Set a firewall's main settings
Enable WAF, Network Shield, or Functions on a firewall from Azion Console, the Azion CLI, or the API, and rename it or turn on Debug Rules.
You can set the main settings of a firewall from Azion Console, the Azion CLI, or the API. The main settings are the firewall’s name, the Products enabled on it, Debug Rules, and its status. The rules the firewall runs belong to its Rules Engine tab instead. To add one, refer to Create a firewall rule.
A firewall carries no domains. A workload uses a firewall through the workload’s deployment, so you set that binding on the workload. In Azion Console, it is the Firewall field of the workload’s Deployment Settings. For the full procedure, refer to Bind a firewall to a workload.
Select your interface. The prerequisites, and the steps that change the Products and confirm the settings, follow your selection.
Prerequisites
- A firewall. To create one and bind it to a workload, refer to Firewall quickstart.
- A subscription for each Product that requires one. For more information, refer to Pricing.
- A signed-in session in Azion Console. For more information, refer to Access Azion Console.
Change the Products enabled on a firewall
Each Product adds criteria or behaviors to the firewall’s Rules Engine. A rule cannot use them while the Product is off. The Modules section of the main settings holds a switch for each Product in this table, and you can turn on any combination of WAF, Network Shield, and Functions:
| Product | What it adds to the firewall | In a new firewall |
|---|---|---|
| Web Application Firewall (WAF) | The Set WAF behavior, which applies a WAF rule set to the request. It also adds the seven Header criteria, such as Header User Agent, and the Request Args and Request Method criteria. | Off |
| Network Shield | The Network criterion, which matches a request against a network list of IP addresses or CIDR ranges, ASNs, or countries. | On |
| Functions | The Run Function behavior, and the Functions Instances tab, where you add a function instance to the firewall. | On |
| DDoS Protection | Mitigation of distributed denial-of-service (DDoS) attacks. Its switch, DDoS Protection Unmetered, cannot be turned off. | Always on |
A WAF rule set scores each request for attacks such as SQL injection, remote file inclusion (RFI), and cross-site scripting (XSS). For every threat family it scores, refer to Rule sets.
Functions starts on through the API, the Azion CLI, and the Create Firewall page. A firewall created from a drawer in Azion Console starts with Functions off. Confirm that Functions is on before you add a function instance.
Bot Manager has no switch of its own. Bot Manager runs as a function instance that a Run Function rule invokes, so it needs Functions on the firewall. To set it up, refer to Bot Manager quickstart.
To enable a Product with the Azion CLI, run azion update firewall with the Product’s flag set to true. This command turns on Network Shield, with the ID of your firewall in place of <firewall-id>:
The command prints the ID of the firewall it updated:
The flag for WAF is --waf-enabled, and the flag for Functions is --functions-enabled. Set a flag to false to disable its Product.
While a rule of the firewall uses the ${network} criterion, the CLI refuses to turn Network Shield off:
The error lists the IDs of the rules that use the criterion:
Network Shield cannot be turned off while any rule of the firewall uses the ${network} criterion. The refusal lists the ID of each of those rules.
Save the main settings before you create a rule that needs the Product. The Rules Engine tab reads the saved settings. While a Product is off, its options still appear in that tab, but they cannot be selected. Each one carries a suffix, such as Set WAF - required WAF or Network - required Network Shield. For the Product each criterion and behavior needs, refer to Rules Engine for Firewall.
Log the rules a firewall runs
With Debug Rules on, the firewall logs each Rules Engine rule that runs on a request. Real-Time Events and Data Stream show those rules in the $traceback field. The Real-Time Events GraphQL API shows them in the $stacktrace variable. Debug Rules is off in a new firewall.
To turn on Debug Rules in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Debug Rules section, turn on Active.
Select Save.
Azion Console shows Your Firewall has been updated. A rule that is missing from the $traceback field of a request did not run on that request. To read the field, refer to Debug rules created with Rules Engine.
Rename a firewall
The name identifies the firewall in the Firewalls list, and it is the heading of the firewall’s page. Every firewall needs one, so the Name field cannot be left empty.
To rename the firewall in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the General section, enter a unique, descriptive Name, such as storefront-firewall.
Select Save.
Azion Console shows Your Firewall has been updated, and the new name appears in the Name column of the Firewalls list.
Deactivate a firewall
The Status section of the main settings holds the firewall’s Active switch. The switch is on in a new firewall.
To deactivate the firewall in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Status section, turn off Active.
Select Save.
Azion Console shows Your Firewall has been updated. To activate the firewall again, turn on Active in the Status section and select Save.
Confirm the main settings of a firewall
A read of the firewall after a change returns the saved settings. Read them before you create a rule that needs a Product.
To confirm the settings with the Azion CLI, describe the firewall in JSON, with its ID in place of <firewall-id>:
The output carries the modules object, with one enabled key per Product:
In this firewall, every Product except WAF is on.
Each main setting carries one name in each interface. The CLI flags apply to azion create firewall and azion update firewall, and every flag in this table except --name takes true or false:
| Setting | Azion Console | Azion CLI flag | API key |
|---|---|---|---|
| Name | Name, in General | --name | name |
| Functions | Functions, in Modules | --functions-enabled | modules.functions.enabled |
| Network Shield | Network Shield, in Modules | --network-protection | modules.network_protection.enabled |
| WAF | Web Application Firewall, in Modules | --waf-enabled | modules.waf.enabled |
| DDoS Protection | DDoS Protection Unmetered, in Modules | None | modules.ddos_protection.enabled, read-only |
| Debug Rules | Active, in Debug Rules | --debug-rules | debug |
| Status | Active, in Status | --active | active |
The saved settings reach traffic only after the change propagates. For more information on propagation, refer to How Firewall works.