Switch a rule set to blocking
Change the mode on the behavior that applies a rule set, so a scored request is refused rather than recorded and served.
You can switch the rule that applies a rule set from logging to blocking from the API or Azion Console. The mode belongs to the Set WAF behavior, not to the rule set, so the same rule set can run in logging on one rule and in blocking on another.
Prerequisites
- A rule that applies the rule set in
logging. To create it, refer to Apply a rule set to every request. - A personal token, for the API request.
Set the mode to blocking
A PUT to /v4/workspace/firewalls/<firewall-id>/request_rules/<rule-id> replaces the rule, so the body carries the criteria too. Send the rule again with mode set to blocking:
The rule now refuses a request whose score reaches a threshold with 400, instead of recording it and serving it. A change takes several minutes to reach Azion’s distributed infrastructure, and requests alternate between the old and new behavior while it arrives.
mode takes logging or blocking and nothing else. A body carrying "mode": "learning" is refused with 400 and the error 10039 Invalid Choice, pointing at /data/behaviors/0/attributes/mode. A body with no mode at all is refused with 10059 Required Field at the same pointer.