Refuse requests above the threshold
Set action to deny on a Bot Manager Lite instance, from Azion Console, the Azion CLI, or the API, and read what a refused request receives.
You can set a Bot Manager Lite instance to refuse a request whose score reaches the threshold, from Azion Console, the Azion CLI, or the API. A refused request receives HTTP 403 with the page titled Azion - Default error page, and nothing in that answer names Bot Manager.
Prerequisites
- A firewall bound to the workload that serves your application, with Bot Manager Lite installed. Refer to the Bot Manager quickstart.
- The scores your own traffic produces, read from an observation window. To run one, refer to Run Bot Manager in observation mode.
- The Azion CLI installed and a configured personal token, for the CLI procedure.
- A personal token, for the API procedure. To create one, refer to Personal Tokens.
Set the action to deny
The object below is one value away from the observation object: action reads deny, so the instance answers 403 to a request whose score reaches threshold instead of serving it. At 30, the threshold Bot Manager Lite ships, a browser is not refused. A Chrome request carrying Accept, Accept-Language, Accept-Encoding, four Sec-Fetch-* headers, and Upgrade-Insecure-Requests reaches the application under this object. internal_logs at 2 keeps a report line for every request, so a refusal leaves a record of the score behind it.
For every argument an instance accepts, refer to Arguments.
To set the action from Azion Console:
Access Azion Console > Firewalls, then select that firewall.
On a firewall carrying no instance yet, select + Function, enter a Name, and select the Bot Manager Lite function in the Function section.
The section holds a JSON editor, because Bot Manager Lite carries no argument schema to build a form from.
The instance holds the new object. An instance already named by a rule keeps that rule: the arguments change under it, and no rule has to be touched.