Glossary
What firewall, rule, criterion, behavior, rule set, network list, score, threshold, and the other terms in the Firewall documentation mean.
Firewall and the Products that run on a firewall, Web Application Firewall (WAF), Network Shield, and Bot Manager, give the terms in this glossary a meaning of their own.
| Term | Definition |
|---|---|
| action | The name other rule engines give to what a rule does to a request it matches, which a firewall calls a behavior. A firewall rule written elsewhere as a condition and an action transfers with its condition as criteria and its action as behaviors. Rules Engine for Firewall documents the six behaviors. |
| Allowed Rules | The Azion Console name for WAF exceptions, and the tab on a rule set where you create and manage them. The API and the CLI call the same object an exception, and Exceptions documents it under both names. |
| allowlist | A network list that a rule uses to admit only the clients it holds. A rule with the Network criterion, the does not match operator (is_not_in_list), and the Deny (403 Forbidden) behavior (deny) blocks every client outside the list. Allowlist names a use, not a list type: Network Lists offers only the IP/CIDR, ASN, and Countries types. |
| arguments | The JSON object a function instance passes to its function, edited in the Arguments section of the instance form and sent as args through the API and the CLI. For Bot Manager it sets the threshold, the action, and the logging, and a key the function does not read is stored and ignored; Arguments documents every field. In a criterion, an argument is the value a variable is compared with. |
| ASN list | A network list of type asn, ASN in Azion Console, that matches a request by the Autonomous System Number (ASN) its client IP address belongs to. An ASN identifies a group of IP networks that one or more operators manage under one clear and unique routing policy. The API takes digits only, such as 64496, and the Console form also accepts an AS prefix; Network Lists compares the three types. |
az_asm | One of the two session cookies Bot Manager Lite sets on a 204 response with no body, alongside az_botm. Its value is a signed copy of the value in az_botm, and rule 17 scores a mismatch between the two. Bot Manager Lite lists the rules that read the pair. |
az_botm | The unsigned cookie of the session pair Bot Manager Lite sets, carrying the x-azion-request-id of the response that set it. Both cookies are scoped to the workload domain and expire after 24 hours, with Max-Age=86400. Logs documents what Bot Manager records about a request. |
| Azion IP Tor Exit Nodes | The Azion-maintained network list of Tor exit nodes, the final points where the Tor network connects to the internet. It is an ip_cidr list with ID 2, present in every account, which Azion keeps up to date and you can reference but not change. To block the clients it holds, refer to Block Tor exit nodes. |
| Azion-maintained list | A network list that Azion creates and keeps up to date, such as Azion IP Tor Exit Nodes. A rule references it like any other network list, but any write to it fails with 22004 Cannot Change Global Network List. Network Lists lists them, and accounts with Origin Shield also receive Azion Origin Shield, which holds the IPv4 and IPv6 prefixes Azion’s infrastructure uses. |
| behavior | The action a rule takes on a request its criteria match. A firewall offers six: Deny (403 Forbidden), Drop (Close Without Response), Set Rate Limit, and Set Custom Response need no Product, Set WAF needs WAF, and Run Function needs Functions. Only Set WAF and Run Function can be followed by another behavior in the same rule; Rules Engine for Firewall documents each one. |
| Blocking | The WAF mode that refuses a request whose score reaches a threat family’s threshold before it reaches your application, answering 400. It is one of the two modes the Set WAF behavior accepts, blocking in the API, and it is set on the rule rather than on the rule set. How Firewall works compares both modes. |
| blocklist | A network list that a rule uses to refuse the clients it holds. A rule with the Network criterion, the matches operator (is_in_list), and the Deny (403 Forbidden) behavior (deny) blocks every client in the list and lets the others through. To build one, refer to Block requests by IP, ASN, or country. |
| bot category | The category Bot Manager records for a request in the bot_category log field, with values such as Search Engine Bot, Bad Bot Signatures, and Credential Stuffing. Bot Manager writes the one category the request best fits, and Bot Manager Lite writes a comma-joined list of the classes of every rule the request matched. Logs lists every value. |
| Bot Manager | The Product that scores each request on the evidence it carries, such as its headers, its address, and its session, and applies an action when the score reaches a threshold. It is not a switch in Modules: it runs as a function instance on the firewall, invoked by a rule with the Run Function behavior. Firewall describes it, and Bot Manager Lite is its self-serve edition. |
| Bot Manager Lite | The self-serve edition of Bot Manager, installed from Azion Marketplace and run as a function instance on a firewall. It scores each request against 26 static rules and runs no dynamic score. Bot Manager Lite lists the rules, the arguments, and the report log. |
| classification | The verdict Bot Manager records for a request in the classified log field: legitimate, good bot, bad bot, or under evaluation. The verdict follows the threshold in force, so the same score reads legitimate under one threshold and bad bot under a lower one. Logs gives the conditions for each, and Real-Time Metrics charts the four together. |
| collision | Two distinct users or devices that share one fingerprint, so Bot Manager scores them as one identity. With the engine_version argument set to 2, Bot Manager derives the fingerprint with a JA4H method that produces fewer collisions than version 1. Arguments compares the two versions. |
| comment | A note written after # at the end of an item in an ip_cidr list, stored with the item and always last on the line, after any due date. A line that starts with # is not a disabled line: the API refuses it as an invalid item with 22005 Invalid IP CIDR. Lists of type asn and countries refuse comments, and Network Lists documents the full item syntax. |
| condition | In WAF, the part of a request an exception matches: a match zone and, for a specific zone, the name or value it applies to. The Azion Console field is Condition, and the API takes conditions as an array with at least one entry; Exceptions lists every option. In a firewall rule, the conditions are the rule’s criteria. |
| countries list | A network list of type countries, Countries in Azion Console, that matches a request by the country Azion resolves from its client IP address. The API takes two-letter uppercase ISO 3166-1 alpha-2 codes such as BR, and the Console form selects countries by name. A blocklist of this type blocks requests by country, the task known as geoblocking; Network Lists compares the three types. |
| criterion | One condition a rule tests: a variable such as ${request_uri}, a comparison operator, and an argument when the operator takes one. Some variables need a Product: ${network} needs Network Shield, and the seven header variables, ${request_args}, and ${request_method} need WAF. Rules Engine for Firewall lists every variable and how criteria combine with and and or. |
| Custom Allowed Rules | A retired name for WAF exceptions that appears in no Azion interface. The Azion Console tab reads Allowed Rules, and the API and the CLI call the object an exception. |
| DDoS Protection | The mitigation of distributed denial-of-service (DDoS) attacks that every firewall runs, shown in the Modules section as DDoS Protection Unmetered and tagged Automatically enabled in all accounts. Its switch cannot be turned off, and the API reports modules.ddos_protection.enabled as true. DDoS Protection documents it. |
| Debug Rules | The Main Settings section that logs the Rules Engine rules each request ran, debug in the API and off when you create a firewall. With its Active switch on, executed rules appear in the $traceback field in Data Stream and Real-Time Events, and in the $stacktrace variable in the GraphQL API. Debug rules created with Rules Engine shows how to read them. |
| does not match | The Azion Console label of the comparison operator that is true when a value does not match a regular expression, or, on the Network criterion, when the client IP address has no match in the network list, where it sends is_not_in_list. With the deny behavior on the Network criterion, it turns the list into an allowlist. Rules Engine for Firewall lists the operators each variable takes. |
| due date | The expiration date an item in an ip_cidr list can carry: --LT and a UTC date and time in YYYY-MM-DDTHH:MM:SSZ form, as in 192.0.2.2 --LT2030-01-01T00:00:00Z. Azion checks it only when you write the list’s items, so a past-dated item is dropped then, and an item whose date passes later keeps matching until you write the items again. The Console help calls it an expiration date, and Network Lists documents its syntax. |
| dynamic score | The part of a score Bot Manager derives from a fingerprint’s behavioral history, measured against the overall traffic pattern of the host. Bot Manager Lite runs static rules only, so its score carries no dynamic part. How Firewall works describes the model. |
| exception | An entry on a rule set that exempts part of a request from one internal WAF rule, or from all of them, so a false positive stops being blocked. Azion Console calls it an allowed rule, and the API and the CLI call it an exception. Exceptions documents the rule ID, conditions, and operator it carries. |
| false positive | A legitimate request that reaches a threat family’s threshold and is treated as an attack. Tuning is where you find one, and an exception clears it. A false negative is the reverse, an attack whose score stays under the threshold, and raising a sensitivity level trades one for the other. |
| fingerprint | The identifier Bot Manager derives for the client behind a request, from what the request and the device’s session carry, such as the IP address and the User-Agent header. It ties the later requests of one device together. Bot Manager reports it in the azion_fingerprint log field and Bot Manager Lite in fingerprint, as four underscore-separated segments; Logs documents both. |
| firewall | An instance of Firewall, the Platform Resource that inspects every request a workload receives before the application does, and runs its rules on it. A workload selects its firewall in the Firewall field of its Deployment Settings, strategy.attributes.firewall in the API, and a firewall carries no domains. Firewall documents the resource and the Products that run on it. |
| function instance | The object that attaches a function to a firewall together with the arguments it runs with, listed in Azion Console under the Functions Instances tab. The function must be created for the firewall execution environment, and a rule with the Run Function behavior invokes the instance, which is how Bot Manager runs. Function instances for Firewall documents the object. |
| global network list | The API’s name for an Azion-maintained list, found in the error 22004 Cannot Change Global Network List that answers any write to one. For the lists Azion maintains, refer to Network Lists. |
| IP/CIDR list | A network list of type ip_cidr, IP/CIDR in Azion Console, that holds IPv4 and IPv6 addresses and CIDR ranges such as 198.51.100.0/24. A rule matches a request when its client IP address falls inside one of the entries. It is the only type whose items accept a due date and a comment, and Network Lists compares the three types. |
| item | One entry in a network list: an IP address or CIDR range, an ASN, or a country code, according to the list type. Exact duplicates are removed silently, while equivalent notations such as 192.0.2.80 and 192.0.2.80/32 are both kept. Network Lists documents the format each type accepts. |
| log tag | The identifier an instance stamps on the report lines it writes, so you can tell one instance’s records from another’s in Real-Time Events. The log_tag argument sets it, as Arguments documents. Bot Manager Lite writes it in the line prefix, [Bot-Protection][<log_tag>], and Bot Manager writes it as a log_tag field. |
| Logging | The WAF mode that scores a request and records the match without blocking it, logging in the API and the other mode the Set WAF behavior accepts. The API refuses learning with 10039, but other surfaces keep that name: Real-Time Events reports the state in wafLearning, labeled WAF Learning, Data Stream in waf_learning, and azion.config.js takes wafMode set to learning. How Firewall works compares both modes. |
| Main Settings | The tab of a firewall that holds its settings in four sections: General, for its name, Modules, Debug Rules, and Status. It holds no domains, because a workload selects its firewall through its deployment. Set a firewall’s main settings covers each section. |
| match target | The name other platforms give to the requests a security policy applies to. A firewall sets it in two places: the workloads whose deployment names the firewall, and the criteria of each rule. A WAF rule set carries no domain or path and scores the requests a rule’s criteria hand it, as How Firewall works describes. |
| match zone | The part of a request a WAF condition inspects, such as a query string value, a header name, or the raw body, out of 15 in all. Azion Console selects one through the Condition field, not through a control named match zone, and the API takes it as conditions[].match. Exceptions lists all 15. |
| matches | The Azion Console label of the comparison operator that tests a value against a regular expression, or, on the Network criterion, the client IP address against a network list, where it sends is_in_list. With the deny behavior on the Network criterion, it is how a blocklist works. In the API, matches itself is refused on ${network} with 25039 Invalid Operator, and Rules Engine for Firewall lists the operators each variable takes. |
modules | The API object that carries the four switches of a firewall: ddos_protection, functions, network_protection, and waf, each with an enabled value. Azion Console renders it as the Modules section of Main Settings. Bot Manager has no key there because it runs as a function instance, and Firewall describes what each switch turns on. |
| Network criterion | The Rules Engine for Firewall criterion that compares the client IP address of a request with a network list: Network in Azion Console and ${network} in the API. It is the only criterion Network Shield adds, so while Network Shield is off, Azion Console shows Network - required Network Shield and the API answers 25047 Missing Required Modules. Its argument is the list ID as a JSON integer, and a string fails with 25042 Invalid Operator Argument Type. |
| network list | An object that holds items of one type, fixed when you create it: an IP/CIDR list, an ASN list, or a countries list. A rule references it by ID through the Network criterion, and one list can serve many rules and firewalls, so a change to its items changes what every one of them matches. Network Lists documents its fields. |
| Network Lists | The feature, and the Azion Console page of the same name, where you create and manage network lists, served in the API at /v4/workspace/network_lists. Network Lists holds the lists, and Network Shield is what lets a firewall rule match requests against them. For fields, types, and errors, refer to Network Lists. |
| Network Shield | The Product you turn on for a firewall so its rules can match requests against network lists through the Network criterion. It is on when you create a firewall, and while a rule uses ${network} it cannot be turned off: the API answers 24005 Cannot Disable Firewall Network Protection Module. Its switch is Network Shield in the Modules section of Main Settings; Firewall describes it, and Pricing carries its plan availability. |
network_protection | The API name of Network Shield on a firewall: modules.network_protection.enabled in a /v4/workspace/firewalls request body, true by default. The error 25047 names the same setting network_protection_enabled. Firewall describes the Product. |
| Operator | The WAF exception field that decides how the exception compares its strings: regex or contains, with contains as the default. It governs the exception’s path and its condition’s name or value together, and Azion Console has no separate regex switch. Exceptions documents it with the other fields. |
| phase | The stage of a request in which rules run. A firewall has one, the request phase, so every rule it runs is a request rule, kept under request_rules in the API. An application adds a response phase, and How Firewall works shows where a function on a firewall runs. |
| propagation | The time a saved change takes to reach Azion’s distributed infrastructure, during which answers alternate between the previous configuration and the one you saved. A change to the items of a network list propagates faster than a rule you add. How Firewall works gives the propagation time of each. |
| Reputation Intelligence | The check that raises a request’s score when its IP address is on a reputation network list. Bot Manager checks the Azion-managed Network Lists of the account by default, and Bot Manager Lite runs the check as rule 14 against the lists named in reputation_network_lists, which is empty by default. It is also a bot_category value, listed on Logs. |
| rule | An entry in the Rules Engine of a firewall that runs its behaviors on every request its criteria match. A firewall evaluates its rules in order, and a behavior such as Deny (403 Forbidden) ends the evaluation for that request. Each rule belongs to one firewall, at /v4/workspace/firewalls/<firewall-id>/request_rules in the API; Rules Engine for Firewall lists its fields. |
| rule ID | The identifier of one internal WAF rule, which an exception names to scope itself to that rule. 0 means all rules and is the default. The API accepts 63 IDs, listed on Rule sets, and Azion Console offers 62 of them, omitting 1314. |
| rule set | The WAF object that carries the eight threat families and the sensitivity level chosen for each, listed in Azion Console under WAF Rules. A rule set detects nothing on its own: a firewall rule with the Set WAF behavior applies it to traffic. Rule sets documents its fields. |
| Rules Engine for Firewall | The feature of a firewall that holds its rules and runs them in order on every request the firewall receives. Azion Console shows it as the Rules Engine tab of a firewall, where each rule pairs criteria with the behaviors they trigger. Rules Engine for Firewall documents every criterion and behavior. |
| ruleset | The name other platforms give to a managed set of WAF rules, which WAF calls a rule set. A managed ruleset transfers in the same shape: its categories are the eight threat families, and its strictness is the sensitivity level of each. The individual rules stay with the platform, as How Firewall works describes. |
| Run Function | The Rules Engine for Firewall behavior that invokes a function instance on the requests a rule matches, run_function in the API, with at most one per rule. It needs the Functions switch in Modules, which is on when you create the firewall through the API, the CLI, or the Create Firewall page. Rules Engine for Firewall documents it. |
| score | A number a Product computes for a request and compares with a threshold. WAF keeps one per threat family, raised by each further piece of evidence of that threat, and in Blocking mode refuses a request whose score reaches its family’s threshold, as How Firewall works describes. Bot Manager keeps one total, raised by each static rule matched and, outside Bot Manager Lite, by the dynamic score, and runs the instance’s action when it reaches the threshold, as How Firewall works describes. |
| security policy | The decisions about which requests may reach an application, which Firewall holds in one firewall: its rules, its function instances, and its Product switches. Workloads that follow the same security policy can share one firewall by naming it in their deployments, so the policy is written once. Firewall best practices weighs what sharing costs. |
| sensitivity level | The setting that fixes the threshold of one threat family, with five values from highest to lowest and a default of medium. A higher sensitivity sets a lower threshold, so WAF blocks more requests. Rule sets carries the score each level blocks at. |
| session signature | The HMAC signature Bot Manager Lite stores in az_asm and checks again on every later request from the same client. The session_signature_key argument supplies the key, az by default on Bot Manager Lite and azion on Bot Manager. Bot Manager Lite documents the argument. |
| Set WAF | The Rules Engine for Firewall behavior that applies a rule set to the requests a rule matches, together with the mode it runs in, set_waf in the API. A rule carries at most one, and Azion Console offers it only while WAF is on for the firewall. Without it a rule set never runs; Rules Engine for Firewall documents its fields. |
| static rule | A check Bot Manager runs against the attributes of a single request, such as its headers and metadata, with no reference to earlier traffic. Each rule a request matches raises its score. Bot Manager Lite publishes the rules that edition runs and the score each one adds. |
| threat family | One of the eight classes of attack a WAF rule set scores, each with its own sensitivity level. They cover attack types such as SQL injection, cross-site scripting, and directory traversal. Rule sets names all eight and what each one detects. |
| threshold | The score at which a Product acts on a request. In WAF, the sensitivity level of a threat family fixes it, and a higher sensitivity sets a lower threshold, as How Firewall works describes. In Bot Manager, the threshold argument sets it: at or above it the instance runs its action, which Arguments lists, and below it the request continues to your application. |
| Tuning | The tab on a WAF rule set that lists the requests each internal rule matched over a window of up to the last 3 days, grouped by rule ID. A query needs a domain and narrows by time range, network list, IP address, and country, and More Details narrows one rule’s occurrences further by path. Selected records become allowed rules in bulk, as Exceptions documents. |
| under evaluation | The classification Bot Manager records when it has not identified a bot and does not yet hold enough fingerprint data to rule out an attack. Consolidating the data of a fingerprint takes up to 15 minutes, and a fingerprint not seen for 15 minutes or more returns to this state. Logs covers the four classifications. |
| WAF | Web Application Firewall, the Product that scores each request against eight threat families and, in Blocking mode, refuses one whose score reaches a threshold. You turn it on per firewall with the Web Application Firewall switch in Modules, modules.waf.enabled in the API, and it is off when you create a firewall. Until it is on for the firewall a request passes through, no rule set runs; Firewall describes it. |