323 questions with Azure Web Application Firewall tags

Sort by: Updated
0 answers

WAF Log Scrubbing XML payloads

Hi, First poster here. I have a SOAP API that is behind an APP GW with WAF and then an APIM. Some of the payloads are triggering built in WAF rules and causing logs to be recorded. I have configured the log scrubbing to target the named properties inside…

Azure Web Application Firewall
asked 2024-10-04T12:33:44.4+00:00
Alex Savage 0 Reputation points
0 answers

Need to exclude specific string that could appear in multiple URLs for Azure WAF.

We use different advertisements that refer to pages on our website. When the third party puts the link on their site it modifies the URL and adds a specific string to the referring URL that is currently being blocked by Azure WAF. It is always firing…

Azure Web Application Firewall
asked 2024-10-04T12:15:35.1466667+00:00
Mike VP 0 Reputation points
1 answer One of the answers was accepted by the question author.

How would TLS inspection work with WAF enabled App Gateway and Azure Firewall?

Hi, I have been struggling with this from a while now. Our design has WAF enabled App gateway for incoming HTTP / HTTPS traffic from internet and then have Azure Firewall behind it. Have couple of queries for which I need assistance: 1: Does WAF has…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
662 questions
Azure Web Application Firewall
asked 2024-09-18T23:33:09.83+00:00
Rakesh Singh 205 Reputation points
edited a comment 2024-10-03T19:28:10.1833333+00:00
Mail Sa 0 Reputation points
1 answer One of the answers was accepted by the question author.

Azure FrontDoor WAF rate limit unexpected behavior

Hi, recently I configured WAF on Azure FrontDoor, but I noticed that the “rate limit” feature not working as expected. I have 2 rules configured with “rate limit”: Then I used the following batch script to make requests to my URL: @echo…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
676 questions
Azure Web Application Firewall
asked 2021-12-16T17:02:15.937+00:00
Maksym Kharchenko2 46 Reputation points
edited a comment 2024-10-02T09:54:09.0233333+00:00
Nikhil Singh 0 Reputation points
0 answers

Allow-Access-Control-Origin Error on Web App

Hey everyone. I may be missing something simple, but here's one for you guys! Turning on App Gateway WAF Policy with a custom rule for geo location match. Essentially just to deny any traffic outside of select countries. Without this WAF Policy turned…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
882 questions
asked 2024-09-24T19:45:46.7866667+00:00
Joseph Dutton 135 Reputation points
commented 2024-09-27T05:33:25.71+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
1 answer

How to remove WAF policy safely.We have an AKAMAI device before the App GW and do not need WAF capability anymore.What is the safest way to do so.

How to remove WAF policy safely or disassociate WAF policy . We have an AKAMAI device before the App GW in our environment hence we do not need WAF capability anymore. What is the safest way to do so. Also can I do it via portal and if I am doing it via…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
Azure Policy
Azure Policy
An Azure service that is used to implement corporate governance and standards at scale for Azure resources.
882 questions
asked 2023-03-21T05:27:06.58+00:00
Samar Masood Khan 20 Reputation points
commented 2024-09-26T11:27:17.2633333+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
0 answers

Need assistance to resolve waf rule " Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link"

Hi We need assistance in resolving an issue with the WAF while loading the following application URL. The web application is calling the API to load the application. Please find the URL and the error message below for reference. Please need assistance…

Azure Web Application Firewall
asked 2024-09-24T08:38:54.99+00:00
Vipul Laxmikant Redkar 0 Reputation points
commented 2024-09-26T08:23:52.2566667+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
1 answer

In "Application Gateway WAF policy" resources cannot select "Rate limit" rule type in custom rules. Only "Match" available.

Hi, In "Application Gateway WAF policy" resources cannot select "Rate limit" rule type in custom rules. Only "Match" available. I want to configure rate-limit rules in my WAF for Application Gateway. I have a bunch of…

Azure Web Application Firewall
asked 2024-09-04T15:48:06.59+00:00
Alex Vasiuk 0 Reputation points
answered 2024-09-26T01:32:25.52+00:00
ChaitanyaNaykodi-MSFT 26,101 Reputation points Microsoft Employee
1 answer

I am getting request such as "~^.*\.mywebsite\.com$" on my azure application gateway. This causes "ERRORINFO_REQUEST_URI_INVALID" error. How do i prevent invalid requests at the Azure WAF2 level?

Recently, we are getting a lot of requests such as "~^.*.mywebsite.com$" and it gets logged in the Application Gateway as "ERRORINFO_REQUEST_URI_INVALID". We would like to prevent such wildcard requests at the Web Application…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
asked 2024-09-25T02:45:36.1433333+00:00
Prasanna Srinivasan 0 Reputation points
answered 2024-09-25T10:50:47.21+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
1 answer

going with the application gateway in fornt of azure firewall does it lose the benefit of l7 load balancing

I have an Azure firewall in a hub and spoke architecture, and one of the spokes contains my web servers, for HTTPS filtering I have an application gateway with the WAF feature and l7 load balancing. I have a requirement to keep centralized security…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
662 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
439 questions
asked 2024-09-23T06:26:52.93+00:00
Mohammad Nemer 0 Reputation points
answered 2024-09-23T10:20:18.8833333+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
0 answers

Requests get blocked in WAF with ERRORINFO_NO_ERROR

In Azure, I have an application gateway with web application firewall. Recently, requests from end users have been blocked with http status 403 Forbidden. They're perfectly normal requests, and I see no reason why they should be blocked. In de logs, the…

Azure Web Application Firewall
asked 2024-09-18T09:14:23.2+00:00
Ard de Gelder 0 Reputation points
commented 2024-09-18T21:33:41.5233333+00:00
ChaitanyaNaykodi-MSFT 26,101 Reputation points Microsoft Employee
0 answers

WAF 2 does not prevent script attack

I have integrated a web application firewall (2) with the application gateway in Prevention mode. However, when I attempt to create a record using FirstName as script tag, the record is successfully created. Ideally, this action should be blocked.…

Azure Web Application Firewall
asked 2024-09-06T09:54:45.77+00:00
Avinash Davkhar 20 Reputation points
commented 2024-09-16T01:47:28.6733333+00:00
Sai Prasanna Sinde (Quadrant Resource LLC) 110 Reputation points Microsoft Vendor
1 answer

Request blocked by Microsoft_DefaultRuleSet-2.1-SQLI-942120 for russian language

When we try to submit the leads in our website We figured out that for Russian language characters Azure Front door firewall rule(942120 - SQL Injection Attack: SQL Operator Detected) was blocking the requests. Below is the screenshot of how we find it…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
676 questions
Azure Web Application Firewall
asked 2024-09-13T12:40:48.4533333+00:00
Mohideen Ansari 0 Reputation points
answered 2024-09-13T19:49:39.2666667+00:00
ChaitanyaNaykodi-MSFT 26,101 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How to fix blocked:mixed-content error on Application Gateway?

I have configured an application gateway associated to a WAF with my app service, the goal was to use WAF in front of my app; the issue now is that I dont have custom domain for my application gateway or app service. Earlier I was using default domain of…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,755 questions
asked 2024-09-04T07:21:43.22+00:00
Najam ul Saqib 280 Reputation points
accepted 2024-09-09T09:31:21.6366667+00:00
Najam ul Saqib 280 Reputation points
1 answer One of the answers was accepted by the question author.

Is it possible to use .azurewebsites.net domain with application gateway?

Hi, I have integrated azure app gateway with my app service to have WAF in front of my web app. I see that I have app gateway's IP address via which I can access the app service, is there any possibility that I use the default domain of web app even with…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,755 questions
asked 2024-09-03T07:22:42.4266667+00:00
Najam ul Saqib 280 Reputation points
accepted 2024-09-09T08:04:01.9766667+00:00
Najam ul Saqib 280 Reputation points
7 answers

When to use Azure WAF or Azure Firewall ?

Hi Folks, Can anyone here please share some thoughts and comments of when to use Azure WAF or Azure Firewall? I have already existing Azure ExpressRoute so my Azure VMs can ping my OnPremise servers, and vice versa. My purpose here is to be able to…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
662 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
92 questions
asked 2020-11-15T13:17:27.597+00:00
EnterpriseArchitect 5,376 Reputation points
commented 2024-09-05T02:47:57.56+00:00
Matthew McKenzie 0 Reputation points
1 answer

Azure NSG rules both for both public and private IPs

Can I apply a public IP to a vm and have it not affect the nsg rules that I have for it's private IPs? I have current nsg rules for the private IP but i want to add a public IP and apply nsg rules to it as well. I will be limiting access to it from…

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,426 questions
Azure Web Application Firewall
asked 2024-08-29T21:57:05.1766667+00:00
Jose Cintron 60 Reputation points
answered 2024-08-30T05:36:13.0666667+00:00
Rohith Vinnakota 595 Reputation points Microsoft Vendor
0 answers

Azure WAF rule 920470 blocking the requests with details massage: Pattern match ^[\w\d/\.\-\+]+(?:\s?;\s?(?:boundary|charset)\s?=\s?['"\w\d\.\-]+)?$ at REQUEST_HEADERS:content-type. But we excluded the rule like in the below snip still the rule blocking

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,063 questions
Azure Web Application Firewall
asked 2024-08-01T12:50:03.74+00:00
Chandu 0 Reputation points
commented 2024-08-30T00:51:31.9933333+00:00
ChaitanyaNaykodi-MSFT 26,101 Reputation points Microsoft Employee
0 answers

Azure WAF Security Features in Standard Tier with Front Door

Hey all - I’m looking for insights regarding the security features offered by the Azure WAF when deployed in the Standard tier with Azure FD, particularly in scenarios where the customer does not want to create any custom rules. Given that the Microsoft…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
676 questions
Azure Web Application Firewall
asked 2024-08-20T04:53:06.4433333+00:00
Bhushan Gawale 316 Reputation points
commented 2024-08-26T09:38:44.1533333+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

How to add correct exclusion on Azure WAF?

Greetings. Please help in creating an exception to the rule: OWASP_3.2 - Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link. My web application generates requests like: …

Azure Web Application Firewall
asked 2024-05-13T11:59:44.36+00:00
Yurii Tsarienko 20 Reputation points
commented 2024-08-26T03:33:39.46+00:00
KapilAnanth-MSFT 45,111 Reputation points Microsoft Employee