Tune a WAF rule set
Read the requests a rule set matched in the Tuning tab, then turn the legitimate ones into exceptions.
You can read the requests a Web Application Firewall (WAF) rule set matched from the Tuning tab in Azion Console. Selected records become exceptions, so the rule set stops matching those requests and keeps scoring the rest.
Tuning runs in Azion Console only. Neither the Azion CLI nor the API carries a tuning path, so both the records and the bulk conversion are reachable from the Console alone.
Tuning is one turn of a loop that starts in Logging mode and ends in Blocking. For why the loop repeats, refer to Scoring and modes.
Workloads replaced Domains, and Tuning names whichever one your account carries. Select the control your Console shows.
Prerequisites
- Access to Azion Console. To sign in, refer to How to access Azion Console.
- A firewall with the WAF module turned on. Refer to Set a firewall’s main settings.
- A rule set applied to traffic by a
Set WAFbehavior. Refer to Create and apply a WAF rule set. - Traffic scored against that rule set within the last 3 days, which is the longest window Tuning reads.
Filter the Tuning records
A query runs over one time range and at least one workload or domain. Every other filter narrows it.
To read the records of a rule set applied to a workload:
Access Azion Console > Edge Libraries > WAF Rules.
The options run from Last 1 hour to Last 3 days, which is the longest window available.
This filter is required. The screen lists no records until a workload is selected.
The query then returns only the records whose source address a Network Lists entry holds.
Select Filter, then choose Country or IP Address. Select Apply to run the query with it.
The Console reports how many records were found. The results list carries one row per internal rule that matched, with the columns Rule ID, Hits, Paths, IPs, Countries, Top 10 IP Addresses, and Top 10 Countries.
For example, a query over Last 12 hours, two workloads, and the Blocklist IPs network list returns only the records those addresses produced.
For every filter and column this screen offers, refer to WAF Exceptions.
Create exceptions from the records
Allowing a record writes an exception for that rule ID. One selection produces several of them: the confirmation states that a separate rule is created for each possible attack on each URI.
To allow records read from a workload:
More Details opens, listing the occurrences behind that rule ID.
Use the checkbox in the Field column. Select as many records as you need.
The confirmation asks for that reason, or for any other information about the requests.
The Console reports how many allowed rules were created, and each one appears on the Allowed Rules tab. New requests to the selected workloads that match those rule IDs are allowed.
When only part of a selection is written, the Console reports a partial failure and the number created. Select the remaining records and allow them again.