Create a WAF exception
Exempt one internal rule from scoring one part of a request, on the path that produces a false positive, from Azion Console, the CLI, or the API.
You can create a Web Application Firewall (WAF) exception from Azion Console, the Azion CLI, or the API. An exception takes one part of a request out of one internal rule’s scoring, on the path you name. To turn many matched requests into exceptions at once instead, refer to Tune a WAF rule set.
Azion Console calls an exception an allowed rule, and the tab that holds them reads Allowed Rules. The API and the Azion CLI call the same object an exception.
The example on this page clears one false positive. An API at /api/v1/data reads a filter query string parameter whose values carry an apostrophe:
Internal rule 1013 matches that apostrophe and the request is refused. The exception below takes the filter parameter out of rule 1013 on that path alone, and leaves the rule scoring every other request.
Select the interface you will use. The prerequisites and every procedure below follow that choice.
Prerequisites
- A firewall with the WAF module turned on. Refer to Set a firewall’s main settings.
- A rule set applied to the requests you want to exempt. Refer to Create and apply a WAF rule set.
- The identifier of the internal rule that produced the false positive. For the identifiers and what each rule detects, refer to WAF Rule Sets.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the exception
An exception names the internal rule it exempts, the path it is restricted to, and at least one condition naming the part of the request it covers. A condition built on a specific_* match zone carries the name or the value of one field; a generic match zone covers that part of every request. For every field an exception takes and all fifteen match zones, refer to WAF Exceptions.
The comparison is set once, for the whole exception. contains reads the path and the condition’s name or value as substrings. regex reads both as regular expressions, and there is no way to make one a pattern and the other a literal.
To create the exception in Azion Console:
Access Azion Console > Edge Libraries > WAF Rules.
In Rule ID, select the rule that produced the false positive. For this example, rule 1013.
In Description, enter what the exception is for. For example: Allow apostrophes in the data API filter.
In Path, enter /api/v1/data.
In Condition, select Specific Query String Name and enter filter in the Name field it reveals.
In Operator, select contains to read the strings as substrings, or regex to read them as regular expressions.
The exception appears in the Allowed Rules tab, in a row carrying Rule ID, Description, Path, Conditions, Status, Last Editor, and Last Modified. The same tab carries a Create from Tuning button, which writes exceptions from records the rule set already matched.
An exception is accepted before it is in force. It reaches Azion’s distributed infrastructure over the next few minutes, so a request that is still refused right after the create has broken nothing. Wait, then send it again.
Confirm what the exception covers
Reading the exception back is the only way to catch that. Compare the conditions you get with the ones you sent, field by field.
To read the exception back in Azion Console:
The column carries the match zone and, for a specific_* zone, the name or the value it applies to. A row whose match zone reads Any where you selected Specific covers that whole part of every request.