# WAF examples

Copy any of these snippets and change the names and ids for your own account. Each one is the smallest complete form of a task the rest of the [Web Application Firewall (WAF)](/en/documentation/platform/firewall/#waf) documentation describes at length: a rule set, the Rules Engine rule that applies it, the exception that clears a false positive, and the query that returns what WAF decided about a request.

A rule set scores nothing on its own. Until a Rules Engine rule on a firewall carries a `Set WAF` behavior naming it, no request is scored, so the first two snippets belong together. Where a snippet has both an API and an Azion CLI form, the page carries both.

---

## A rule set in the request path

- [A rule set at medium sensitivity](/en/documentation/guides/application-security/firewall-and-waf/rule-set-medium.md): Create a rule set carrying the eight threat families at the sensitivity level every family starts on.
- [A rule that applies a rule set](/en/documentation/guides/application-security/firewall-and-waf/apply-rule-set.md): Build the Rules Engine rule whose `Set WAF` behavior puts a rule set in front of every request a firewall receives.
- [Bind a rule set in azion.config.js](/en/documentation/guides/application-security/firewall-and-waf/config-file-binding.md): Declare the rule set and the firewall rule that applies it in the configuration file, instead of creating both by hand.

---

## What a rule set blocks

- [Switch a rule set to blocking](/en/documentation/guides/application-security/firewall-and-waf/switch-to-blocking.md): Change the mode on the behavior that applies a rule set, so a scored request is refused rather than served.
- [Raise one threat family](/en/documentation/guides/application-security/firewall-and-waf/raise-one-threat-family.md): Set a higher sensitivity on one threat family and keep the other seven where they are.

---

## A block and its exception

- [Read the score of a blocked request](/en/documentation/guides/application-security/firewall-and-waf/read-block-score.md): Query Real-Time Events for the internal rules that matched a request and the score each threat family gave it.
- [Exempt one query string parameter](/en/documentation/guides/application-security/firewall-and-waf/exempt-query-parameter.md): Stop one internal rule firing on one named query string argument, and leave it firing everywhere else.
- [Exempt one request header](/en/documentation/guides/application-security/firewall-and-waf/exempt-request-header.md): Name a single header in an exception, and avoid the condition shape that silently covers every header.

---

## Related resources

- [WAF quickstart](/en/documentation/platform/firewall/waf/quickstart.md): Run these snippets in order, from an empty account to a request that is refused.
- [Scoring and modes](/en/documentation/platform/firewall/waf/scoring-and-modes.md): The path a request travels, the scoring model, and what each mode does.
- [WAF Rule Sets](/en/documentation/platform/firewall/waf/rules-set.md): Every field a rule set carries, its eight threat families, and the internal rules behind them.
- [WAF Exceptions](/en/documentation/platform/firewall/waf/custom-allowed-rules.md): Every field an exception carries and the fifteen match values a condition takes.
- [Firewall best practices](/en/documentation/platform/firewall/best-practices.md#waf): What each of these snippets costs in production, and the order to apply them in.
- [Troubleshoot Firewall](/en/documentation/platform/firewall/troubleshooting.md#waf): What to read when a snippet runs and the result is not what you expected.
