more than 12K or 18K URL under block for particular rule like SQLI or XSS how can we make false positive by custom or exculsion

Parmeshwar Mukhede 0 Reputation points
2024-02-27T09:10:45.4066667+00:00

Result of latest scan on application associated with AFD-WAF, we observed for reach rule blocked under SQLI and XSS are more than 12 K URLs, and all are under blockage because of just one or more char like ",: etc. which are must required part of each request like Jason body or payload. but no provision to update the Jason for underlying rule to overcome the false positive or its difficult add custom rule or exclusion for all the blocked URL or the blocked variable keys. please suggested us best way to overcome the blockages ins short span.

Azure Web Application Firewall
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. KapilAnanth-MSFT 39,461 Reputation points Microsoft Employee
    2024-02-27T10:55:51.7933333+00:00

    @Parmeshwar Mukhede ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.

    I understand that you would like to tune your App gateway WAF.

    Every application has it's own requirement and you have to Tune your WAF according to the requirement.

    Hope this helps.

    Cheers,

    Kapil