Run Bot Manager on selected paths
Run a Bot Manager instance only on the paths that need it, such as a login or a checkout, with its own threshold, action, and log tag.
You run a Bot Manager instance on the paths you choose, such as /account/ and /checkout/, from Azion Console, the Azion CLI, or the API. To run one instance on every request a firewall receives, refer to Run Bot Manager on every request.
Bot Manager bills each request it scores, and a path that no rule matches is not scored. One instance carries one threshold and one action, so paths that differ in value, such as a catalog and a checkout, take an instance each, with its own rule.
- The rule compares the request URI with the selected paths. A request to any other path is not scored.
- A request for an image, a stylesheet, a script, or another static asset on those paths is not scored either.
- The instance scores every other request and writes a report line tagged with its
log_tag. - A request whose score reaches the threshold receives the instance’s action, and a request below it continues.
Prerequisites
- A firewall bound to the workload that serves the paths, with Functions turned on in its main settings. Refer to the Bot Manager quickstart.
- Bot Manager enabled on the account, or Bot Manager Lite installed from Azion Marketplace, and the ID of the installed function for the CLI and the API. To install Bot Manager Lite, refer to Install Bot Manager Lite.
- A personal token, for the API and the CLI.
- The Azion CLI installed and authorized, for the CLI procedure.
- Access to Azion Console, for the Console procedure. Refer to Access Azion Console.
The examples score /account/ and /checkout/ on www.example.com, with the instance checkout-bots on the firewall <firewall-id>. Replace them with your paths, names, and firewall.
Create an instance for the paths
The instance takes one JSON arguments object, and nothing validates it: a misspelled key such as thresold is stored, and the function never reads it. Write threshold and action on every instance. Bot Manager Lite ships deny at 30, and Bot Manager documents allow at Infinity, so an instance that sets neither refuses requests on one edition and passes them on the other. The object below starts in observation mode: action is allow, so nothing is refused, and internal_logs is 2, so every request writes a report line. log_tag names this instance in those lines.
Run it for 24 to 72 hours, then set threshold in the gap between the scores of the clients you recognize and the automated ones, and choose one of the seven actions:
action | What the function does at the threshold |
|---|---|
allow | Lets the request continue, whatever its score |
custom_html | Returns the HTML in custom_html, with the status code in custom_status_code |
deny | Returns 403 with Azion’s default error page |
drop | Terminates the request without a response |
hold_connection | Holds the connection open for 1 minute, then drops the request |
random_delay | Waits a random period between 1 and 10 seconds, then lets the request continue |
redirect | Redirects the request to the location in redirect_to |
A value outside the seven is read as allow, and so are custom_html and redirect without their second argument. On Bot Manager, mode set to api scores web services and API traffic that carries no cookies. For the starting threshold per kind of path, refer to Run a stricter Bot Manager instance on a high-value path.
To create the instance in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
On a firewall that carries no instance yet, the button reads + Function Instance.
In the General section, enter checkout-bots as the Name.
In the Function section, select the installed Bot Manager or Bot Manager Lite function.
In the Arguments section, enter the object.
The instance appears in the Functions Instances list, which shows its Name, Function, Last Editor, and Last Modified.
The instance exists on the firewall and scores nothing until a rule runs it.
Create the rule that runs it on the paths
The rule holds two blocks of criteria, and a request matches it only when it matches both. The first block names the paths, each joined by or: Request Uri starts with /account/, or starts with /checkout/. The second block keeps static assets out, because none is a client and each is a request Bot Manager bills: Request Uri does not match this expression, which also matches an asset requested with a query string:
The Run Function behavior names the instance, and a rule carries at most one, so a second instance on other paths takes a second rule.
To create the rule in Azion Console:
Access Azion Console > Firewalls, select the firewall, then select the Rules Engine tab.
Enter checkout - score clients.
In the Criteria section, select the Request Uri variable, the starts with operator, and /account/ as the argument.
Select Or, then Request Uri, starts with, and /checkout/.
Select Add Criteria. In the new block, select Request Uri, does not match, and the expression above.
In the Behaviors section, select Run Function, then checkout-bots.
The instance scores every request to /account/ and /checkout/ except static assets, and no request to any other path. A format added to your site later is scored until you add it to the expression.
Confirm the instance scores only the paths
A new rule reaches traffic 6 minutes 29 seconds to 9 minutes 18 seconds after you save it, and a change to an instance’s arguments about 105 seconds after. Repeat each check until the answers agree.
To confirm what the instance scores:
-
Send one request with no user agent to a selected path, and one to a path outside them:
Shell -
Query the
functionConsoleEventsdataset for the report lines, with atsRangethat covers the requests:Shell -
Read the lines. The request to
/checkout/has one, which opens with the instance’s tag and carriesrequest_uri,score,matched_rules, andaction:The request to
/has no line, because the rule does not match it.
The instance scores the selected paths and nothing else. Read score and matched_rules rather than classified, which depends on the threshold in force. For every field of a line, refer to Logs, and to raise the action once the window closes, refer to Refuse requests above the threshold.