Install the Phone Validation integration
Install Phone Validation from Azion Marketplace and run it on a firewall to check phone numbers against IPQualityScore before requests reach your origin.
You install the Phone Validation integration from Azion Marketplace and run it on a Firewall, from Azion Console. The integration checks phone numbers with the IPQualityScore API: risk score, country of origin, carrier, line type, and connection status. On each request, the function reads the phone number from the query string, the request body, or a header, queries IPQualityScore, and then blocks the request, drops it, or adds a header to signal the result. This stops fraudulent numbers, inactive lines, and high-risk VOIPs before they reach your origin.
Five objects have to exist before a request is checked: the installed function, a firewall carrying the Functions module, a function instance holding the arguments, a Rules Engine rule with the Run Function behavior, and a workload deployment bound to the firewall. Each section below creates one of them.
Prerequisites
- An Azion account. To sign in, refer to How to access Azion Console.
- An application served by a workload, whose deployment you bind to the firewall in the last section.
- An IPQualityScore account. After you create it, get your API key from the IPQualityScore dashboard.
- The Azion CLI installed and authorized, for the last section.
- Turning on a product or a module can generate usage costs. For more information, refer to Pricing.
Install the integration
The function is installed once per account. To install it:
Access Azion Console > Marketplace.
Enter Phone Validation in the Search on Marketplace field, then select the integration’s card. Browsing the cards and the categories reaches the same page.
The card shows Successfully installed! and Latest version installed!, and the function appears in the Function list of the Create Instance drawer.
Create the firewall
The firewall is where the function is instanced and where the rule that runs it lives. To create one:
Access Azion Console > Firewalls, then create a firewall.
In the General section, enter a Name. For example: phone-validation-firewall.
In the Modules section, turn on the Functions switch.
The firewall shows a Functions Instances tab while the Functions module stays on. To use an existing firewall instead, turn on its Functions module and save it. For every setting on this form, refer to Set a firewall’s main settings.
Create the function instance
The instance holds your IPQualityScore API key, where the phone number comes from, and what to do with a risky one. To create it:
In Firewalls, select your firewall, then select the Functions Instances tab.
A firewall that has no instance shows the same action as Function Instance. The Create Instance drawer opens.
In Name, enter a name. For example: phone-validation.
In Function, select the Phone Validation function. The list holds only the functions that run on a firewall.
In Arguments, the editor is prefilled with the integration’s default arguments in JSON. Enter your values, as the next section describes.
The instance is listed in the Functions Instances tab.
Arguments
The instance takes your API key, the source of the phone number, and the action:
| Variable | Required | Description |
|---|---|---|
api_key | Yes | Your IPQualityScore API key |
fast | No | Turns on fast validation mode. When true, the API skips some forensic checks for lower latency. Recommended: true. Default: false |
get_data_from | Yes | Where the function reads the phone number. Accepted values: querystring, body, header |
data_name | Yes | The name of the query string parameter, body field, or header that holds the phone number |
when_score_above | No | The score threshold (0–100) that triggers the action in execute. A fraud score ≥ 90 is high risk. If you do not set it, the function takes no action |
execute | No | The action when the score exceeds when_score_above. Accepted values: deny, drop, add_header |
Each execute value does the following:
| Value | Behavior |
|---|---|
deny | Runs the Deny behavior, which returns a 403 Forbidden response |
drop | Runs the Drop behavior, which closes the connection without a response |
add_header | Adds the ipqs-limit-score-reached header to the request and lets the request continue. Use it to handle the result in Rules Engine or at the origin |
Create the rule
The instance checks nothing until a rule runs it. A Rules Engine for Firewall rule selects the requests that reach the instance, through a Run Function behavior. To create the rule:
In Firewalls, select your firewall, then select the Rules Engine tab.
In Name, enter a name. For example: Run Phone Validation.
In the Criteria section, select the requests that trigger the phone validation check. For example: if Host matches yourdomain.com.
In the Behaviors section, select Run Function, then select the instance by the name you gave it.
The firewall runs the instance on every request that matches the criterion.
Bind the firewall to the workload
The binding is on the workload’s deployment, so create a deployment that names both the application and the firewall:
The command prints the id of the new deployment:
Requests to the workload’s domain reach the firewall, and the rule runs the Phone Validation instance on each one that matches.