Create and apply a WAF rule set
Create a WAF rule set with the threat families and sensitivity you choose, then apply it to a firewall with a Set WAF behavior.
Create a Web Application Firewall (WAF) rule set, then apply it to a firewall with a Rules Engine rule. Both tasks run from Azion Console, the Azion CLI, or the API.
For a first run that ends in a blocked request, refer to WAF quickstart. That page fixes every option along the way. This page leaves them open: you choose the threat families, the sensitivity of each one, and the mode.
Select an interface. The prerequisites and both tasks follow that choice.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- A firewall carrying the WAF module. WAF is the one module a firewall leaves off by default. Refer to Set a firewall’s main settings.
- A workload bound to that firewall, so the rule you create receives traffic. Refer to Bind a firewall to a workload.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the rule set
A rule set carries up to eight threat families, and each family holds its own sensitivity. The sensitivity fixes the score a request has to reach before that family blocks it. Every family opens at medium. A higher sensitivity blocks at a lower score: it catches attacks carrying less evidence, and refuses more legitimate traffic with them. For what each family detects and what each level costs, refer to WAF Rule Sets.
The form lists all eight families, so every sensitivity is set in one place. To create the rule set in Azion Console:
Access Azion Console > Edge Libraries > WAF Rules.
In the General section, enter a Name. For example: checkout-waf.
The Threat Type Configuration section lists eight families, each opening on Sensitivity Medium. For example, set SQL Injection to Sensitivity High.
The rule set appears in WAF Rules, with its Threat Type Configuration and Status. It scores nothing until a Rules Engine rule names it.
Apply the rule set to a firewall
A Rules Engine for Firewall rule selects requests with its own criteria and runs behaviors on them. The Set WAF behavior names one rule set and one mode. A rule carries at most one Set WAF behavior.
The mode belongs to the behavior rather than to the rule set, and it is required. Logging scores a request, records it, and serves it. Blocking refuses a request whose score reaches a threshold of its family. For the order to move between them, refer to Firewall best practices.
To apply the rule set in Azion Console:
Access Azion Console > Firewalls, then select the firewall bound to your workload.
Enter a name for the rule. For example: Apply checkout-waf.
In the Criteria section, select the Request Uri variable, the starts with operator, and / as the argument.
In the Behaviors section, select Set WAF, then select checkout-waf as the rule set.
The firewall scores every request it receives against the rule set.
A new rule takes minutes to reach Azion’s distributed infrastructure. Until it has, a request can still be answered the way it was before the rule existed.