---
name: azion-bind-a-rule-set-in-azion-config-js
description: >-
  Declare the WAF rule set and the firewall rule that applies it in azion.config.js, so the Azion CLI creates both from the repository.
---

# Bind a rule set in azion.config.js

You can declare a WAF rule set and the firewall rule that applies it in `azion.config.js`, and let the [Azion CLI](/en/documentation/devtools/cli/) create both from the file. Both then live in the repository, under review alongside the application they protect.

---

## Prerequisites

You need the Azion CLI installed and a configured personal token.

---

## Declare the rule set and the rule

In `azion.config.js`, declare the firewall with `waf: true`, the rule that carries the `setWafRuleset` behavior, and the rule set under `waf`:

```javascript
import { defineConfig } from 'azion';

export default defineConfig({
  firewall: {
    name: 'storefront-firewall',
    active: true,
    waf: true,
    rules: [
      {
        name: 'Apply storefront-waf',
        active: true,
        criteria: [
          {
            variable: 'request_uri',
            conditional: 'if',
            operator: 'starts_with',
            argument: '/',
          },
        ],
        behaviors: [
          {
            setWafRuleset: {
              wafMode: 'blocking',
              wafId: '<waf-id>',
            },
          },
        ],
      },
    ],
  },
  waf: [
    {
      name: 'storefront-waf',
      engineSettings: {
        engineVersion: '2021-Q3',
        type: 'score',
        attributes: {
          rulesets: [1],
          thresholds: [
            { threat: 'sql_injection', sensitivity: 'medium' },
            { threat: 'cross_site_scripting', sensitivity: 'medium' },
          ],
        },
      },
    },
  ],
});
```

The Azion CLI reads the file and creates what it declares: the firewall with WAF turned on, the rule set, and the rule that applies it.

`waf: true` on the firewall turns WAF on, and it stays off until you turn it on. A family you leave out of `thresholds` is not configured, so list every family you want scored. `setWafRuleset` takes exactly two keys, `wafMode` and `wafId`. `wafMode` takes `learning` or `blocking` in this file: the same mode reads *Logging* in Azion Console and `logging` in an API payload. For what each mode does, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/).

---

## Next steps

- [Apply a rule set to every request](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set.md): The same binding as an API call, with the response it returns.
- [azion.config.js](/en/documentation/devtools/cli/azion-config-js.md): Every field this file accepts, including the firewall behaviors a rule can carry.
