Move deprecated rule sets to a firewall
Rebuild each setting of a deprecated Firewall rule set as a firewall rule in Azion Console, then remove the rule set from your applications.
You can move each setting of a deprecated Firewall rule set to a firewall from Azion Console. A rule in Rules Engine for Firewall replaces each setting. To add a rule that no deprecated rule set carried, refer to Create a firewall rule.
A deprecated rule set was turned on in the main settings of an application. A behavior in that application’s Rules Engine applied it. Azion Console marks a deprecated rule set with a banner that asks you to upgrade it. A firewall carries DDoS Protection, Network Shield, Web Application Firewall (WAF), and Functions itself. One firewall can protect several workloads.
Each section of this page rebuilds one setting as a firewall rule. Geo-blocking and IP blocking also need a network list, and a secure token needs a function instance. Once the firewall applies its rules, you remove the deprecated rule sets from your applications.
Prerequisites
- Access to Azion Console. To sign in, refer to Access Azion Console.
- A firewall bound to the workload that serves the application with the deprecated rule set. To create a firewall and bind it, refer to Firewall quickstart. To bind a firewall you already have, open the workload in Workloads. In Deployment Settings, select the firewall in Firewall, then select Save.
- The values of the deprecated rule set: its accepted referrer domains, blocked countries, blocked IP addresses, token secret, rate limit, and WAF rule sets.
- For a secure token, the Secure Token function in your account, installed from Marketplace.
- For a WAF rule set, the rule set to apply. To create one, refer to Create and apply a WAF rule set.
Move a referrer block
A referrer block denies a request whose Referer header matches none of the domains the deprecated rule set accepts. On a firewall, one rule pairs a Header Referer condition per accepted domain with the Deny (403 Forbidden) behavior. The Header Referer variable needs WAF on the firewall. While WAF is off, the variable shows as Header Referer - required WAF and cannot be selected.
To move the referrer block in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Main Settings tab, turn on Web Application Firewall.
Select Save. Azion Console shows Your Firewall has been updated.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name, such as referrer-block. A Description is optional.
In the Criteria section, select Header Referer as the variable and does not match as the operator. Enter one accepted domain as the argument, such as example.com.
For each remaining accepted domain, select And. Then set Header Referer, does not match, and that domain.
In the Behaviors section, select Deny (403 Forbidden).
Select Save.
Azion Console shows Rule successfully created. The rule appears in the Rules Engine tab with Active in the Status column.
Azion Console allows at most 10 conditions in a criteria group and five groups in a rule. For more accepted domains, select Add Criteria to start another group, which Azion Console joins to the first with And. For how does not match compares the header, refer to Rules Engine for Firewall.
Move geo-blocking
Geo-blocking moves to a network list of type Countries and a rule that denies requests by that list. The rule’s Network variable needs Network Shield on the firewall. A firewall starts with Network Shield on. While it is off, the variable shows as Network - required Network Shield and cannot be selected.
To create the network list in Azion Console:
Access Azion Console > Network Lists.
Select Network List. The Create Network List page opens.
In the General section, enter a Name, such as geo-block.
In the Network List Settings section, select Countries. The form opens with ASN selected.
In Countries, select each country that the deprecated rule set listed.
Select Save.
Azion Console shows Your network list has been created. The type of a list cannot change after you create it. To reuse a Countries list you already have, open it from Network Lists, add the countries, and select Save.
To create the rule that denies requests by the list:
Access Azion Console > Firewalls, then select the firewall.
In the Main Settings tab, confirm that Network Shield is on. If it is off, turn it on and select Save.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name, such as geo-block. A Description is optional.
In the Criteria section, select Network as the variable. Select matches for a blocklist, or does not match for an allowlist.
In Select a Network, select the list, such as geo-block.
In the Behaviors section, select Deny (403 Forbidden).
Select Save.
Azion Console shows Rule successfully created. A blocklist rule denies requests from the countries in the list. An allowlist rule denies requests from every other country.
Move a secure token
A secure token moves to an instance of the Secure Token function. A firewall rule runs the instance with the Run Function behavior. The arguments of the instance carry the secret that composes the token hash. The Function field offers only the firewall functions in your account, so install the Secure Token function from Marketplace first.
To create the function instance in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Main Settings tab, confirm that Functions is on. If it is off, turn it on and select Save.
The tab appears only while Functions is on.
Select Function.
In the General section, enter a Name, such as secure-token.
In Function, select the Secure Token function.
In Arguments, enter the arguments the Secure Token function expects, with the secret of the deprecated rule set. For those arguments, refer to Install the Secure Token integration.
Select Save.
The instance appears in the Functions Instances tab, with the Secure Token function in the Function column. For how an instance passes its arguments to the function, refer to Function instances for Firewall.
To create the rule that runs the instance:
On the same firewall, select the Rules Engine tab.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name, such as secure-token. A Description is optional.
In the Criteria section, select Host as the variable and is equal as the operator. Enter the domain that serves the protected content, such as <your-domain>.
Select And. Then select Request Uri and starts with, and enter the protected path, such as /classes.
In the Behaviors section, select Run Function.
In Select a Function, select the instance, such as secure-token. The list holds the active instances of this firewall.
Select Save.
Azion Console shows Rule successfully created. The rule runs the Secure Token instance on each request to that domain whose path starts with the protected path. For every option of the behavior, refer to Rules Engine for Firewall.
Move IP blocking
IP blocking moves to a network list of type IP/CIDR and a rule that denies requests by that list. The rule’s Network variable needs Network Shield on the firewall. A firewall starts with Network Shield on. While it is off, the variable shows as Network - required Network Shield and cannot be selected.
To create the network list in Azion Console:
Access Azion Console > Network Lists.
Select Network List. The Create Network List page opens.
In the General section, enter a Name, such as ip-block.
In the Network List Settings section, select IP/CIDR. The form opens with ASN selected.
In List, paste the blocked IP addresses of the deprecated rule set, one IP address or CIDR per line.
Select Save.
Azion Console shows Your network list has been created. The list keeps one copy of each entry you paste twice. To reuse an IP/CIDR list you already have, open it from Network Lists, add the addresses, and select Save.
To create the rule that denies requests by the list:
Access Azion Console > Firewalls, then select the firewall.
In the Main Settings tab, confirm that Network Shield is on. If it is off, turn it on and select Save.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name, such as ip-block. A Description is optional.
In the Criteria section, select Network as the variable. Select matches for a blocklist, or does not match for an allowlist.
In Select a Network, select the list, such as ip-block.
In the Behaviors section, select Deny (403 Forbidden).
Select Save.
Azion Console shows Rule successfully created. A blocklist rule denies requests from the addresses in the list. An allowlist rule denies requests from every other address.
Move rate limiting
Rate limiting moves to a rule with the Set Rate Limit behavior. The behavior needs no Product on the firewall, so the main settings of the firewall stay as they are.
To move the rate limit in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
Select Rule. The Create Rule drawer opens.
In the General section, enter a Name, such as rate-limit. A Description is optional.
In the Criteria section, the condition opens with Request Uri and starts with. Enter / to limit every request.
In the Behaviors section, select Set Rate Limit.
In Rate Limit Type, select Req/s or Req/min.
In Average Rate Limit, enter the average rate of the deprecated rule set. The value is at least 1.
In Limit By, select Client IP address or Global, as the deprecated rule set did.
With Req/s, enter the burst size of the deprecated rule set in Maximum Burst Size. The value is at least 1.
Select Save.
Azion Console shows Rule successfully created. Maximum Burst Size appears only with Req/s. For every field of the behavior, refer to Rules Engine for Firewall.
Once the rule takes effect, requests that arrive at the same time beyond the burst receive 429. Requests sent one after another are held for about one second and then served. For more information, refer to How Firewall works.
Move a WAF rule set
A WAF rule set that an application applied moves to a firewall rule with the Set WAF behavior. A rule holds one Set WAF behavior, so each WAF rule set you move needs a rule of its own. Set WAF needs WAF on the firewall. While WAF is off, the behavior shows as Set WAF - required WAF and cannot be selected.
To move a WAF rule set in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
In the Main Settings tab, turn on Web Application Firewall.
Select Save. Azion Console shows Your Firewall has been updated.
Select Rule. To add the rule set to a rule you already have, select that rule instead.
In the General section, enter a Name, such as waf-rule-set. A Description is optional.
In the Criteria section, the condition opens with Request Uri and starts with. Enter / to inspect every request.
In the Behaviors section, select Set WAF.
In Select a WAF, select the WAF rule set.
In Select a WAF mode, select Logging or Blocking.
Select Save.
Azion Console shows Rule successfully created. For what each mode does, refer to Scoring and modes. For every option of the behavior, refer to Rules Engine for Firewall.
Remove the deprecated rule sets from your applications
Remove a deprecated rule set from an application only after the firewall applies the rules that replace it. Removing it sooner leaves the requests it covered without either protection.
A rule added to a firewall already in traffic takes effect 6 min 29 s to 9 min 18 s after you save it. A workload newly bound to a firewall can take several minutes to apply its first rule, and no duration is guaranteed. A change to a network list in use takes effect 46 s to about 100 s after you save it. While a change spreads, requests can receive the old answer and the new one in turn.
To confirm that the firewall applies a rule, send a request that the rule matches. Send it again until it answers as the rule says. A request that a Deny (403 Forbidden) rule matches receives 403 and Azion’s default error page. For a network list rule, the Your IP row of that page shows the address the firewall matched against the list.
To remove a deprecated rule set from an application in Azion Console:
In Azion Console, open each application that used a deprecated rule set.
Select each rule whose behavior applies a deprecated Firewall rule set or a WAF rule set.
Delete that behavior from the rule. To remove the whole rule instead, delete it from the list of rules and confirm.
Select Save.
The application stops applying the deprecated rule set, and the firewall’s rules protect the workload. For more information on the Rules Engine of an application, refer to Rules Engine for Applications.