Check or change the WAF mode
The mode sits on the Set WAF behavior of a Rules Engine rule, not on the rule set. Read it there, and switch it there.
You can read the mode of a Web Application Firewall (WAF) rule set, and change it, from Azion Console or the API.
The mode is an attribute of the Set WAF behavior on a Rules Engine for Firewall rule. It is not a field of the rule set. One rule set can therefore run in one mode on one rule, and in another mode elsewhere. Applying a rule set for the first time belongs to Create and apply a WAF rule set.
Select the interface you will use. The prerequisites and both tasks below follow that choice.
Prerequisites
- A firewall bound to the workload that serves your application. Refer to Bind a firewall to a workload.
- A rule on that firewall carrying a
Set WAFbehavior. Refer to Create and apply a WAF rule set.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Check the mode
A firewall holds several rules, and only the one carrying Set WAF decides the mode. Find that rule first.
To read the mode in Azion Console:
Access Azion Console > Firewalls, then select the firewall that runs the rule set.
A rule that applies a rule set to every request reads If Request Uri starts with / under Criteria, and Set WAF under Behaviors.
In the Behaviors section, the Set WAF behavior names the rule set. The mode dropdown beside it shows Logging or Blocking.
That value is the mode every request selected by this rule runs under. A rule carries at most one Set WAF behavior.
Change the mode
The mode has exactly two values, and learning is not one of them. For what each mode does to a request that reaches a threshold, refer to Scoring and modes.
To change the mode in Azion Console:
Reach the rule through the steps in Check the mode.
The rule now names the new mode. The change takes time to reach Azion’s distributed infrastructure. A request that still behaves under the earlier mode has broken nothing: wait, then send it again.