Access denied with code 403 (phase 2). Match of \"eq 0\" against \"MULTIPART_UNMATCHED_BOUNDARY\" required. WAF 200004

Ko Ko Tun 41 Reputation points
2022-11-17T03:55:08.787+00:00

I got

Access denied with code 403 (phase 2). Match of \"eq 0\" against \"MULTIPART_UNMATCHED_BOUNDARY\" required.

at app-gateway at WAF with ruleId_s = 200004 when I tried to upload screenshot to my server.

I found some answer at stackoverflow from below.

https://stackoverflow.com/questions/72322174/waf-200003-multipart-request-body-strict-validation

I can't find official answer from Microsoft.
Is it false positive ?
Should I disable the rule at WAF?

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
937 questions
Azure Web Application Firewall
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 46,261 Reputation points Microsoft Employee
    2022-11-17T12:22:44.72+00:00

    Hello @Ko Ko Tun ,

    Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.

    I understand that you are getting an "Access denied with code 403 (phase 2). Match of \"eq 0\" against \"MULTIPART_UNMATCHED_BOUNDARY\" required" error in Application gateway WAF logs with ruleId_s = 200004 when you try to upload screenshots to your server.

    I checked with the Application gateway WAF Product Group team and below is their update:

    Yes, this is a known issue, and we are in process of rolling out a fix. Workaround to disable this rule is reasonable for time being.

    This bug/known issue is being tracked internally and a fix will be rolled out soon.

    Kindly let us know if the above helps or you need further assistance on this issue.


    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful