---
name: azion-move-deprecated-rule-sets-to-a-firewall
description: >-
  Rebuild each setting of a deprecated Firewall rule set as a firewall rule in Azion Console, then remove the rule set from your applications.
---

# Move deprecated rule sets to a firewall

You can move each setting of a deprecated Firewall rule set to a [firewall](/en/documentation/platform/firewall/) from Azion Console. A rule in [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/) replaces each setting. To add a rule that no deprecated rule set carried, refer to [Create a firewall rule](/en/documentation/guides/application-security/firewall-and-waf/work-with-rules-engine/).

A deprecated rule set was turned on in the main settings of an application. A behavior in that application's Rules Engine applied it. Azion Console marks a deprecated rule set with a banner that asks you to upgrade it. A firewall carries [DDoS Protection](/en/documentation/platform/workloads/#ddos-protection), [Network Shield](/en/documentation/platform/firewall/how-it-works/#network-shield), [Web Application Firewall (WAF)](/en/documentation/platform/firewall/how-it-works/#waf), and [Functions](/en/documentation/platform/firewall/functions/) itself. One firewall can protect several workloads.

Each section of this page rebuilds one setting as a firewall rule. Geo-blocking and IP blocking also need a [network list](/en/documentation/platform/firewall/network-shield/network-lists/), and a secure token needs a function instance. Once the firewall applies its rules, you remove the deprecated rule sets from your applications.

---

## Prerequisites

- Access to Azion Console. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- A firewall bound to the workload that serves the application with the deprecated rule set. To create a firewall and bind it, refer to [Firewall quickstart](/en/documentation/platform/firewall/quickstart/). To bind a firewall you already have, open the workload in **Workloads**. In **Deployment Settings**, select the firewall in **Firewall**, then select **Save**.
- The values of the deprecated rule set: its accepted referrer domains, blocked countries, blocked IP addresses, token secret, rate limit, and WAF rule sets.
- For a secure token, the Secure Token function in your account, installed from Marketplace.
- For a WAF rule set, the rule set to apply. To create one, refer to [Create and apply a WAF rule set](/en/documentation/guides/application-security/firewall-and-waf/create-waf-rule-set/).

---

## Move a referrer block

A referrer block denies a request whose `Referer` header matches none of the domains the deprecated rule set accepts. On a firewall, one rule pairs a *Header Referer* condition per accepted domain with the *Deny (403 Forbidden)* behavior. The *Header Referer* variable needs WAF on the firewall. While WAF is off, the variable shows as *Header Referer - required WAF* and cannot be selected.

To move the referrer block in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Turn on WAF**

   In the **Main Settings** tab, turn on **Web Application Firewall**.

3. **Save the main settings**

   Select **Save**. Azion Console shows `Your Firewall has been updated`.

4. **Select the Rules Engine tab**

5. **Start a new rule**

   Select **Rule**. The **Create Rule** drawer opens.

6. **Name the rule**

   In the **General** section, enter a **Name**, such as `referrer-block`. A **Description** is optional.

7. **Set the first accepted domain**

   In the **Criteria** section, select *Header Referer* as the variable and *does not match* as the operator. Enter one accepted domain as the argument, such as `example.com`.

8. **Add the other accepted domains**

   For each remaining accepted domain, select **And**. Then set *Header Referer*, *does not match*, and that domain.

9. **Add the behavior**

   In the **Behaviors** section, select *Deny (403 Forbidden)*.

10. **Save the rule**

    Select **Save**.

Azion Console shows `Rule successfully created`. The rule appears in the **Rules Engine** tab with *Active* in the **Status** column.

Azion Console allows at most 10 conditions in a criteria group and five groups in a rule. For more accepted domains, select **Add Criteria** to start another group, which Azion Console joins to the first with *And*. For how *does not match* compares the header, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#operators).

---

## Move geo-blocking

Geo-blocking moves to a network list of type *Countries* and a rule that denies requests by that list. The rule's *Network* variable needs Network Shield on the firewall. A firewall starts with Network Shield on. While it is off, the variable shows as *Network - required Network Shield* and cannot be selected.

To create the network list in Azion Console:

1. **Open the Network Lists page**

   Access [Azion Console](https://console.azion.com/) > **Network Lists**.

2. **Start a new network list**

   Select **Network List**. The **Create Network List** page opens.

3. **Name the list**

   In the **General** section, enter a **Name**, such as `geo-block`.

4. **Select the Countries type**

   In the **Network List Settings** section, select *Countries*. The form opens with *ASN* selected.

5. **Add the countries**

   In **Countries**, select each country that the deprecated rule set listed.

6. **Save the list**

   Select **Save**.

Azion Console shows `Your network list has been created`. The type of a list cannot change after you create it. To reuse a *Countries* list you already have, open it from **Network Lists**, add the countries, and select **Save**.

To create the rule that denies requests by the list:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Confirm that Network Shield is on**

   In the **Main Settings** tab, confirm that **Network Shield** is on. If it is off, turn it on and select **Save**.

3. **Select the Rules Engine tab**

4. **Start a new rule**

   Select **Rule**. The **Create Rule** drawer opens.

5. **Name the rule**

   In the **General** section, enter a **Name**, such as `geo-block`. A **Description** is optional.

6. **Set the criterion**

   In the **Criteria** section, select *Network* as the variable. Select *matches* for a blocklist, or *does not match* for an allowlist.

7. **Select the list**

   In **Select a Network**, select the list, such as `geo-block`.

8. **Add the behavior**

   In the **Behaviors** section, select *Deny (403 Forbidden)*.

9. **Save the rule**

   Select **Save**.

Azion Console shows `Rule successfully created`. A blocklist rule denies requests from the countries in the list. An allowlist rule denies requests from every other country.

---

## Move a secure token

A secure token moves to an instance of the Secure Token function. A firewall rule runs the instance with the *Run Function* behavior. The arguments of the instance carry the secret that composes the token hash. The **Function** field offers only the firewall functions in your account, so install the Secure Token function from Marketplace first.

To create the function instance in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Confirm that Functions is on**

   In the **Main Settings** tab, confirm that **Functions** is on. If it is off, turn it on and select **Save**.

3. **Select the Functions Instances tab**

   The tab appears only while **Functions** is on.

4. **Start a new instance**

   Select **Function**.

5. **Name the instance**

   In the **General** section, enter a **Name**, such as `secure-token`.

6. **Select the function**

   In **Function**, select the Secure Token function.

7. **Enter the arguments**

   In **Arguments**, enter the arguments the Secure Token function expects, with the secret of the deprecated rule set. For those arguments, refer to [Install the Secure Token integration](/en/documentation/guides/application-development/integrations/secure-token/).

8. **Save the instance**

   Select **Save**.

The instance appears in the **Functions Instances** tab, with the Secure Token function in the **Function** column. For how an instance passes its arguments to the function, refer to [Function instances for Firewall](/en/documentation/platform/firewall/functions-instances/#arguments).

To create the rule that runs the instance:

1. **Select the Rules Engine tab**

   On the same firewall, select the **Rules Engine** tab.

2. **Start a new rule**

   Select **Rule**. The **Create Rule** drawer opens.

3. **Name the rule**

   In the **General** section, enter a **Name**, such as `secure-token`. A **Description** is optional.

4. **Set the domain**

   In the **Criteria** section, select *Host* as the variable and *is equal* as the operator. Enter the domain that serves the protected content, such as `<your-domain>`.

5. **Set the path**

   Select **And**. Then select *Request Uri* and *starts with*, and enter the protected path, such as `/classes`.

6. **Add the behavior**

   In the **Behaviors** section, select *Run Function*.

7. **Select the instance**

   In **Select a Function**, select the instance, such as `secure-token`. The list holds the active instances of this firewall.

8. **Save the rule**

   Select **Save**.

Azion Console shows `Rule successfully created`. The rule runs the Secure Token instance on each request to that domain whose path starts with the protected path. For every option of the behavior, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#run-function).

---

## Move IP blocking

IP blocking moves to a network list of type *IP/CIDR* and a rule that denies requests by that list. The rule's *Network* variable needs Network Shield on the firewall. A firewall starts with Network Shield on. While it is off, the variable shows as *Network - required Network Shield* and cannot be selected.

To create the network list in Azion Console:

1. **Open the Network Lists page**

   Access [Azion Console](https://console.azion.com/) > **Network Lists**.

2. **Start a new network list**

   Select **Network List**. The **Create Network List** page opens.

3. **Name the list**

   In the **General** section, enter a **Name**, such as `ip-block`.

4. **Select the IP/CIDR type**

   In the **Network List Settings** section, select *IP/CIDR*. The form opens with *ASN* selected.

5. **Add the addresses**

   In **List**, paste the blocked IP addresses of the deprecated rule set, one IP address or CIDR per line.

6. **Save the list**

   Select **Save**.

Azion Console shows `Your network list has been created`. The list keeps one copy of each entry you paste twice. To reuse an *IP/CIDR* list you already have, open it from **Network Lists**, add the addresses, and select **Save**.

To create the rule that denies requests by the list:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Confirm that Network Shield is on**

   In the **Main Settings** tab, confirm that **Network Shield** is on. If it is off, turn it on and select **Save**.

3. **Select the Rules Engine tab**

4. **Start a new rule**

   Select **Rule**. The **Create Rule** drawer opens.

5. **Name the rule**

   In the **General** section, enter a **Name**, such as `ip-block`. A **Description** is optional.

6. **Set the criterion**

   In the **Criteria** section, select *Network* as the variable. Select *matches* for a blocklist, or *does not match* for an allowlist.

7. **Select the list**

   In **Select a Network**, select the list, such as `ip-block`.

8. **Add the behavior**

   In the **Behaviors** section, select *Deny (403 Forbidden)*.

9. **Save the rule**

   Select **Save**.

Azion Console shows `Rule successfully created`. A blocklist rule denies requests from the addresses in the list. An allowlist rule denies requests from every other address.

---

## Move rate limiting

Rate limiting moves to a rule with the *Set Rate Limit* behavior. The behavior needs no Product on the firewall, so the main settings of the firewall stay as they are.

To move the rate limit in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Select the Rules Engine tab**

3. **Start a new rule**

   Select **Rule**. The **Create Rule** drawer opens.

4. **Name the rule**

   In the **General** section, enter a **Name**, such as `rate-limit`. A **Description** is optional.

5. **Set the criterion**

   In the **Criteria** section, the condition opens with *Request Uri* and *starts with*. Enter `/` to limit every request.

6. **Add the behavior**

   In the **Behaviors** section, select *Set Rate Limit*.

7. **Select the rate unit**

   In **Rate Limit Type**, select *Req/s* or *Req/min*.

8. **Enter the average rate**

   In **Average Rate Limit**, enter the average rate of the deprecated rule set. The value is at least `1`.

9. **Select what the limit counts**

   In **Limit By**, select *Client IP address* or *Global*, as the deprecated rule set did.

10. **Enter the burst size**

    With *Req/s*, enter the burst size of the deprecated rule set in **Maximum Burst Size**. The value is at least `1`.

11. **Save the rule**

    Select **Save**.

Azion Console shows `Rule successfully created`. **Maximum Burst Size** appears only with *Req/s*. For every field of the behavior, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#set-rate-limit).

Once the rule takes effect, requests that arrive at the same time beyond the burst receive `429`. Requests sent one after another are held for about one second and then served. For more information, refer to [How Firewall works](/en/documentation/platform/firewall/how-it-works/#rate-limits).

---

## Move a WAF rule set

A WAF rule set that an application applied moves to a firewall rule with the *Set WAF* behavior. A rule holds one *Set WAF* behavior, so each WAF rule set you move needs a rule of its own. *Set WAF* needs WAF on the firewall. While WAF is off, the behavior shows as *Set WAF - required WAF* and cannot be selected.

To move a WAF rule set in Azion Console:

1. **Open the firewall bound to your workload**

   Access [Azion Console](https://console.azion.com/) > **Firewalls**, then select the firewall.

2. **Turn on WAF**

   In the **Main Settings** tab, turn on **Web Application Firewall**.

3. **Save the main settings**

   Select **Save**. Azion Console shows `Your Firewall has been updated`.

4. **Select the Rules Engine tab**

5. **Start a new rule**

   Select **Rule**. To add the rule set to a rule you already have, select that rule instead.

6. **Name the rule**

   In the **General** section, enter a **Name**, such as `waf-rule-set`. A **Description** is optional.

7. **Set the criterion**

   In the **Criteria** section, the condition opens with *Request Uri* and *starts with*. Enter `/` to inspect every request.

8. **Add the behavior**

   In the **Behaviors** section, select *Set WAF*.

9. **Select the rule set**

   In **Select a WAF**, select the WAF rule set.

10. **Select the mode**

    In **Select a WAF mode**, select *Logging* or *Blocking*.

11. **Save the rule**

    Select **Save**.

Azion Console shows `Rule successfully created`. For what each mode does, refer to [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes/#modes). For every option of the behavior, refer to [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine/#set-waf).

---

## Remove the deprecated rule sets from your applications

Remove a deprecated rule set from an application only after the firewall applies the rules that replace it. Removing it sooner leaves the requests it covered without either protection.

A rule added to a firewall already in traffic takes effect 6 min 29 s to 9 min 18 s after you save it. A workload newly bound to a firewall can take several minutes to apply its first rule, and no duration is guaranteed. A change to a network list in use takes effect 46 s to about 100 s after you save it. While a change spreads, requests can receive the old answer and the new one in turn.

To confirm that the firewall applies a rule, send a request that the rule matches. Send it again until it answers as the rule says. A request that a *Deny (403 Forbidden)* rule matches receives `403` and Azion's default error page. For a network list rule, the `Your IP` row of that page shows the address the firewall matched against the list.

To remove a deprecated rule set from an application in Azion Console:

1. **Open the application**

   In Azion Console, open each application that used a deprecated rule set.

2. **Select the Rules Engine tab**

3. **Open each rule that applies a deprecated rule set**

   Select each rule whose behavior applies a deprecated Firewall rule set or a WAF rule set.

4. **Delete the behavior**

   Delete that behavior from the rule. To remove the whole rule instead, delete it from the list of rules and confirm.

5. **Save the rule**

   Select **Save**.

The application stops applying the deprecated rule set, and the firewall's rules protect the workload. For more information on the Rules Engine of an application, refer to [Rules Engine for Applications](/en/documentation/platform/applications/rules-engine/).

---

## Next steps

- [Rules Engine for Firewall](/en/documentation/platform/firewall/rules-engine.md): Every criterion, operator, and behavior a firewall rule accepts.
- [Deny requests from a list of countries](/en/documentation/guides/application-security/bots-and-network/deny-countries.md): Deny the countries a network list holds with a firewall rule.
- [Allow only the addresses in a list](/en/documentation/guides/application-security/bots-and-network/allowlist.md): Deny every client whose address is not in a network list.
- [Rate-limit the addresses in a list](/en/documentation/guides/application-security/bots-and-network/rate-limit-list.md): Apply a rate limit only to the clients a network list holds.
- [Apply a rule set to every request](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set.md): Hand every request to a WAF rule set with the Set WAF behavior.
- [Run a function on a firewall](/en/documentation/guides/application-development/functions-and-runtime/firewall.md): Run a firewall function from a rule, as the secure token rule does.
