---
name: azion-run-a-function-on-a-firewall
description: >-
  Create a function that runs on a firewall, instantiate it, and add the Rules Engine rule that triggers it.
---

# Run a function on a firewall

You can create a function, instantiate it on a firewall, and trigger it with a Rules Engine rule. Every step runs in Azion Console. To instantiate a function on a firewall from the Azion API, refer to [Instantiate a function on a firewall](/en/documentation/guides/application-security/firewall-and-waf/instantiate-functions/). To run a function on an application instead, refer to [Run a function on an application](/en/documentation/guides/application-development/functions-and-runtime/serverless-functions/).

---

## Prerequisites

- An Azion account. To create one, refer to [How to create an account on Azion](/en/documentation/fundamentals/creating-account/).
- The **Edit Functions** permission on the account. It grants permission to create, edit, and remove functions, and it also requires the permission **View Functions**.
- The **Edit Firewall** permission on the account. It grants permission to view, create, edit, and remove a firewall, and it also requires the permission **View Firewall**. Refer to [Teams Permissions](/en/documentation/fundamentals/teams-permissions/).

---

## Create the function

A function runs on a firewall when it exports a `firewall` handler. To create the function:

1. **Open the Functions page**

   Access [Azion Console](https://console.azion.com/) > **Products Menu** > **Libraries** > **Functions**.

2. **Select + Function**

3. **Name the function**

   Enter a name for the function. For example: `deny-request`.

4. **Paste the code in the Code tab**

   In the **Code** tab, paste the following code:

   ```javascript
   export default {
     firewall: (request, env, ctx) => {
       ctx.deny();
     }
   };
   ```

5. **Select Save**

The function is saved and available to instantiate on a firewall.

The `firewall` handler decides the outcome of the request. `ctx.deny()` closes the request with an HTTP `403 Forbidden` response. When the handler does not call `ctx.deny()`, the request continues to the `fetch` handler. For the other outcomes a firewall function returns, refer to [Functions for Firewall](/en/documentation/platform/firewall/functions/).

> **Tip**
>
> The sample uses the ES Modules pattern. To move a function from the Service Worker pattern to this one, refer to [Migrate handler patterns in Functions](/en/documentation/guides/application-development/functions-and-runtime/migrate-handler-patterns/).

---

## Create the firewall

A firewall runs a function only with the **Functions** module turned on. To create the firewall:

1. **Open the Firewall page**

   In Azion Console, go to **Products Menu** > **Firewall**.

2. **Select + Firewall**

3. **Name the firewall**

   Enter a name for the firewall. For example: `deny-request firewall`.

4. **Select the domains the firewall secures**

   In the **Domains** field, select the domains to associate with the firewall.

5. **Turn on the Functions module**

6. **Turn on the Active switch**

7. **Select Save**

The firewall is saved, and the **Functions Instances** and **Rules Engine** tabs become available on the same page.

> **Note**
>
> To use a firewall that already exists, open it and turn on the **Functions** module in the **Main Settings** tab.

---

## Instantiate the function on the firewall

A function instance binds the function to one firewall. To create the instance:

1. **Go to the Functions Instances tab**

   In the firewall you created, go to the **Functions Instances** tab.

2. **Select + Function Instance**

3. **Name the instance**

   Enter a name for the instance. For example: `deny-request instance`.

4. **Select the function**

   Select the `deny-request` function. Only functions whose **Initiator Type** is set to *Firewall* appear in the list.

5. **Select Save**

The instance appears in the **Functions Instances** tab. It does not run until a Rules Engine rule selects it.

---

## Add the rule that runs the function

A Rules Engine rule sets the criteria that trigger the instance. To run the instance on requests whose URI starts with `/admin`:

1. **Go to the Rules Engine tab**

   In the same firewall, go to the **Rules Engine** tab.

2. **Select + Rule**

3. **Name the rule**

   Enter a name for the rule. For example: `Run deny-request`.

4. **Select the variable in the Criteria section**

   In the **Criteria** section, select the `Request URI` variable.

5. **Select starts with as the comparison operator**

6. **Enter the argument**

   Enter `/admin` as the argument.

7. **In the Behaviors section, select Run Function**

8. **Select the instance you created**

9. **Select Save**

The rule runs the instance on every request whose URI starts with `/admin`, and the function answers those requests with an HTTP `403 Forbidden` response. Changes can take a few minutes to propagate. Wait before you send a request that matches the criteria.

> **Caution**
>
> The sample function denies every request the rule matches. Set criteria that select only the requests you want to block.

---

## Next steps

- [Instantiate a function on a firewall](/en/documentation/guides/application-security/firewall-and-waf/instantiate-functions.md): Create the same instance from the Azion API, and pass Args to it in JSON.
- [Functions for Firewall](/en/documentation/platform/firewall/functions.md): The outcomes a firewall function returns, and the request and response headers it adds.
- [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine.md): Every criteria variable, comparison operator, and behavior a firewall rule accepts.
- [Run a function on an application](/en/documentation/guides/application-development/functions-and-runtime/serverless-functions.md): The same path on an application, where the rule also sets the execution phase.
