Block bots and Tor exit nodes with a template
Deploy the Bot Manager Lite and TOR Block Starter Kit template to create a firewall that scores requests and denies Tor exit-node addresses.
You create a firewall that scores requests with Bot Manager Lite and refuses Tor exit-node addresses by deploying the Bot Manager Lite and TOR Block Starter Kit template from Azion Console.
The template creates the firewall, one Bot Manager Lite function instance on it, and the Rules Engine rules that run the instance, check that the workloads you name are valid, and deny a request whose address is in the Azion IP Tor Exit Nodes Network List. Running the instance uses the Functions module and matching the list uses Network Shield, so the firewall carries both.
To put Bot Manager Lite on a firewall you already run instead, refer to Add Bot Manager Lite to a Firewall. To build the instance and the rule by hand, refer to Bot Manager quickstart.
Prerequisites
- Bot Manager Lite installed from Marketplace. For more information, refer to Install Bot Manager Lite.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
- The IDs of the workloads you want the firewall to protect. They are optional: the firewall deploys with no workload bound to it.
- The instance runs as a Functions instance and the deny rule runs on Network Shield. Both can generate usage costs. For the metrics Bot Manager is billed on, refer to Pricing.
The template checks that Bot Manager Lite is installed before it creates anything. When it is not, the deployment fails and writes a log line naming the reason.
Deploy the template
To deploy the template in Azion Console:
Access Azion Console > Workloads, select a workload you want the firewall to protect, and copy its ID from the address.
Go to the Bot Manager Lite and TOR Block Starter Kit template.
In Domain ID(s), enter the IDs you copied. The field is optional: left empty, the template creates the firewall without binding it to a workload, and you bind one yourself afterwards.
When the deployment finishes, the account carries a new firewall holding the function instance, the rule that runs it, and the rule that denies the Tor exit-node list.
What the template configures
The function instance is listed under the firewall’s Functions Instances tab, and the rules that run it under its Rules Engine tab. The instance carries three arguments:
| Argument | Value | What it does |
|---|---|---|
threshold | 10 | The score a request reaches before action fires. Bot Manager Lite ships 30, so the template acts on requests the shipped default lets through |
action | allow | The instance scores every request and refuses none of them. For the seven values it takes, refer to Arguments |
internal_logs | 2 | One report log line per request, whatever the request scored. For the four values it takes, refer to Bot Manager Lite |
Nothing checks that object. An instance stores every key it is sent and reads it back unchanged, including a key the function never reads. A threshold written thresold stays thresold, the function goes on scoring against 30, and no interface reports the difference.
Edit the object in the instance’s Arguments section. Bot Manager Lite publishes no argument schema, so the editor has no form to build from one and you write raw JSON. For every argument an instance accepts, refer to Arguments.
Score a request from a Tor exit node
Azion IP Tor Exit Nodes is Network List 2, maintained by Azion and present in every account. The rule the template creates matches that list and denies the request.
Bot Manager Lite also reads Network Lists. Rule 14 checks the client address against the lists whose IDs are listed in reputation_network_lists and adds 6 points for each list the address is found in. The template sets three arguments and reputation_network_lists is not one of them, so the instance scores a Tor address like any other until you name the list yourself:
A request from a Tor exit node then scores 6 points more than the same request from any other address. For the rule table behind that score, refer to Bot Manager Lite.
Read what the instance scored
With internal_logs set to 2, the instance writes one report log line for every request it scores, including a request that scored 0. Read those lines in Real-Time Events, or forward them to a destination you own with Data Stream. For the fields a line carries, refer to Logs.
Because action is allow, the instance itself refuses nothing: the rule matching the Network List is what denies a Tor address. Set threshold and action from the scores your own traffic produces, rather than from the values the template starts at. For more information, refer to Monitor and calibrate Bot Manager.