---
name: azion-set-a-firewall-s-main-settings
description: >-
  Enable WAF, Network Shield, or Functions on a firewall from Azion Console, the Azion CLI, or the API, and rename it or turn on Debug Rules.
---

# Set a firewall's main settings

You can set the main settings of a [firewall](/en/documentation/platform/firewall/) from Azion Console, the Azion CLI, or the API. The main settings are the firewall's name, the Products enabled on it, Debug Rules, and its status. The rules the firewall runs belong to its **Rules Engine** tab instead. To add one, refer to [Create a firewall rule](/en/documentation/guides/application-security/firewall-and-waf/work-with-rules-engine/).

A firewall carries no domains. A workload uses a firewall through the workload's deployment, so you set that binding on the workload. In Azion Console, it is the **Firewall** field of the workload's **Deployment Settings**. For the full procedure, refer to [Bind a firewall to a workload](/en/documentation/guides/application-security/firewall-and-waf/firewall-protect-your-domain/).

---

Select your interface. The prerequisites, and the steps that change the Products and confirm the settings, follow your selection.

## Prerequisites

- A firewall. To create one and bind it to a workload, refer to [Firewall quickstart](/en/documentation/platform/firewall/quickstart/).
- A subscription for each Product that requires one. For more information, refer to [Pricing](/en/documentation/fundamentals/pricing/).

**Console**

- A signed-in session in Azion Console. For more information, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**CLI**

- The [Azion CLI](/en/documentation/devtools/cli/), authorized with your account. The commands on this page use the flags of Azion CLI 4.23.0.
- The firewall's ID, which appears in the address of its page in Azion Console, after `/firewalls/edit/`.

**API**

- A personal token. The `Authorization` header carries it as `Token [TOKEN VALUE]`. To create one, refer to [Manage a personal token](/en/documentation/guides/platform/account-and-billing/personal-tokens/).
- `curl` or any other HTTP client.
- The firewall's ID, which appears in the address of its page in Azion Console, after `/firewalls/edit/`.

---

## Change the Products enabled on a firewall

Each Product adds criteria or behaviors to the firewall's [Rules Engine](/en/documentation/platform/firewall/rules-engine/). A rule cannot use them while the Product is off. The **Modules** section of the main settings holds a switch for each Product in this table, and you can turn on any combination of WAF, Network Shield, and Functions:

| Product                                                                                 | What it adds to the firewall                                                                                                                                                                      | In a new firewall |
| --------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------- |
| [Web Application Firewall (WAF)](/en/documentation/platform/firewall/how-it-works/#waf) | The *Set WAF* behavior, which applies a WAF rule set to the request. It also adds the seven *Header* criteria, such as *Header User Agent*, and the *Request Args* and *Request Method* criteria. | Off               |
| [Network Shield](/en/documentation/platform/firewall/how-it-works/#network-shield)      | The *Network* criterion, which matches a request against a [network list](/en/documentation/platform/firewall/network-shield/network-lists/) of IP addresses or CIDR ranges, ASNs, or countries.  | On                |
| [Functions](/en/documentation/platform/firewall/functions/)                             | The *Run Function* behavior, and the **Functions Instances** tab, where you add a function instance to the firewall.                                                                              | On                |
| [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection)                | Mitigation of distributed denial-of-service (DDoS) attacks. Its switch, **DDoS Protection Unmetered**, cannot be turned off.                                                                      | Always on         |

A WAF rule set scores each request for attacks such as SQL injection, remote file inclusion (RFI), and cross-site scripting (XSS). For every threat family it scores, refer to [Rule sets](/en/documentation/platform/firewall/waf/rules-set/#threat-families).

Functions starts on through the API, the Azion CLI, and the **Create Firewall** page. A firewall created from a drawer in Azion Console starts with Functions off. Confirm that **Functions** is on before you add a function instance.

Bot Manager has no switch of its own. [Bot Manager](/en/documentation/platform/firewall/how-it-works/#bot-manager) runs as a function instance that a *Run Function* rule invokes, so it needs Functions on the firewall. To set it up, refer to [Bot Manager quickstart](/en/documentation/platform/firewall/bot-manager/quickstart/).

**Console**

To enable a Product in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Main Settings tab**

3. **Turn on the Product**

   In the **Modules** section, turn on the switch of each Product you need: **Web Application Firewall**, **Network Shield**, or **Functions**.

4. **Save the settings**

   Select **Save**.

Azion Console shows `Your Firewall has been updated`. To disable a Product, turn its switch off in the same section and select **Save**.

**CLI**

To enable a Product with the Azion CLI, run `azion update firewall` with the Product's flag set to `true`. This command turns on Network Shield, with the ID of your firewall in place of `<firewall-id>`:

```bash
azion update firewall --firewall-id <firewall-id> --network-protection true
```

The command prints the ID of the firewall it updated:

```text
Updated Firewall with ID <firewall-id>
```

The flag for WAF is `--waf-enabled`, and the flag for Functions is `--functions-enabled`. Set a flag to `false` to disable its Product.

While a rule of the firewall uses the `${network}` criterion, the CLI refuses to turn Network Shield off:

```bash
azion update firewall --firewall-id <firewall-id> --network-protection false
```

The error lists the IDs of the rules that use the criterion:

```text
Error: Failed to update the Firewall: ["Cannot disable firewall network protection module, because it is being referenced by the following rules: <rule-id>, <rule-id>, <rule-id>."]. Check your settings and try again. If the error persists, contact Azion support
```

**API**

To enable a Product with the API, send a `PATCH` request to the firewall. The body sets the Product's `enabled` key inside `modules`. This request turns on Network Shield:

```bash
curl --request PATCH \
  --url https://api.azion.com/v4/workspace/firewalls/<firewall-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{"modules":{"network_protection":{"enabled":true}}}'
```

The API answers `202` and returns the firewall with Network Shield on:

```text
{"state":"pending","data":{"id":<firewall-id>,…,"modules":{…,"network_protection":{"enabled":true},…}}}
```

The key for WAF is `modules.waf.enabled`, and the key for Functions is `modules.functions.enabled`. `modules.ddos_protection` is read-only. Set `"enabled": false` to disable a Product. The [Azion API reference](https://api.azion.com/) documents every key of a firewall.

While a rule of the firewall uses the `${network}` criterion, a `PATCH` that sets `network_protection` to `"enabled": false` is refused with `400`:

```text
{"errors":[{"code":"24005","title":"Cannot Disable Firewall Network Protection Module","detail":"Cannot disable firewall network protection module, because it is being referenced by the following rules: <rule-id>, <rule-id>, <rule-id>.","status":"400","source":{"pointer":"/data/modules/network_protection/enabled"},"meta":{"referenced_in_rules":"<rule-id>, <rule-id>, <rule-id>"}}]}
```

Network Shield cannot be turned off while any rule of the firewall uses the `${network}` criterion. The refusal lists the ID of each of those rules.

Save the main settings before you create a rule that needs the Product. The **Rules Engine** tab reads the saved settings. While a Product is off, its options still appear in that tab, but they cannot be selected. Each one carries a suffix, such as *Set WAF - required WAF* or *Network - required Network Shield*. For the Product each criterion and behavior needs, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#criteria).

---

## Log the rules a firewall runs

With Debug Rules on, the firewall logs each Rules Engine rule that runs on a request. [Real-Time Events](/en/documentation/platform/real-time-events/) and [Data Stream](/en/documentation/platform/data-stream/) show those rules in the `$traceback` field. The Real-Time Events GraphQL API shows them in the `$stacktrace` variable. Debug Rules is off in a new firewall.

To turn on Debug Rules in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Main Settings tab**

3. **Turn on Debug Rules**

   In the **Debug Rules** section, turn on **Active**.

4. **Save the settings**

   Select **Save**.

Azion Console shows `Your Firewall has been updated`. A rule that is missing from the `$traceback` field of a request did not run on that request. To read the field, refer to [Debug rules created with Rules Engine](/en/documentation/guides/application-development/getting-started/debug-rules/).

---

## Rename a firewall

The name identifies the firewall in the **Firewalls** list, and it is the heading of the firewall's page. Every firewall needs one, so the **Name** field cannot be left empty.

To rename the firewall in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Main Settings tab**

3. **Enter the new name**

   In the **General** section, enter a unique, descriptive **Name**, such as `storefront-firewall`.

4. **Save the settings**

   Select **Save**.

Azion Console shows `Your Firewall has been updated`, and the new name appears in the **Name** column of the **Firewalls** list.

---

## Deactivate a firewall

The **Status** section of the main settings holds the firewall's **Active** switch. The switch is on in a new firewall.

To deactivate the firewall in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Main Settings tab**

3. **Turn off the firewall**

   In the **Status** section, turn off **Active**.

4. **Save the settings**

   Select **Save**.

Azion Console shows `Your Firewall has been updated`. To activate the firewall again, turn on **Active** in the **Status** section and select **Save**.

---

## Confirm the main settings of a firewall

A read of the firewall after a change returns the saved settings. Read them before you create a rule that needs a Product.

**Console**

To confirm the settings in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Main Settings tab**

   The tab holds four sections: **General**, **Modules**, **Debug Rules**, and **Status**.

Each switch in the **Modules** section is on for a Product that is enabled on the firewall.

**CLI**

To confirm the settings with the Azion CLI, describe the firewall in JSON, with its ID in place of `<firewall-id>`:

```bash
azion describe firewall --firewall-id <firewall-id> --format json
```

The output carries the `modules` object, with one `enabled` key per Product:

```json
{
 "modules": {
  "ddos_protection": { "enabled": true },
  "functions":       { "enabled": true },
  "network_protection": { "enabled": true },
  "waf":             { "enabled": false }
 },
 "product_version": "2.0"
}
```

In this firewall, every Product except WAF is on.

**API**

To confirm the settings with the API, send a `GET` request to the firewall:

```bash
curl --request GET \
  --url https://api.azion.com/v4/workspace/firewalls/<firewall-id> \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The API answers `200` and returns the firewall:

```text
{"data":{"id":<firewall-id>,"name":"<firewall-name>",
 "modules":{"ddos_protection":{"enabled":true},"functions":{"enabled":true},
            "network_protection":{"enabled":true},"waf":{"enabled":true}},
 "debug":false,"active":true,…}}
```

`modules` holds one `enabled` key per Product, `debug` holds Debug Rules, and `active` holds the status. In this firewall, every Product is on and Debug Rules is off.

Each main setting carries one name in each interface. The CLI flags apply to `azion create firewall` and `azion update firewall`, and every flag in this table except `--name` takes `true` or `false`:

| Setting         | Azion Console                                 | Azion CLI flag         | API key                                      |
| --------------- | --------------------------------------------- | ---------------------- | -------------------------------------------- |
| Name            | **Name**, in **General**                      | `--name`               | `name`                                       |
| Functions       | **Functions**, in **Modules**                 | `--functions-enabled`  | `modules.functions.enabled`                  |
| Network Shield  | **Network Shield**, in **Modules**            | `--network-protection` | `modules.network_protection.enabled`         |
| WAF             | **Web Application Firewall**, in **Modules**  | `--waf-enabled`        | `modules.waf.enabled`                        |
| DDoS Protection | **DDoS Protection Unmetered**, in **Modules** | None                   | `modules.ddos_protection.enabled`, read-only |
| Debug Rules     | **Active**, in **Debug Rules**                | `--debug-rules`        | `debug`                                      |
| Status          | **Active**, in **Status**                     | `--active`             | `active`                                     |

The saved settings reach traffic only after the change propagates. For more information on propagation, refer to [How Firewall works](/en/documentation/platform/firewall/how-it-works/#propagation).

---

## Next steps

- [Create a firewall rule](/en/documentation/guides/application-security/firewall-and-waf/work-with-rules-engine.md): Add a rule that uses the criteria and behaviors of the Products you turned on.
- [How Firewall works](/en/documentation/platform/firewall/how-it-works.md#products-enabled-on-a-firewall): What each Product enabled on a firewall adds to the way it handles a request.
- [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set.md): Create a rule set and hand requests to it with a Set WAF rule, once WAF is on.
- [Instantiate a function on a firewall](/en/documentation/guides/application-security/firewall-and-waf/instantiate-functions.md): Add the function instance that a Run Function rule runs, once Functions is on.
- [Block requests by IP, ASN, or country](/en/documentation/guides/application-security/bots-and-network/blocklists-ip-addresses-edge.md): Match requests against a network list with the Network criterion of Network Shield.
- [Debug rules created with Rules Engine](/en/documentation/guides/application-development/getting-started/debug-rules.md): Read the rules each request ran after you turn on Debug Rules.
