Run a function on a firewall
Create a function that runs on a firewall, instantiate it, and add the Rules Engine rule that triggers it.
You can create a function, instantiate it on a firewall, and trigger it with a Rules Engine rule. Every step runs in Azion Console. To instantiate a function on a firewall from the Azion API, refer to Instantiate a function on a firewall. To run a function on an application instead, refer to Run a function on an application.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- The Edit Functions permission on the account. It grants permission to create, edit, and remove functions, and it also requires the permission View Functions.
- The Edit Firewall permission on the account. It grants permission to view, create, edit, and remove a firewall, and it also requires the permission View Firewall. Refer to Teams Permissions.
Create the function
A function runs on a firewall when it exports a firewall handler. To create the function:
Access Azion Console > Products Menu > Libraries > Functions.
Enter a name for the function. For example: deny-request.
In the Code tab, paste the following code:
The function is saved and available to instantiate on a firewall.
The firewall handler decides the outcome of the request. ctx.deny() closes the request with an HTTP 403 Forbidden response. When the handler does not call ctx.deny(), the request continues to the fetch handler. For the other outcomes a firewall function returns, refer to Functions for Firewall.
Create the firewall
A firewall runs a function only with the Functions module turned on. To create the firewall:
In Azion Console, go to Products Menu > Firewall.
Enter a name for the firewall. For example: deny-request firewall.
In the Domains field, select the domains to associate with the firewall.
The firewall is saved, and the Functions Instances and Rules Engine tabs become available on the same page.
Instantiate the function on the firewall
A function instance binds the function to one firewall. To create the instance:
In the firewall you created, go to the Functions Instances tab.
Enter a name for the instance. For example: deny-request instance.
Select the deny-request function. Only functions whose Initiator Type is set to Firewall appear in the list.
The instance appears in the Functions Instances tab. It does not run until a Rules Engine rule selects it.
Add the rule that runs the function
A Rules Engine rule sets the criteria that trigger the instance. To run the instance on requests whose URI starts with /admin:
In the same firewall, go to the Rules Engine tab.
Enter a name for the rule. For example: Run deny-request.
In the Criteria section, select the Request URI variable.
Enter /admin as the argument.
The rule runs the instance on every request whose URI starts with /admin, and the function answers those requests with an HTTP 403 Forbidden response. Changes can take a few minutes to propagate. Wait before you send a request that matches the criteria.