---
name: azion-add-bot-manager-lite-to-a-firewall
description: >-
  Deploy the Bot Manager Lite Integration Kit template to add a function instance and a Rules Engine rule to a firewall you already have.
---

# Add Bot Manager Lite to a Firewall

You add [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/) to a [firewall](/en/documentation/platform/firewall/) you already run by deploying the Bot Manager Lite Integration Kit template from Azion Console.

The template creates one Bot Manager Lite function instance on the firewall you name, and one [Rules Engine](/en/documentation/platform/firewall/rules-engine/) rule that runs it. It adds to a firewall rather than creating one, so the deployment asks for the firewall's ID.

To create the instance and the rule yourself instead, refer to [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).

---

## Prerequisites

- A [firewall](/en/documentation/platform/firewall/) in your account, and its ID. For more information, refer to [Set a firewall's main settings](/en/documentation/guides/application-security/firewall-and-waf/firewall-configure-main-settings/).
- The **Functions** module turned on for that firewall.
- Bot Manager Lite installed from Marketplace. For more information, refer to [Install Bot Manager Lite](/en/documentation/guides/application-development/integrations/bot-manager-lite/).
- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- The instance runs as a [Functions](/en/documentation/platform/functions/) instance, which can generate usage costs. For the metrics Bot Manager is billed on, refer to [Pricing](/en/documentation/fundamentals/pricing/#bot-manager).

The template checks the first three requirements before it creates anything. When one of them is not met, the deployment fails and writes a log line naming the reason.

---

## Deploy the template

To deploy the template in Azion Console:

1. **Copy the firewall ID**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, select the firewall, and copy the ID from the address. The address ends in `/firewalls/edit/<firewall-id>`.

2. **Open the template**

   Go to the [Bot Manager Lite Integration Kit](https://console.azion.com/create/azion/bot-manager-integration-kit) template.

3. **Enter the firewall ID**

   In **Firewall ID**, enter the ID you copied. A field marked with an asterisk is mandatory.

4. **Select Deploy**

When the deployment finishes, the firewall carries the new function instance and the rule that runs it.

---

## What the template configures

The function instance is listed under the firewall's **Functions Instances** tab, and the rule that runs it under its **Rules Engine** tab. The instance carries three arguments:

```json
{
  "threshold": 10,
  "action": "allow",
  "internal_logs": 2
}
```

| Argument        | Value   | What it does                                                                                                                                                                                |
| --------------- | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `threshold`     | `10`    | The score at which `action` fires. The function ships a default of `30`, so the template acts on more requests than an instance that sets nothing                                           |
| `action`        | `allow` | The instance scores every request and refuses none. The seven values `action` takes are listed in [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/#action)            |
| `internal_logs` | `2`     | Every request produces a report log line, whatever it scored. The four values are listed in [Bot Manager Lite](/en/documentation/platform/firewall/bot-manager/bot-manager-lite/#arguments) |

Nothing validates that object. Every key an instance carries is stored and read back exactly as it was sent, including a key the function never reads. Write `thresold` in place of `threshold` and the instance keeps `thresold`, the function keeps scoring against `30`, and no interface reports a problem.

Edit the arguments in the instance's **Arguments** section. The installed function publishes no argument schema, so the editor has no form to build from one and the object is written as raw JSON. For every argument an instance accepts, refer to [Arguments](/en/documentation/platform/firewall/bot-manager/arguments/).

---

## Read what the instance scored

With `internal_logs` set to `2`, the instance writes one report log line for every request it scores, including a request that scored `0`. Read those lines in [Real-Time Events](/en/documentation/platform/real-time-events/), or forward them to a destination you own with [Data Stream](/en/documentation/platform/data-stream/). For the fields a line carries, refer to [Logs](/en/documentation/platform/firewall/bot-manager/logs/).

Because `action` is `allow`, the instance refuses nothing while you read them. Set `threshold` and `action` from the scores your own traffic produces, rather than from the values the template starts at. For more information, refer to [Monitor and calibrate Bot Manager](/en/documentation/guides/application-security/bots-and-network/monitor-and-calibrate-bot-manager/#read-the-report-log-in-real-time-events).

---

## Next steps

- [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart.md): Create the instance and the rule yourself, from Azion Console, the Azion CLI, or the API.
- [Arguments](/en/documentation/platform/firewall/bot-manager/arguments.md): Every argument a function instance accepts, with its type, its default, and the values it takes.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#bot-manager): Set the threshold from your own score distribution before the instance refuses anything.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#bot-manager): Find why an argument change did nothing, or why a client cannot reach the application.
