Change the order of firewall rules
Move a firewall rule above another one, so that a deny rule refuses a client before the rule that applies WAF scores it.
You change the order in which a firewall runs its rules from Azion Console or the Azion CLI. A firewall runs its rules in sequence, and a behavior such as Deny (403 Forbidden) stops every rule after it. The platform assigns each rule its position in creation order, so a deny rule created on a firewall that already applies WAF runs after the WAF rule, and WAF scores a client the deny rule refuses. For how the order decides what runs, refer to Rule order.
Prerequisites
- A firewall that holds the rules to order. To create a rule that denies the addresses in a network list, refer to Block addresses until a date.
- Access to Azion Console, for the Console procedure. Refer to Access Azion Console.
- The Azion CLI installed and authorized, and the ID of the firewall, for the CLI procedure.
The examples move the rule siem - deny listed addresses above the rule that applies WAF, on the firewall <firewall-id>. Replace them with your rules and firewall.
Move a rule above another rule
The rule you move runs before every rule below it, so a request it denies never reaches them. The Azion CLI sets the whole order at once, from the IDs of every rule of the firewall.
To move the rule in Azion Console:
Access Azion Console > Firewalls, select the firewall, then go to the Rules Engine tab.
In the Rules Engine list, move siem - deny listed addresses above the rule that applies WAF.
The Rules Engine list shows siem - deny listed addresses above the rule that applies WAF.
The firewall runs siem - deny listed addresses before the rule that applies WAF, so a listed address is refused before WAF scores it.
The Block attackers automatically from SIEM detections use case uses the values of this example.
In the Screen file uploads for malicious content use case, this section takes these values:
| Setting | Value |
|---|---|
| Position | Below upload - deny flagged senders |
Confirm the new order
To confirm the order, list the rules of the firewall again:
The command prints the rules in the new order, with siem - deny listed addresses above the rule that applies WAF. For every flag of the command, refer to Azion CLI firewall-rule.