WAF quickstart
Create a rule set, apply it to a firewall with a Set WAF behavior, and confirm that an injection-shaped request is refused.
This guide instructs you through scoring your first request against Web Application Firewall (WAF).
- Create a rule set that carries eight threat families at
mediumsensitivity. - Apply that rule set to a firewall with a
Set WAFbehavior in blocking mode. - Send an injection-shaped request and read the refusal.
Four objects put a request under inspection, and each one links to the next:
- The rule set holds the threat families and the sensitivity chosen for each.
- The firewall carries the WAF module, and the workload serving your application is bound to that firewall.
- The Rules Engine rule on that firewall carries a
Set WAFbehavior, which names the rule set and the mode. - The request is what WAF then scores against the rule set.
A rule set inspects nothing on its own. Until a Rules Engine rule names it, no request is scored.
Select the interface you will use. The prerequisites and every stage below follow that choice.
Prerequisites
- An Azion account. To create one, refer to How to create an account on Azion.
- A firewall with the WAF module turned on. WAF is the one module a firewall does not turn on for itself. Refer to Set a firewall’s main settings.
- A workload bound to that firewall, serving an application. Refer to Bind a firewall to a workload.
- Access to Azion Console. To sign in, refer to How to access Azion Console.
Create the WAF rule set
The rule set holds what to detect. It carries eight threat families, and each family has a sensitivity level that fixes the score at which it blocks. Every family starts at medium, which is the level this guide uses.
To create the rule set in Azion Console:
Access Azion Console > Edge Libraries > WAF Rules.
In the General section, enter a Name. For example: storefront-waf.
The Threat Type Configuration section lists eight threat families. Each one opens on Sensitivity Medium.
The rule set appears in WAF Rules, which lists its Threat Type Configuration, Status, Last Editor, and Last Modified.
Apply the rule set with a Rules Engine rule
A Rules Engine for Firewall rule selects requests by its own criteria. Its Set WAF behavior then names one rule set and one mode. The rule below applies your rule set to every request the firewall receives.
The mode is required, and it belongs to the behavior rather than to the rule set. Blocking refuses a request whose score reaches a threshold. Logging records the same request and serves it. This guide uses Blocking.
To apply the rule set in Azion Console:
Still in Azion Console, go to Firewalls and select that firewall.
Enter a name for the rule. For example: Apply storefront-waf.
In the Criteria section, select the Request Uri variable, the starts with comparison operator, and / as the argument.
In the Behaviors section, select Set WAF, then select the rule set you created.
The firewall now scores every request it receives against the rule set. A rule carries at most one Set WAF behavior.
Verify that WAF blocks a request
The check is the same whichever interface built the rule. Your workload answers on a domain of the form <id>.map.azionedge.net, written below as <your-workload-domain>.
A new binding takes time to reach Azion’s distributed infrastructure. Expect close to six minutes before the rule takes effect. The domain then answers inconsistently for several minutes, while the change arrives in different places. A request that still returns the earlier response has broken nothing: wait, then send it again.
Send a clean request first:
The request is not scored as a threat and reaches the application, which answers it:
Your own application decides that status. What matters is that the request is not refused.
Now send an injection-shaped request, carrying 1' OR '1'='1 in the query string:
WAF refuses it:
The body is Azion’s default error page, headed Bad Request. Nothing in the response names WAF, the rule that matched, or the score. Record x-azion-request-id: that value finds the request in Real-Time Events.
That request tripped the internal rules 1009 and 1013, both on the q argument. It scored under the SQL injection and cross-site scripting families. Your rule set is now scoring traffic.