Create a firewall rule
Add a rule to the Rules Engine of a firewall from Azion Console, the Azion CLI, or the API, and confirm that it denies a request.
You can create a firewall rule in Rules Engine from Azion Console, the Azion CLI, or the API. The first rule on this page denies one test path, so a single request confirms that the firewall applies it. The second, created in Azion Console, refuses a client that presents no certificate.
An application carries a Rules Engine of its own. A rule that adds a request header for your origin belongs to Rules Engine for Applications.
Select the interface you work in. The prerequisites and the steps that create the first rule switch with your selection.
Prerequisites
- A firewall bound to your workload. To create one and bind it, refer to Firewall quickstart.
- For the client-certificate rule, mutual TLS (mTLS) turned on for that workload. For more information, refer to Support for mTLS for Secure.
- Access to Azion Console. To sign in, refer to Access Azion Console.
Deny requests to one path
The rule in this section matches requests whose path starts with /deny-test and refuses them with 403. Requests to every other path still reach your application. The criterion also matches longer paths that begin with the same characters, such as /deny-test-old.
Neither the Request Uri criterion nor the Deny (403 Forbidden) behavior needs a Product on the firewall. Other criteria and behaviors need Web Application Firewall (WAF), Network Shield, or Functions enabled on the firewall. For the full list, refer to Rules Engine for Firewall.
To create the rule with the Azion CLI, save its definition as rule.json. The file carries the rule’s name, whether it is active, its criteria, and its behaviors:
criteria is a list of groups, and each group is a list of conditions. The first condition takes "conditional": "if", and each later one takes and or or.
Then create the rule on your firewall, with its ID in place of <firewall-id>:
The command prints the ID of the new rule:
The rule is active on the firewall, because the file sets "active": true. azion create firewall-rule accepts only --firewall-id and --file. The file holds the same body that the API accepts.
The firewall processes its rules in list order, and a deny behavior ends that processing for the request it refuses. For more information, refer to How Firewall works.
Confirm that the rule denies the path
A new rule takes effect 6 min 29 s to 9 min 18 s after you create it. Until then, /deny-test answers as it did before. While the change spreads, requests can receive the old answer and the new one in turn. A workload newly bound to a firewall can take several minutes to enforce its first rule, and no duration is guaranteed.
To confirm the rule, send a request to the test path, with your workload’s domain in place of <your-domain>:
The firewall refuses the request with 403:
The body is Azion’s default error page. It reads Forbidden and shows the same request ID as the x-azion-request-id header. A request to any other path still reaches your application.
If /deny-test still answers after 9 min 18 s, refer to Troubleshoot Firewall. For more information on propagation, refer to How Firewall works.
Require a client certificate
The rule in this section matches a request whose client presents no certificate and answers it with 401 and a JSON body. Use it to enforce an mTLS policy, such as one that BACEN compliance requires. The Ssl Verification Status criterion and the Set Custom Response behavior need no Product on the firewall.
To create the rule in Azion Console:
Access Azion Console > Firewalls, then select the firewall.
Select Rule.
In the General section, enter a Name, such as require-client-certificate.
In the Criteria section, select Ssl Verification Status as the variable and is equal as the operator. In Select an SSL Status, select Missing Client Certificate.
In the Behaviors section, select Set Custom Response as the behavior.
In Status code, enter 401.
In Content Type, enter the MIME type of the response body, such as application/json.
In Content Body, enter the message the client receives, such as {}.
Select Save.
Azion Console shows Rule successfully created. Once the rule takes effect, a request without a client certificate receives 401 and the body you entered.
For every option of this criterion and this behavior, refer to Rules Engine for Firewall.
To forward the client certificate’s Common Name (CN) to your origin instead, use Rules Engine for Applications. There, a behavior that adds a request header, such as client_cn, sends the ${ssl_client_s_dn_parsed} variable. For the complete setup, refer to Pass client certificate details to the origin.