Azion CLI waf
Azion CLI commands that create, list, describe, update, and delete WAF rule sets and their threat thresholds, with every flag and its default.
The Azion CLI waf commands create, list, describe, update, and delete WAF rule sets. A rule set holds one threshold for each threat it covers, a threat name paired with a sensitivity, and the CLI output calls it a WAF. The options every command accepts, such as --format, --out, and -y, are on Global options.
Create
azion create waf creates a rule set with the name and settings you pass:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | — | Turns the rule set on (true) or off (false). |
--engine-version | — | string | — | Version of the WAF engine. A rule set created without it gets 2021-Q3. |
--file | — | string | — | Path to a JSON file with the attributes of the rule set. Use - to read the JSON from standard input. |
--name | — | string | — | Name of the rule set. |
--product-version | — | string | — | Product version of the rule set. A rule set created without it gets 1.0. |
--rulesets | — | string | — | Comma-separated list of the IDs of the rulesets to turn on. A rule set created without it gets 1. |
--thresholds | — | string | — | Comma-separated list of threat=sensitivity pairs. A rule set created without it gets all eight threats at medium. |
--type | — | string | — | Type of the WAF engine. A rule set created without it gets score. |
The eight threats are cross_site_scripting, directory_traversal, evading_tricks, file_upload, identified_attack, remote_file_inclusion, sql_injection, and unwanted_access. The sensitivity takes highest, high, medium, low, or lowest.
This command creates an active rule set named my-strict-waf with highest sensitivity for cross-site scripting and high for SQL injection:
The command prints the ID of the rule set:
The rule set holds only the thresholds you pass: azion describe waf --waf-id 12348 --format json lists cross_site_scripting at highest and sql_injection at high, and no other threat.
A sensitivity outside these five values is refused:
List
azion list waf lists the rule sets of your account, 50 to a page:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--details | — | — | — | Adds the PRODUCT VERSION, LAST EDITOR, and LAST MODIFIED columns to the ID, NAME, and ACTIVE columns. |
--filter | — | string | — | Name to filter the list by. |
--order-by | — | string | — | Field to sort the list by. |
--page | — | int | 1 | Number of the page to return. |
--page-size | — | int | 50 | Number of rule sets on each page. |
This command lists the rule sets of the account:
The command prints one row per rule set:
Describe
azion describe waf prints the settings of one rule set:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--waf-id | — | int | — | ID of the rule set to describe. |
This command describes the rule set with ID 12347, created with --name and --active only:
The command prints the name, the state, and the engine settings of the rule set. All eight threats carry the default medium sensitivity:
With --format json, the command prints the full object: active, engine_settings, id, is_versioned, last_editor, last_modified, name, product_version, version, version_id, and version_state. The engine_settings object holds engine_version, type, and an attributes object with the rulesets and thresholds that the create and update flags set.
An ID that does not exist fails with this error:
Update
azion update waf changes the name, the active state, or the engine settings of a rule set:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--active | — | string | — | Turns the rule set on (true) or off (false). |
--engine-version | — | string | — | Version of the WAF engine. |
--file | — | string | — | Path to a JSON file with the attributes to change. Use - to read the JSON from standard input. |
--name | — | string | — | New name of the rule set. |
--rulesets | — | string | — | Comma-separated list of the IDs of the rulesets to turn on. |
--thresholds | — | string | — | Comma-separated list of threat=sensitivity pairs. Replaces the whole list of thresholds. |
--type | — | string | — | Type of the WAF engine. |
--waf-id | — | int | — | Required, with --file too. ID of the rule set to update. Without it, the command asks for the ID. |
This command renames the rule set with ID 12347 to my-waf-renamed and sets SQL injection to lowest sensitivity:
The command prints the ID of the updated rule set:
After this update, azion describe waf --waf-id 12347 --format json returns one threshold, sql_injection at lowest. The other seven threats are gone from the rule set.
Delete
azion delete waf deletes a rule set:
| Flag | Short | Type | Default | Description |
|---|---|---|---|---|
--waf-id | — | int | — | ID of the rule set to delete. |
This command deletes the rule set with ID 12347:
The command confirms the deletion:
Use a JSON file
azion create waf and azion update waf read the attributes of the rule set from a JSON file with --file.
This file creates an active rule set named my-site-waf with high sensitivity for SQL injection. The command reads name, active, and engine_settings from it:
Pass the file to the create command:
The command prints the ID of the rule set:
The rule set created from this file holds one threshold, sql_injection at high, as azion describe waf --format json shows.
On update, the command does not read "id" from the file. Pass --waf-id on the command line, or the command asks for the ID. This file renames the rule set with ID 12349:
Pass the file and the ID to the update command:
The command prints the ID of the updated rule set:
The update is partial: the file leaves active out, and the rule set stays active.