---
name: azion-apply-a-rule-set-to-every-request
description: >-
  Create the firewall rule whose Set WAF behavior hands every request to one rule set, from Azion Console, the Azion CLI, or the API.
---

# Apply a rule set to every request

You can create the [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule that applies a rule set to every request from Azion Console, the Azion CLI, or the API. A rule set scores nothing until a rule names it, and the criterion below skips no request.

---

## Prerequisites

- A firewall bound to your workload, with WAF turned on in its main settings.
- A rule set to apply, such as `storefront-waf`. To create one, refer to [Create a rule set at medium sensitivity](/en/documentation/guides/application-security/firewall-and-waf/rule-set-medium/).
- The [Azion CLI](/en/documentation/devtools/cli/) installed and a configured personal token, for the CLI procedure.
- A personal token, for the API request.

---

## Create the rule

**Console**

To create the rule from Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select that firewall.

2. **Select the Rules Engine tab**

3. **Select + Rule**

4. **Name the rule**

   Enter `Apply storefront-waf` as the name.

5. **Set the criterion**

   In the **Criteria** section, select the `Request Uri` variable, the *starts with* operator, and `/` as the argument.

6. **Add the Set WAF behavior**

   In the **Behaviors** section, select **Set WAF**, then `storefront-waf` as the rule set and *Blocking* as the mode.

7. **Save the rule**

The rule hands every request the firewall receives to `storefront-waf` in blocking mode.

For the same rule with the threat families and the mode left open, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

**CLI**

To create the rule with the Azion CLI, save it as `rule.json`, with the id of your rule set in `waf_id`:

```json
{
  "name": "Apply storefront-waf",
  "active": true,
  "criteria": [
    [
      {
        "conditional": "if",
        "variable": "${request_uri}",
        "operator": "starts_with",
        "argument": "/"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_waf",
      "attributes": {
        "waf_id": 12349,
        "mode": "blocking"
      }
    }
  ]
}
```

Then create the rule from the file:

```bash
azion create firewall-rule --firewall-id <firewall-id> --file rule.json
```

```text
Created Firewall Rule with ID 123457
```

The output reports the id of the new rule.

**API**

Save the rule as `rule.json`, with the id of your rule set in `waf_id`:

```json
{
  "name": "Apply storefront-waf",
  "active": true,
  "criteria": [
    [
      {
        "conditional": "if",
        "variable": "${request_uri}",
        "operator": "starts_with",
        "argument": "/"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_waf",
      "attributes": {
        "waf_id": 12349,
        "mode": "blocking"
      }
    }
  ]
}
```

Send a `POST` request to the firewall's request rules endpoint, with the file as the body:

```bash
curl --request POST \
  --url https://api.azion.com/v4/workspace/firewalls/<firewall-id>/request_rules \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data @rule.json
```

The API answers `202` and returns the rule with two keys it assigned: an empty `description` and the `order` the rule holds among the rules of that firewall.

> **Note**
>
> `criteria` is a list of lists, and a rule carries at most one `Set WAF` behavior. `mode` is required on that behavior: a `set_waf` behavior sent without it is refused with `400` and the error `10059 Required Field`, pointing at `/data/behaviors/0/attributes/mode`. Key the criterion on `${request_uri}`, not on the query string. An empty variable does not match, so `${request_args}` with the `matches` operator and `.*` skips every request carrying no query string, including a `POST` whose payload sits entirely in the body.

---

## Next steps

- [Switch a rule set to blocking](/en/documentation/guides/application-security/firewall-and-waf/switch-to-blocking.md): Change the mode on this behavior after the rule is already in place.
- [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes.md): Where this rule sits in the path a request travels, and what happens after it matches.
