is it safe to create WAF but not enable it?

Russell Hutson 1 Reputation point
2022-09-28T14:51:05.697+00:00

We have a frontdoor which has both Production and Staging pools behind it.

I want to experiment with using the Azure WAF but don't want anything to impact my production environments.

As WAFs are associated to the Frontdoor, I'm worried it will affect my production environment, before we have successfully proven it work on staging.

Looks like I can enable WAF policies on my staging domains.
And looks like I can create a policy and completely disable it when I create it. (Policy State).

But I want to make absolutely sure there is no impact on production until I enable the WAf Policy of=n the production domain.

thanks in advance

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
577 questions
Azure Web Application Firewall
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. David Broggy 5,681 Reputation points MVP
    2022-09-28T15:22:52.073+00:00

    HI Russell,
    As long as it's in detection mode and not prevention there won't be any impact.
    Configuring a regional waf vs global will also add additional isolation.
    Of course this is just my personal experience, you won't get any legal commitments from a Q&A forum :).

    245606-image.png

    0 comments No comments