293 questions with Azure Web Application Firewall tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

Is it possible to have `ApplicationGatewayFirewallLog` for disabled rules on Application Gateway WAF in Prevention mode

Application Gateway with WAF in Detection mode logs each matched rule. However, in Prevention mode it catches only rules which are enabled. It makes sense somehow, because we don't want to have disabled rules evaluated in prevention mode, however I want…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-04-26T09:03:48.847+00:00
Krzysztof Madej 26 Reputation points
commented 2022-04-26T11:37:01.197+00:00
Krzysztof Madej 26 Reputation points
2 answers

Preview OWASP ModSecurity Core Rule Set 3.2 for Azure Web Application Firewall

There is a public preview of OWASP ModSecurity Core Rule Set 3.2 for Azure Web Application Firewall since July 2021. I´m wondering when it will be an official offer for Azure customers, once it has important improvements that could be usefull for us. …

Azure Web Application Firewall
asked 2022-04-13T19:10:24.183+00:00
Helio A. de Oliveira 1 Reputation point
answered 2022-04-22T15:34:12.75+00:00
Helio A. de Oliveira 1 Reputation point
1 answer

Azure Front Door WAF rate-limit behind NAT

Hello, I was researching Azure FrontDoor rate-limiting capabilities and as far as I can tell rate-limiting happens on an IP level, ie: when an IP surpasses the limit set for a given threshold it's blocked from calling the backend for a certain amount…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Web Application Firewall
asked 2022-03-30T09:52:31.163+00:00
Pantelis, Vasilis 1 Reputation point
commented 2022-04-21T11:40:23.043+00:00
GitaraniSharma-MSFT 49,261 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

"File Upload Limit" that can be set by WAF

Hello. I'm collecting information about setting up WAF for Application Gateway v2. I have three questions about the file upload limit in the WAF settings. 1. What is the file upload limit? What does this file upload refer to? For example, is it…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-04-13T06:30:56.31+00:00
haji-2517 21 Reputation points
accepted 2022-04-18T05:56:12.697+00:00
haji-2517 21 Reputation points
1 answer One of the answers was accepted by the question author.

Problem to receieve HTTPS trafic in Azure Application Gateway

In my scenario, I have an Application Gateway And three web apps on the backend. I route traffic based on subdomain and config Listener with HTTPS. All of the home pages of these web apps work well. Also, I have a program that sends data to…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,288 questions
asked 2022-04-08T14:28:17.257+00:00
Mohsen Akhavan 746 Reputation points
accepted 2022-04-13T06:06:47.18+00:00
Mohsen Akhavan 746 Reputation points
2 answers One of the answers was accepted by the question author.

DDoS Protection vs Bot detection

Hi, Good Day. I have recently come across that Azure DDoS is a new service that offers protection against DDoS kinds of attack by default. When we say DDoS, this is mainly caused by bots or scripts to emulate thousands of attacks in a min. Does…

Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
67 questions
Azure Web Application Firewall
asked 2022-04-01T16:02:54.197+00:00
Raghuraman C 21 Reputation points
answered 2022-04-05T10:46:10.36+00:00
Raghuraman C 21 Reputation points
1 answer

Not possible to modify Action on Managed-rules in Application Gateway WAF

Hi, We are using Azure application gateway WAF. Our WAF is in "Prevention" policy mode. We have defined some custom rules with blocked action. We would like to enable some of the managed rules with "Only Log" action. However…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-03-30T09:31:29.737+00:00
MF 71 Reputation points
commented 2022-04-05T09:18:48.477+00:00
MF 71 Reputation points
1 answer One of the answers was accepted by the question author.

Add IP Range - Azure Front Door WAF Custom Rule

Hi, My requirement is to block all requests from a range of IP addresses. This range of IP addresses will be added into a new custom rule. However, I do not know the format in which an IP range can be added into the textbox (screenshot below)…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Web Application Firewall
asked 2022-03-29T19:11:07.703+00:00
Ashwin D 21 Reputation points
commented 2022-03-30T15:31:07.603+00:00
Ashwin D 21 Reputation points
1 answer

Azure application gateway (SSL Certificate – Signature verification Failed Vulnerability and SSL Certificate – Subject Common Name Does Not Match server FQDN)

I have Azure application gateway with WAF wich have many backends and but Qualys did scan about several Ips associate this azure application gateway and found vulnerabilite like (SSL Certificate – Signature verification Failed Vulnerability and SSL…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-03-24T18:39:39.27+00:00
Rafael Campos 1 Reputation point
answered 2022-03-28T10:46:58.967+00:00
GitaraniSharma-MSFT 49,261 Reputation points Microsoft Employee
3 answers One of the answers was accepted by the question author.

Does Azure WAF bot protection work on Azure Front Door Classic?

Does Azure WAF bot protection work on Azure Front Door Classic or do you need to upgrade to premium?

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Web Application Firewall
asked 2022-03-21T18:00:25.433+00:00
Adam Ahmed 21 Reputation points
accepted 2022-03-23T15:11:19.237+00:00
Adam Ahmed 21 Reputation points
1 answer One of the answers was accepted by the question author.

Rate limiting in Azure Application gateway+ WAF

Hi here, Is it possible to implement Rate limiting using Azure application gateway and WAF for REST APIs hosted in App service ?

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-03-14T11:22:26.54+00:00
Upendra 21 Reputation points
accepted 2022-03-15T14:45:01.207+00:00
Upendra 21 Reputation points
2 answers

Block certain URLs/domains/hostnames on WAF

Hi, We have a WAF policy configured for our Application Gateway that sits in front of the website/server. The requirement from the client is to block certain hostnames/domains from accessing their website/server. Although it is possible to create…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2021-06-03T14:12:07.707+00:00
Soeb 1 Reputation point
answered 2022-03-14T17:09:39.31+00:00
Emad Adel 1 Reputation point
1 answer One of the answers was accepted by the question author.

Which type of App Service Environment v3 (Public IP or Private IP) is suitable for this scenario?

I wanna host three Web Apps on App Service Environment 3 (like the below diagram). Also, an Application Gateway control and routes incoming traffic between three Web Apps based on domain address. When I create ASE v3, I should select Public IP…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
Azure Dedicated Host
Azure Dedicated Host
An Azure service that provides a dedicated physical server to host Azure virtual machines for Windows and Linux.
49 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,288 questions
asked 2022-02-28T07:14:05.127+00:00
Mohsen Akhavan 746 Reputation points
commented 2022-03-07T09:13:05.97+00:00
Alan Kinane 16,806 Reputation points MVP
3 answers One of the answers was accepted by the question author.

Best practice for allowing SMTP to an Exchange VM in Azure

Hi, I need to allow incoming public SMTP and HTTPS traffic into one Exchange server in Azure. What is best practice for this situation? I could add a public IP address to the nic and allow smtp from specified IP ranges in an NSG. But I believe…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,480 questions
Azure Web Application Firewall
Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,468 questions
asked 2020-08-25T08:20:11.893+00:00
mij2020 366 Reputation points
answered 2022-02-16T06:53:14.707+00:00
Jayadeava Balaraja 1 Reputation point
0 answers

Application gateway WAF - blocking url parameters

Hello, I have a Windows server with few running REST services on it. URLs: Example 1: https://service.company.com/api/MyService/Login/?user='tom'&pass='123456' Example 2:…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
asked 2022-01-05T19:33:42.69+00:00
Werner Weiss 1 Reputation point
commented 2022-01-12T13:27:06.187+00:00
ChaitanyaNaykodi-MSFT 24,231 Reputation points Microsoft Employee
2 answers

How to setup WAF Reverse Proxy , DDOS in Azure

Dear Community, Please can you let me know how How to setup WAF Reverse Proxy , DDOS in Azure for a DNS? and get SSL Certificate Regards Rajesh S

Azure DDos Protection
Azure DDos Protection
An Azure service that provides defense against distributed denial-of-service (DDoS) attacks.
67 questions
Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
629 questions
Azure Web Application Firewall
asked 2022-01-07T16:24:29.887+00:00
Rajesh Sajjanar 1 Reputation point
answered 2022-01-09T17:03:14.563+00:00
Rajesh Sajjanar 1 Reputation point
0 answers

Azure FrontDoor WAF does not filter PUT requests

Hello, I'm trying to use Azure FrontDoor WAF with some web applications, but I noticed that default WAF rules do not filter PUT requests. I have tried to use some common XSS and SQL injection code into PUT requests, but WAF does not block anything by…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Web Application Firewall
asked 2021-12-22T12:54:33.897+00:00
Maksym Kharchenko2 41 Reputation points
commented 2021-12-22T19:58:46.38+00:00
suvasara-MSFT 10,026 Reputation points
1 answer One of the answers was accepted by the question author.

Azure FrontDoor WAF rate limit unexpected behavior

Hi, recently I configured WAF on Azure FrontDoor, but I noticed that the “rate limit” feature not working as expected. I have 2 rules configured with “rate limit”: Then I used the following batch script to make requests to my URL: @echo…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
622 questions
Azure Web Application Firewall
asked 2021-12-16T17:02:15.937+00:00
Maksym Kharchenko2 41 Reputation points
commented 2021-12-20T12:03:31.883+00:00
GitaraniSharma-MSFT 49,261 Reputation points Microsoft Employee
1 answer

How to configure rate limtting in Azure WAF for Application Gateway

Hi All, How can I configure rate-limiting using WAF for Application Gateway. Thanks

Azure Web Application Firewall
asked 2021-12-17T04:53:12.913+00:00
Dots 1 Reputation point
answered 2021-12-17T10:01:31.117+00:00
GitaraniSharma-MSFT 49,261 Reputation points Microsoft Employee
3 answers One of the answers was accepted by the question author.

Azure application gateway with Web App - Gateway IP wont work

Hello Team, I have Azure web app and i wanted to configure Azure Application gateway so that all the public IP traffic are routed through application gateway. For that i have created Application gateway and vNET, later I go to Web App Service -…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,002 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,288 questions
asked 2021-11-24T14:14:17.033+00:00
Atulkumar Thummar 101 Reputation points
accepted 2021-12-01T05:59:09.46+00:00
Atulkumar Thummar 101 Reputation points