Create Managed Rule Exclusion to exclude a rule on a particular host
Hi, I am trying to create an exclusion rule on a particular OWASP policy code to exclude a particular host name. I include the rule and use the following: Match Variable: Request Header Values Operation: Equals Select: {my.host.com} I've tried various…
Azure Web Application Firewall
powershell script to change certificate in WAF
I have renewed my SSL certificate. Is there any powershell script to change certificate in WAF
Azure Web Application Firewall
Why does Azure application gateway rate limit WAF return a 403 and not a 429?
When Azure Application gateway rate limiter functions as expected, we were expecting a 429, but instead, a 403 is returned. Why is this?
Azure Application Gateway
Azure Web Application Firewall
Azure Application gateway with WAF
Dear team, I'm using Azure application gateway with tier Standard V2. I concert about the difference between application gateway and WAF. As I understand, when I only use Azure application gateway, it doesn't include all features of WAF, or it includes…
Azure Web Application Firewall
Is Log Analytics Workspace required to view WAF logs for Azure Front Door? How to identify blocked traffic?
Hi, I want to use Azure Front Door to protect my applications and domains running on several VMs. I would like to review the WAF logs to understand which traffic has been blocked due to potential threats and anomaly score. From what I understand, I can…
Azure Web Application Firewall
Is it possible to disable logging for custom rules in Azure WAF?
Is it possible to disable logging for custom rules in Azure WAF? I’d like to avoid logging allowed actions since they produce too much noise.
Azure Web Application Firewall
Exclude/exempt specific IP from WAF managed rules
Hi, I have an application hosted on Azure WAFV2, I need to define an exclusion using client IP address. Basically any request coming from that IP should not be examined against OWASP 3.2 managed rules. I tried defining exclusions but IP specific…
Azure Application Gateway
Azure Web Application Firewall

Can't add more than three custom domains
I am trying to setup a large quantity of custom domains to be returned to my site and I cannot create more than three. Any ideas on why? A while back I was allowed additional custom domains but now it seems it was either removed or I cannot add anymore.…
Azure Web Application Firewall
User session timeout issues on the WAF-protected web application. After two or three minutes, the session closes, but response times when making requests or navigating within the application are functioning accordingly.
User session timeout issues on the WAF-protected web application. After two or three minutes, the session closes, but response times when making requests or navigating within the application are functioning accordingly. The logs within the login have…
Azure Web Application Firewall
「A potentially dangerous Request.Form value was detected from the client」
I am building a web server in Azure with a configuration of CDN - WAF - WebApps. This is a .Net Framework web application. Because requestValidationMode="4.0" "A potentially dangerous Request.Form value was detected from the…
Azure Web Application Firewall
WAF policy IP address or range
Are there any limitations on the IP lists associated with IoCs? For example, today we have a list of more than 7,500 IPs reported by the SOC, which we are blocking on security devices. Regards. Humberto G
Azure Web Application Firewall
WAF error "Execution error - PCRE limits exceeded"
Our waf rules are blocking some content from accessing the backend web server; I searched the wag logs and found some OWASAP rules, the associated rule number is 932150, and the normal error message should be Remote Command Execution: Direct Unix Command…
Azure Web Application Firewall

WAF is returning 400 Bad Request - Request too long
WAF -> Azure Firewall -> IIS WAF returning 400 - Bad Request - Request too long. I've disabled "Enforce Request Body Inspection", and "Enforce Maximum Request Body Limit". Also, WAF is in detection mode, not prevention mode. I…
Azure Web Application Firewall
How to configure custom rate limiting rule for Azure Front Door Standard Web Application Firewall
I want to configure a rate limiting rule in the web application firewall for Azure Front Door Standard. When requests from a client IP address exceed the set threshold, the requests should be blocked. I cannot find examples for this scenario. I find only…
Azure Web Application Firewall
How to Change the Azure WAF Policy Mode
Is there a way to change / switch the WAF policy mode between prevention & detection after the creation of WAF? I can't get such option from the Azure portal, and neither the steps mentioned in Azure documentation. If the option is not available in…
Azure Web Application Firewall
Increased Chunk load failure post CDN migration
We recently migrated our CDN from Microsoft(Classic) to AFD premium. Post this migration we are seeing high chunk load failures. We have WAF in detection mode so we are not expecting it to block any traffic. WAF currently has…
Azure Web Application Firewall
Connection Issue of External WAF to an Instance inside Azure Cloud
Hello everyone, I'm reaching out to request guidance and support regarding an issue we're encountering. We are currently unable to receive syslog traffic from our external WAF to one of our log collectors within our Azure network. At present, we are not…
Azure Web Application Firewall

Can I set WAF rules to Log by default and override specific ones to Block?
Hey, I have set the WAF in Prevention mode to allow my custom rules like Rate limiting to be in effect with Blocking action. However as I was facing so many false positives with Microsoft_DefaultRuleSet 2.1, I changed the action as Log for it so that I…
Azure Front Door
Azure Web Application Firewall
List of characters or strings blocked in Azure frontdoor WAF policies
Hi, I am need of document link, where I can find what special characters are blocked under which Frontdoor WAF policy. I am at premium tier of Azure Frontdoor and WAF policies.
Azure Web Application Firewall
During WAF creation Default Ruleset 2.1 showing as in preview
While creating a new WAF policy for Regional WAF (Application Gateway), moving to the Managed rules tab to select the default ruleset, Microsoft_DefaultRuleSet_2.1 is showing (preview). I thought this was GA already? See below image. Thanks.