active:        true
Last Editor:   you@example.com
Modified at:   "2026-01-01T12:00:00.853715Z"
```

With `--format json`, the command prints the full object: `active`, `created_at`, `debug`, `id`, `is_versioned`, `last_editor`, `last_modified`, `modules`, `name`, `product_version`, `version`, `version_id`, and `version_state`. The `modules` object holds an `enabled` value for `ddos_protection`, `functions`, `network_protection`, and `waf`. The create and update flags set the last three, and `network_protection` is the API name of Network Shield.

An ID that does not exist fails with this error:

```text
Error: Failed to get the Firewall: The given ID or API's endpoint doesn't exist or isn't available. Check that the identifying information is correct. Check your settings and try again. If the error persists, contact Azion support
```

---

## Update

`azion update firewall` changes the name, the active state, or the switches of a firewall:

```bash
azion update firewall [flags]
```

| Flag                   | Short | Type   | Default | Description                                                                                                     |
| ---------------------- | ----- | ------ | ------- | --------------------------------------------------------------------------------------------------------------- |
| `--active`             | —     | string | —       | Turns the firewall on (`true`) or off (`false`).                                                                |
| `--debug-rules`        | —     | string | —       | Takes `true` or `false`. With `true`, you can check whether the firewall's Rules Engine for Firewall rules ran. |
| `--file`               | —     | string | —       | Path to a JSON file with the attributes to change. Use `-` to read the JSON from standard input.                |
| `--firewall-id`        | —     | int    | —       | **Required**, with `--file` too. ID of the firewall to update. Without it, the command asks for the ID.         |
| `--functions-enabled`  | —     | string | —       | Turns Functions for Firewall on (`true`) or off (`false`) for the firewall.                                     |
| `--name`               | —     | string | —       | New name of the firewall.                                                                                       |
| `--network-protection` | —     | string | —       | Turns Network Shield on (`true`) or off (`false`) for the firewall.                                             |
| `--waf-enabled`        | —     | string | —       | Turns WAF on (`true`) or off (`false`) for the firewall.                                                        |

The switch flags take `true` or `false`. Any other value, such as `yes`, is refused:

```text
Error: Invalid value for --waf-enabled flag: yes
```

This command renames the firewall with ID `12353` to `my-firewall-renamed`, turns debugging on, and turns Network Shield on:

```bash
azion update firewall --firewall-id 12353 --name my-firewall-renamed --debug-rules true --network-protection true
```

The command prints the ID of the updated firewall:

```text
Updated Firewall with ID 12353
```

---

## Delete

`azion delete firewall` deletes a firewall:

```bash
azion delete firewall [flags]
```

| Flag            | Short | Type | Default | Description                   |
| --------------- | ----- | ---- | ------- | ----------------------------- |
| `--firewall-id` | —     | int  | —       | ID of the firewall to delete. |

This command deletes the firewall with ID `12353`:

```bash
azion delete firewall --firewall-id 12353
```

The command confirms the deletion:

```text
Firewall 12353 was successfully deleted
```

---

## Use a JSON file

`azion create firewall` and `azion update firewall` read the attributes of the firewall from a JSON file with `--file`.

This file creates an active firewall named `my-site-firewall`. The command reads `name` and `active` from it:

```json
{
  "name": "my-site-firewall",
  "active": true
}
```

Pass the file to the create command:

```bash
azion create firewall --file fw-create.json
```

The command prints the ID of the firewall:

```text
Created Firewall with ID 12354
```

The firewall created from this file has Functions and Network Shield on and WAF off, as `azion describe firewall --format json` shows in its `modules` object.

On update, the command does not read `"id"` from the file. Pass `--firewall-id` on the command line, or the command asks for the ID. This file renames the firewall with ID `12354` and keeps it active:

```json
{
  "id": 12354,
  "name": "my-site-firewall-updated",
  "active": true
}
```

Pass the file and the ID to the update command:

```bash
azion update firewall --firewall-id 12354 --file fw-update.json
```

The command prints the ID of the updated firewall:

```text
Updated Firewall with ID 12354
```

---

## Related resources

- [Global options](/en/documentation/devtools/cli/globals.md): The options every command accepts, such as `--format`, `--out`, and `-y`.
- [Firewall](/en/documentation/platform/firewall.md): What a firewall inspects, and the Products it runs on a request.
- [Azion CLI firewall-rule](/en/documentation/devtools/cli/resources/firewall-rule.md): The commands that create, order, and manage the rules a firewall runs.
- [Azion CLI firewall-instance](/en/documentation/devtools/cli/resources/firewall-instance.md): The commands that add function instances to a firewall.
