---
name: azion-block-bots-and-tor-exit-nodes-with-a-template
description: >-
  Deploy the Bot Manager Lite and TOR Block Starter Kit template to create a firewall that scores requests and denies Tor exit-node addresses.
---

# Block bots and Tor exit nodes with a template

You create a [firewall](/en/documentation/platform/firewall/) that scores requests with [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) and refuses Tor exit-node addresses by deploying the Bot Manager Lite and TOR Block Starter Kit template from Azion Console.

The template creates the firewall, one Bot Manager Lite function instance on it, and the [Rules Engine](/en/documentation/platform/firewall/rules-engine/) rules that run the instance, check that the workloads you name are valid, and deny a request whose address is in the `Azion IP Tor Exit Nodes` [Network List](/en/documentation/platform/firewall/network-shield/network-lists/). Running the instance uses the **Functions** module and matching the list uses **Network Shield**, so the firewall carries both.

To put Bot Manager Lite on a firewall you already run instead, refer to [Add Bot Manager Lite to a Firewall](/en/documentation/guides/application-development/integrations/bot-manager-lite-integration-kit/). To build the instance and the rule by hand, refer to [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).

---

## Prerequisites

- Bot Manager Lite installed from Marketplace. For more information, refer to [Install Bot Manager Lite](/en/documentation/guides/application-development/integrations/bot-manager-lite/).
- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- The IDs of the workloads you want the firewall to protect. They are optional: the firewall deploys with no workload bound to it.
- The instance runs as a [Functions](/en/documentation/platform/functions/) instance and the deny rule runs on **Network Shield**. Both can generate usage costs. For the metrics Bot Manager is billed on, refer to [Pricing](/en/documentation/fundamentals/pricing/#bot-manager).

The template checks that Bot Manager Lite is installed before it creates anything. When it is not, the deployment fails and writes a log line naming the reason.

---

## Deploy the template

To deploy the template in Azion Console:

1. **(Optional) Copy the workload IDs**

   Access [Azion Console](https://console.azion.com/) > **Workloads**, select a workload you want the firewall to protect, and copy its ID from the address.

2. **Open the template**

   Go to the [Bot Manager Lite and TOR Block Starter Kit](https://console.azion.com/create/azion/bot-manager-and-tor-block-starter-kit) template.

3. **Enter the workload IDs**

   In **Domain ID(s)**, enter the IDs you copied. The field is optional: left empty, the template creates the firewall without binding it to a workload, and you bind one yourself afterwards.

4. **Select Deploy**

When the deployment finishes, the account carries a new firewall holding the function instance, the rule that runs it, and the rule that denies the Tor exit-node list.

---

## What the template configures

The function instance is listed under the firewall's **Functions Instances** tab, and the rules that run it under its **Rules Engine** tab. The instance carries three arguments:

```json
{
  "threshold": 10,
  "action": "allow",
  "internal_logs": 2
}
```

| Argument        | Value   | What it does                                                                                                                                                                                         |
| --------------- | ------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `threshold`     | `10`    | The score a request reaches before `action` fires. Bot Manager Lite ships `30`, so the template acts on requests the shipped default lets through                                                    |
| `action`        | `allow` | The instance scores every request and refuses none of them. For the seven values it takes, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#action)                   |
| `internal_logs` | `2`     | One report log line per request, whatever the request scored. For the four values it takes, refer to [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/#arguments) |

Nothing checks that object. An instance stores every key it is sent and reads it back unchanged, including a key the function never reads. A threshold written `thresold` stays `thresold`, the function goes on scoring against `30`, and no interface reports the difference.

Edit the object in the instance's **Arguments** section. Bot Manager Lite publishes no argument schema, so the editor has no form to build from one and you write raw JSON. For every argument an instance accepts, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/).

---

## Score a request from a Tor exit node

`Azion IP Tor Exit Nodes` is Network List `2`, maintained by Azion and present in every account. The rule the template creates matches that list and denies the request.

Bot Manager Lite also reads Network Lists. Rule `14` checks the client address against the lists whose IDs are listed in `reputation_network_lists` and adds 6 points for each list the address is found in. The template sets three arguments and `reputation_network_lists` is not one of them, so the instance scores a Tor address like any other until you name the list yourself:

```json
{
  "threshold": 10,
  "action": "allow",
  "internal_logs": 2,
  "reputation_network_lists": [2]
}
```

A request from a Tor exit node then scores 6 points more than the same request from any other address. For the rule table behind that score, refer to [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/#rules).

---

## Read what the instance scored

With `internal_logs` set to `2`, the instance writes one report log line for every request it scores, including a request that scored `0`. Read those lines in [Real-Time Events](/en/documentation/platform/real-time-events/), or forward them to a destination you own with [Data Stream](/en/documentation/platform/data-stream/). For the fields a line carries, refer to [Logs](/en/documentation/platform/firewall/bot-manager/logs/).

Because `action` is `allow`, the instance itself refuses nothing: the rule matching the Network List is what denies a Tor address. Set `threshold` and `action` from the scores your own traffic produces, rather than from the values the template starts at. For more information, refer to [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager/#read-the-report-log-in-real-time-events).

---

## Next steps

- [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite.md): The 26 rules the function scores against, including the reputation rule the Tor list feeds.
- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument a function instance accepts, with its type, its default, and the values it takes.
- [Network Lists](/en/documentation/platform/firewall/network-shield/network-lists.md): Build a list of your own addresses to name in reputation\_network\_lists alongside the Tor list.
- [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager.md): Read the report log and set the threshold from the scores your own traffic produces.
