Updating your Edge Firewall

In this document, we will indicate the features used in the deprecated versions, showing how to bring them to the latest version. To learn more about new features, and how to use them, see the product page and documentation.

Rule Sets deprecated from Edge Firewall show the following banner: This Edge Firewall rule set is deprecated. Please upgrade to the new version.

banner


Until now, the use of a Rule Set from Edge Firewall or WAF was through activation of Edge Firewall and Web Application Firewall modules in the Main Settings tab of each Edge Application and subsequent use of Behaviors Set Edge Firewall Rule Set and Set WAF Rule Set in the Edge Application Rules Engine.

Edge Firewall has become an independent product that concentrates all security features: DDoS Protection, Network Layer Protection, Web Application Firewall, and Edge Functions.

Before updating your version of the Edge Firewall it’s necessary to have the latest version of the Edge Application product.


Assigning your Rule Sets to the latest version of Edge Firewall

Section titled Assigning your Rule Sets to the latest version of Edge Firewall

To use the latest Azion Edge Firewall, follow the steps below, each section describes how each feature works on the new modules, Network Lists, and Rules Engine.

Step 1 - Creating new rule sets in Edge Firewall

Section titled Step 1 - Creating new rule sets in Edge Firewall

First, you need to create a Rule Set and new rules based on pre-existing rules. Through the process, we will explain how each feature works on the latest version:

Create Edge Firewall Rule Set:

Section titled Create Edge Firewall Rule Set:
  1. Log into Azion Console, go to the Products menu in the upper left corner, under SECURE select Edge Firewall. You can also click directly on Edge Firewall on the Getting started page.
  2. Add an Edge Firewall by clicking Add a Rule Set or edit an already created one.
  3. Follow the steps below according to the functionality:

referer-blocking

If you used Referer Block in your deprecated rule set, in the new rule set:

  1. Enable the module Web Application Firewall.
  2. Then, follow the tab Rules Engine in Criteria, and select Header Referer.
  3. Add the domain of the old Rule Set with the condition Header Referer, using the comparator does not match.
  4. For each domain in Accepted Domains of the old Rule Set, add an AND rule by repeating step 3.
  5. In Behavior, select the Behavior Deny 403.

geo-blocking

If you used Geo-Blocking in your deprecated rule set, in the new rule set:

  1. Access the Azion Console and enter the Libraries > Network Lists menu.
  2. Add or edit a Network List.
  3. In the Type option, select Countries.
  4. Copy the list of countries from the deprecated rule set to Network Lists.
  5. In the Edge Firewall, enable the Network Layer Protection module.
  6. On the Rules Engine tab, create a new Rule and select Criteria: Network.
  7. Choose a logical operator where Match means Blacklist and Does not Match means Whitelist.
  8. Then, select the Country type of Network List created in steps 3 and 4.
  9. In Behavior, select the Behavior Deny 403.

secure-token

If you used Secure Token in your deprecated rule set, in the new rule set:

  1. Enable the module Edge Functions.
  2. In the Functions tab, select Add function to instantiate a Secure Token Edge Function.
  3. Fill in the information and use the editor to customize Function Args to define the secret that composes the hash.
  4. On the Rules Engine tab, define a Criteria that will be used on Edge Function.
  5. In Behavior select Run Function, then select Secure Token function, created in steps 2 and 4.

ip-blocking

If you used IP Blocking in your deprecated rule set, in the new rule set:

  1. Access the Azion Console and enter the Libraries > Network Lists menu.
  2. Add or edit a Network List.
  3. In the Type option, select IP/CIDR.
  4. Copy the list of IP`s from the deprecated rule set to Network Lists.
  5. In the Edge Firewall, enable the Network Layer Protection module.
  6. On the Rules Engine tab, create a new Rule and select Criteria: Network.
  7. Choose a logical operator where Match means Blacklist and Does not Match means Whitelist.
  8. Then, select the IP/CIDR type of Network List created in steps 3 and 4.
  9. In Behavior, select the Behavior Deny 403.

rate-limiting

If you used Rate Limiting in your deprecated rule set, in the new rule set:

  1. Select the Rules Engine tab.
  2. Then, define the Criteria for your Rule Set.
  3. In Behavior, select Set Rate Limit.
  4. Set the number of requests per second in the Average Rate Limit.
  5. Set to Client IP Address or Global.
  6. After, set the Maximum burst size.

Association of Domains to the new Rule Set

Section titled Association of Domains to the new Rule Set

After making the settings associate one or more domains to the new Rule Set:

  1. Edit the new Rule Set of the Edge Firewall.
  2. In the Domains section, select domains that will be associated with the Rule Set in Main Settings.
  3. Save to apply the configuration.

After making the settings associate your WAF Rule Set to the new Rule Set. You can use the WAF Rule Sets the same way. However, they pass from the Edge Application to the Edge Firewall Rules Engine:

  1. Edit the new Rule Set of the Edge Firewall.
  2. Enable the module Web Application Firewall.
  3. On the Rules Engine tab, add or edit a Rule.
  4. Set the Criteria to condition the use of the WAF Rule Set.
  5. In Behavior select Set WAF Rule Set and choose a WAF Rule Set.
  6. Save to apply the settings.

Step 2 - Removing the Edge Firewall rules in the Edge Application

Section titled Step 2 - Removing the Edge Firewall rules in the Edge Application

After creating and applying the Rule Sets for the latest version of Edge Firewall for your domain, remove the Rules in Edge Application:

  1. Log into Azion Console, go to the Products menu in the upper left corner and under BUILD select Edge Applications.
  2. Edit an Edge Application with the Edge Firewall configuration.
  3. On the Rules Engine tab, identify the Behaviors Set Edge Firewall with Rule Sets or Set WAF Rule Set.
  4. Remove the Behavior from Edge Application.
  5. Next, confirm the deletion by clicking Delete and your rule will be removed.

Contributors