---
name: azion-switch-a-rule-set-to-blocking
description: >-
  Change the mode on the behavior that applies a rule set, so a scored request is refused rather than recorded and served.
---

# Switch a rule set to blocking

You can switch the rule that applies a rule set from `logging` to `blocking` from the API or Azion Console. The mode belongs to the `Set WAF` behavior, not to the rule set, so the same rule set can run in `logging` on one rule and in `blocking` on another.

---

## Prerequisites

- A rule that applies the rule set in `logging`. To create it, refer to [Apply a rule set to every request](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set/).
- A personal token, for the API request.

---

## Set the mode to blocking

A `PUT` to `/v4/workspace/firewalls/<firewall-id>/request_rules/<rule-id>` replaces the rule, so the body carries the criteria too. Send the rule again with `mode` set to `blocking`:

```json
{
  "name": "Apply storefront-waf",
  "active": true,
  "criteria": [
    [
      {
        "conditional": "if",
        "variable": "${request_uri}",
        "operator": "starts_with",
        "argument": "/"
      }
    ]
  ],
  "behaviors": [
    {
      "type": "set_waf",
      "attributes": {
        "waf_id": 12349,
        "mode": "blocking"
      }
    }
  ]
}
```

The rule now refuses a request whose score reaches a threshold with `400`, instead of recording it and serving it. A change takes several minutes to reach Azion's distributed infrastructure, and requests alternate between the old and new behavior while it arrives.

`mode` takes `logging` or `blocking` and nothing else. A body carrying `"mode": "learning"` is refused with `400` and the error `10039 Invalid Choice`, pointing at `/data/behaviors/0/attributes/mode`. A body with no `mode` at all is refused with `10059 Required Field` at the same pointer.

> **Note**
>
> To change the mode from Azion Console, open the firewall, select the **Rules Engine** tab and the rule, and set the mode on its **Set WAF** behavior to *Blocking*. The full procedure is in [Check or change the WAF mode](/en/documentation/guides/application-security/firewall-and-waf/how-to-check-your-waf-mode/).

---

## Next steps

- [Apply a rule set to every request](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set.md): The rule this change edits, and the criterion it has to keep.
- [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes.md): What each mode does to a request whose score reaches a threshold.
