# Security resources

[View in Terraform Registry](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_main_setting)

The security resources of the Azion Terraform Provider configure what stops a request before it reaches your application: protection against threats, geolocation blocking, and rate limiting. The provider manages a [Firewall](/en/documentation/platform/firewall/) and its rules and function instances, Web Application Firewall (WAF) settings and [rule sets](/en/documentation/platform/firewall/waf/rules-set/), and [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists/) with six resources. Twelve data sources read the same objects back, one that lists them and one that reads a single object per resource type.

---

## Security resources

| Resource                                                                                                                                         | Description                                                                             |
| ------------------------------------------------------------------------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------- |
| [`azion_firewall_main_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_main_setting)             | Creates and manages the main settings of a firewall.                                    |
| [`azion_firewall_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_rule_engine)               | Creates and manages a Rules Engine rule of a firewall.                                  |
| [`azion_firewall_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/firewall_functions_instance) | Creates and manages a function instance in a firewall.                                  |
| [`azion_waf`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/waf)                                                 | Creates and manages a WAF.                                                              |
| [`azion_waf_rule_set`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/waf_rule_set)                               | Creates and manages a WAF rule set.                                                     |
| [`azion_network_list`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/resources/network_list)                               | Creates and manages a network list of IP addresses and CIDR ranges, countries, or ASNs. |

`azion_firewall_main_setting` requires `name`, a string that holds the name of the firewall, and accepts `active`, a boolean that sets whether the firewall is active. `azion_network_list` requires `name`, a string that holds the name of the list, and `list_type`, a string that takes `ip_cidr`, `countries`, or `asns`. `azion_waf_rule_set` takes a `name`. The Terraform Registry page of each resource lists every argument.

---

## Data sources

| Data source                                                                                                                                         | Description                                |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------ |
| [`azion_firewall_main_settings`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_main_settings)           | Lists firewalls.                           |
| [`azion_firewall_main_setting`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_main_setting)             | Reads one firewall.                        |
| [`azion_firewall_rules_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_rules_engine)             | Lists the Rules Engine rules of firewalls. |
| [`azion_firewall_rule_engine`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_rule_engine)               | Reads one Rules Engine rule of a firewall. |
| [`azion_firewall_function_instances`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_functions_instance) | Lists the function instances of firewalls. |
| [`azion_firewall_functions_instance`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/firewall_functions_instance) | Reads one function instance of a firewall. |
| [`azion_wafs`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/wafs)                                               | Lists WAFs.                                |
| [`azion_waf`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf)                                                 | Reads one WAF.                             |
| [`azion_waf_rule_sets`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf_rule_sets)                             | Lists WAF rule sets.                       |
| [`azion_waf_rule_set`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/waf_rule_set)                               | Reads one WAF rule set.                    |
| [`azion_network_lists`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/network_lists)                             | Lists network lists.                       |
| [`azion_network_list`](https://registry.terraform.io/providers/aziontech/azion/latest/docs/data-sources/network_list)                               | Reads one network list.                    |

---

## Example

This configuration pins the provider, creates a network list of IP ranges, an active firewall, and a WAF rule set, and outputs the ID of the firewall. It reads your personal token from the `api_token` variable that the [Azion Terraform Provider quickstart](/en/documentation/devtools/terraform/getting-started/) declares.

```hcl
terraform {
  required_providers {
    azion = {
      source  = "aziontech/azion"
      version = "2.0.0"
    }
  }
}

provider "azion" {
  api_token = var.api_token
}

# Create network list for blocked IPs
resource "azion_network_list" "blocked_ips" {
  name      = "blocked-ips"
  list_type = "ip_cidr"
}

# Create firewall
resource "azion_firewall_main_setting" "my_firewall" {
  name   = "my-firewall"
  active = true

  # Link to workload/application
}

# Create WAF rule set
resource "azion_waf_rule_set" "my_waf" {
  name = "my-waf"

  # WAF configuration
}

output "firewall_id" {
  value = azion_firewall_main_setting.my_firewall.id
}
```

---

## Related resources

- [Firewall](/en/documentation/platform/firewall.md): The platform page for firewalls, their rules, and the WAF, Network Shield, and Bot Manager protections they run.
- [Resources and data sources](/en/documentation/devtools/terraform/examples.md): Every resource and data source of the provider, with an example per family.
- [Applications resources](/en/documentation/devtools/terraform/applications.md): The resources that manage applications, their cache settings, rules, device groups, and function instances.
- [Migrate from provider v1.x to v2.0](/en/documentation/devtools/terraform/terraform-migration-v3-to-v4.md): The resource names and arguments that changed between provider v1.x and v2.0.
