How to disable Microsoft_DefaultRuleSet-2.0-BLOCKING-EVALUATION-949110?

Deshmukh, Vijit 496 Reputation points
2022-11-08T15:07:07.827+00:00

Hi Team,
We are using Azure Front Door.
And using by default WAF rules.
But WAF is blocking some requests, in diagnostic logs we found rule_name Microsoft_DefaultRuleSet-2.0-BLOCKING-EVALUATION-949110

Please let us know is there any way to unblock/bypass/exception for this, as it is not from the list of managed rules.

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
576 questions
0 comments No comments
{count} votes

Accepted answer
  1. KapilAnanth-MSFT 35,001 Reputation points Microsoft Employee
    2022-11-09T07:12:24.183+00:00

    Hi @Deshmukh, Vijit ,

    Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
    I understand that you are hitting the WAF rule 949110 with your AFD.

    Please note that Rule 949110 cannot be disabled.

    • This rule means Inbound Anomaly Score Exceeded.
    • This is triggered when the anomaly threshold exceeds. This is in-turn caused by other rules that are hit which increase the anomaly score.
    • 258518-image.png
    • You have to check the diagnostic logs and find the exact rules that are increasing the anomaly score.
    • You should create the custom rules or exceptions to bypass the rules which increase the anomaly score.

    Refer: Web Application Firewall DRS rule groups and rules

    The following docs may come in handy
    Tuning Web Application Firewall (WAF)
    Anomaly scoring

    Cheers,
    Kapil

    ----------------------------------------------------------------------------------------------------------------

    Please don’t forget to close the thread by clicking "Accept the answer" wherever the information provided helps you, as this can be beneficial to other community members.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful