Azion CLI waf-exceptions
Azion CLI commands that create, list, describe, update, and delete WAF exceptions, with every flag, its type, and its default.
The Azion CLI waf-exceptions commands create, list, describe, update, and delete the exceptions of a Web Application Firewall (WAF). An exception exempts part of a request from a WAF rule. Every command takes the --waf-id of the WAF that holds the exceptions. The options every command accepts, such as --format, --out, and -y, are on Global options.
Create
azion create waf-exceptions creates an exception on a WAF from a JSON file:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | "true" | Turns the exception on (true) or off (false). |
--conditions | — | string | — | Conditions of the exception, in JSON format. |
--file | — | string | — | Required. Path to a JSON file with the attributes of the exception. Use - to read the JSON from standard input. Without it, the command fails with Error: failed to create the WAF Exception: ["Ensure this field has at least 1 elements."], whatever --conditions holds. |
--name | — | string | — | Name of the exception. |
--operator | — | string | — | Operator that matches the conditions: regex or contains. |
--path | — | string | — | Path the exception applies to. |
--rule-id | — | int | — | ID of the WAF rule the exception applies to. |
--waf-id | — | int | — | ID of the WAF that holds the exception. |
This file describes an active exception named my-exception. It exempts the query string parameter named docs from WAF rule 1000 on requests whose path contains /my-path:
This command creates the exception from the file exception.json on the WAF with ID 12347:
The command prints the ID of the exception:
List
azion list waf-exceptions lists the exceptions of one WAF, 50 to a page:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--details | — | — | — | Adds the LAST EDITOR and LAST MODIFIED columns to the ID, NAME, RULE ID, PATH, and ACTIVE columns. |
--filter | — | string | — | Name to filter the list by. |
--order-by | — | string | — | Field to sort the list by. |
--page | — | int | 1 | Number of the page to return. |
--page-size | — | int | 50 | Number of exceptions on each page. |
--waf-id | — | int | — | ID of the WAF whose exceptions to list. |
This command lists the exceptions of the WAF with ID 12347:
The command prints one row per exception:
Describe
azion describe waf-exceptions prints the settings of one exception:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--exception-id | — | int | — | ID of the exception to describe. |
--waf-id | — | int | — | ID of the WAF that holds the exception. |
This command describes the exception with ID 123486 on the WAF with ID 12347:
The command prints the rule, the path, the operator, and the state of the exception:
With --format json, the command prints the full object: active, conditions, id, last_editor, last_modified, name, operator, path, and rule_id. The conditions array is in the JSON output only.
Update
azion update waf-exceptions changes the name, the rule, the path, the conditions, or the state of an exception:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | "true" | Turns the exception on (true) or off (false). |
--conditions | — | string | — | Conditions of the exception, in JSON format. |
--exception-id | — | int | — | ID of the exception to update. |
--file | — | string | — | Path to a JSON file with the attributes to change. Use - to read the JSON from standard input. |
--name | — | string | — | New name of the exception. |
--operator | — | string | — | Operator that matches the conditions: regex or contains. |
--path | — | string | — | Path the exception applies to. |
--rule-id | — | int | — | ID of the WAF rule the exception applies to. |
--waf-id | — | int | — | ID of the WAF that holds the exception. |
Delete
azion delete waf-exceptions deletes an exception from a WAF:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--exception-id | — | int | — | ID of the exception to delete. |
--waf-id | — | int | — | ID of the WAF that holds the exception. |
Use a JSON file
azion create waf-exceptions reads the attributes of an exception from a JSON file with --file. The file carries name, rule_id, path, operator, active, and conditions, and the WAF ID goes on the command line with --waf-id.
Each entry of conditions takes a match value, which names the part of the request the exception covers. The specific_query_string_name value also takes a name key, which holds the name of the query string parameter. For every value match accepts and the keys each one takes, refer to Exceptions.
When the platform refuses a condition, the error the command prints does not name the field. A match value the platform does not accept fails with this error:
A specific_query_string_name condition that carries value in place of name fails with Error: failed to create the WAF Exception: ["This field is required."]. To see which field the platform refused, add --debug and keep the line that carries the detailed error:
The line names the field by its JSON pointer, after Source::