---
name: azion-check-or-change-the-waf-mode
description: >-
  The mode sits on the Set WAF behavior of a Rules Engine rule, not on the rule set. Read it there, and switch it there.
---

# Check or change the WAF mode

You can read the mode of a [Web Application Firewall (WAF)](/en/documentation/platform/firewall/#waf) rule set, and change it, from Azion Console or the API.

The mode is an attribute of the `Set WAF` behavior on a [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) rule. It is not a field of the rule set. One rule set can therefore run in one mode on one rule, and in another mode elsewhere. Applying a rule set for the first time belongs to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

---

Select the interface you will use. The prerequisites and both tasks below follow that choice.

## Prerequisites

- A firewall bound to the workload that serves your application. Refer to [Bind a firewall to a workload](/en/documentation/guides/application-security/firewall-and-waf/firewall-protect-your-domain/).
- A rule on that firewall carrying a `Set WAF` behavior. Refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

**Console**

- Access to Azion Console. To sign in, refer to [How to access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).

**API**

- A personal token and `curl`. To create a token, refer to [Personal Tokens](/en/documentation/fundamentals/personal-tokens/).
- The id of the firewall that carries the rule.

---

## Check the mode

A firewall holds several rules, and only the one carrying `Set WAF` decides the mode. Find that rule first.

**Console**

To read the mode in Azion Console:

1. **Open the firewall**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall that runs the rule set.

2. **Select the Rules Engine tab**

3. **Select the rule that applies the rule set**

   A rule that applies a rule set to every request reads `If` `Request Uri` `starts with` `/` under **Criteria**, and **Set WAF** under **Behaviors**.

4. **Read the mode**

   In the **Behaviors** section, the **Set WAF** behavior names the rule set. The mode dropdown beside it shows *Logging* or *Blocking*.

That value is the mode every request selected by this rule runs under. A rule carries at most one **Set WAF** behavior.

**API**

To read the mode over the API:

1. **List the rules of the firewall**

   Replace `<firewall-id>` with the id of your firewall, and `[TOKEN VALUE]` with your personal token:

   ```bash
   curl --request GET \
     --url https://api.azion.com/v4/workspace/firewalls/<firewall-id>/request_rules \
     --header 'Accept: application/json' \
     --header 'Authorization: Token [TOKEN VALUE]'
   ```

2. **Find the set\_waf behavior**

   The call answers `200`. The rule that applies a rule set reads back with this behavior:

   ```json
   "behaviors": [
     { "type": "set_waf", "attributes": { "waf_id": 12345, "mode": "blocking" } }
   ]
   ```

`mode` carries `logging` or `blocking`, the two values Azion Console renders as *Logging* and *Blocking*. Record the `id` of that rule. Changing the mode needs it.

---

## Change the mode

The mode has exactly two values, and `learning` is not one of them. For what each mode does to a request that reaches a threshold, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/#modes).

**Console**

To change the mode in Azion Console:

1. **Open the rule**

   Reach the rule through the steps in [Check the mode](#check-the-mode).

2. **Open the mode dropdown on the Set WAF behavior**

3. **Select Logging or Blocking**

4. **Select Save**

The rule now names the new mode. The change takes time to reach Azion's distributed infrastructure. A request that still behaves under the earlier mode has broken nothing: wait, then send it again.

**API**

Send the whole `set_waf` behavior, because `mode` is required inside it. A behavior that omits `mode` is refused with `400` and the error `10059 Required Field`, on the pointer `/data/behaviors/0/attributes/mode`.

1. **Send the change**

   Replace `<firewall-id>` and `<rule-id>` with the ids you recorded, and `waf_id` with the id of your rule set. Send the rule's complete `behaviors` array rather than the `set_waf` entry alone:

   ```bash
   curl --request PATCH \
     --url https://api.azion.com/v4/workspace/firewalls/<firewall-id>/request_rules/<rule-id> \
     --header 'Accept: application/json' \
     --header 'Authorization: Token [TOKEN VALUE]' \
     --header 'Content-Type: application/json' \
     --data '{
     "behaviors": [
       {
         "type": "set_waf",
         "attributes": {
           "waf_id": 12345,
           "mode": "logging"
         }
       }
     ]
   }'
   ```

2. **Read the mode back**

   Run the `GET` from [Check the mode](#check-the-mode) again, and confirm that `mode` carries the value you sent.

Any other value is refused. Other Azion surfaces spell this mode `learning`, and a behavior carrying that value returns:

```json
{
  "errors": [
    {
      "code": "10039",
      "title": "Invalid Choice",
      "detail": "\"learning\" is not a valid choice.",
      "status": "400",
      "source": { "pointer": "/data/behaviors/0/attributes/mode" }
    }
  ]
}
```

---

## Next steps

- [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes.md): What each mode does to a request, and what a blocked request receives.
- [Tune a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/tune-waf.md): Read what a rule set matched in Logging and turn a false positive into an exception.
- [Find the WAF score of a blocked request](/en/documentation/guides/application-security/firewall-and-waf/how-to-find-waf-score.md): Find the score and the rule that fired on a request.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#waf): What to check when a rule set blocks nothing, or blocks the wrong traffic.
