---
name: azion-change-the-order-of-firewall-rules
description: >-
  Move a firewall rule above another one, so that a deny rule refuses a client before the rule that applies WAF scores it.
---

# Change the order of firewall rules

You change the order in which a firewall runs its rules from Azion Console or the Azion CLI. A firewall runs its rules in sequence, and a behavior such as *Deny (403 Forbidden)* stops every rule after it. The platform assigns each rule its position in creation order, so a deny rule created on a firewall that already applies WAF runs after the WAF rule, and WAF scores a client the deny rule refuses. For how the order decides what runs, refer to [Rule order](/en/documentation/platform/firewall/how-it-works/#rule-order).

---

## Prerequisites

- A firewall that holds the rules to order. To create a rule that denies the addresses in a network list, refer to [Block addresses until a date](/en/documentation/guides/application-security/bots-and-network/temporary-block/).
- Access to Azion Console, for the Console procedure. Refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and authorized, and the ID of the firewall, for the CLI procedure.

The examples move the rule `siem - deny listed addresses` above the rule that applies WAF, on the firewall `<firewall-id>`. Replace them with your rules and firewall.

---

## Move a rule above another rule

The rule you move runs before every rule below it, so a request it denies never reaches them. The Azion CLI sets the whole order at once, from the IDs of every rule of the firewall.

**Console**

To move the rule in Azion Console:

1. **Open the firewall's Rules Engine tab**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, select the firewall, then go to the **Rules Engine** tab.

2. **Move the rule to the top**

   In the **Rules Engine** list, move `siem - deny listed addresses` above the rule that applies WAF.

The **Rules Engine** list shows `siem - deny listed addresses` above the rule that applies WAF.

**CLI**

To move the rule with the Azion CLI, list the rules of the firewall to read their IDs:

```bash
azion list firewall-rule --firewall-id <firewall-id>
```

The command prints one row per rule:

```text
ID              NAME                          ACTIVE  DESCRIPTION
<waf-rule-id>   <waf-rule-name>               true
<deny-rule-id>  siem - deny listed addresses  true
```

Send every rule ID of the firewall, in the order the rules must run, with the deny rule first:

```bash
azion update firewall-rule-order --firewall-id <firewall-id> --rule-ids "<deny-rule-id>,<waf-rule-id>"
```

The command confirms the new order:

```text
Ordered Rules Engine of Firewall with ID <firewall-id>
```

A list that leaves out a rule of the firewall fails with this error:

```text
Error: Failed to order the rules in Rules Engine of the Firewall: ["When ordering you should provide the order for all rules."]. Check your settings and try again. If the error persists, contact Azion support.
```

The firewall runs `siem - deny listed addresses` before the rule that applies WAF, so a listed address is refused before WAF scores it.

The [Block attackers automatically from SIEM detections](/en/documentation/use-cases/secure-applications-and-networks/block-attackers-automatically-from-siem-detections/) use case uses the values of this example.

In the [Screen file uploads for malicious content](/en/documentation/use-cases/secure-applications-and-networks/screen-file-uploads-for-malicious-content/) use case, this section takes these values:

| Setting  | Value                                 |
| -------- | ------------------------------------- |
| Position | Below `upload - deny flagged senders` |

---

## Confirm the new order

To confirm the order, list the rules of the firewall again:

```bash
azion list firewall-rule --firewall-id <firewall-id>
```

The command prints the rules in the new order, with `siem - deny listed addresses` above the rule that applies WAF. For every flag of the command, refer to [Azion CLI firewall-rule](/en/documentation/devtools/cli/resources/firewall-rule/#order-rules).

---

## Next steps

- [Rule order](/en/documentation/platform/firewall/how-it-works.md#rule-order): Why the position of a rule decides which rules run on a request.
- [Block attackers automatically from SIEM detections](/en/documentation/use-cases/secure-applications-and-networks/block-attackers-automatically-from-siem-detections.md): A deny rule on a network list that holds the first position, above the rule that applies WAF.
- [Screen file uploads for malicious content](/en/documentation/use-cases/secure-applications-and-networks/screen-file-uploads-for-malicious-content.md): A firewall function that screens uploads, in a rule below the rule that denies flagged senders.
