Azure App Gateway v2 WAF difference?

Rich Roy 26 Reputation points
2021-08-26T20:57:05.307+00:00

I have a v2 sku app gateway with several URLS and back end pools works great. There is a message that says "Upgrade to the WAF tier to increase your app's security." which, "looks" like you simple hit the slider over and then press save and Bingo, all done. Too many years in IT has made be think...hmmm can't be that simple got to be more to it. So, is there more to it? I can't find a good video or walk thru that discusses this. All the WAF or AppGateway stuff I find is the usual "Hello world" level of examples or from scratch stuff. Nothing of the kind...take your working App gateway and upgrade it to a WAF .

So anyone got some tips? Video? blog etc? or is it really that simple?

Thanks

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,006 questions
Azure Web Application Firewall
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ChaitanyaNaykodi-MSFT 24,391 Reputation points Microsoft Employee
    2021-08-31T20:19:33.787+00:00

    Hello @Rich Roy , apologies for the delayed response here.

    When you select the WAF tier in portal and enable the firewall option This enables firewall for your App Gateway but there additional settings and custom policies you can set to take full advantage of this feature.

    When you enable the WAF tier from your portal and WAF settings are visible and can be changed from within the Application Gateway view, your WAF is in state 1. Please refer to this document for additional details regarding the states.

    127987-image.png

    The recommended method is to Migrate to a WAF policy as it provides you with additional features like WAF policy settings, managed rulesets, exclusions, and disabled rule-groups. Essentially, all the WAF configurations that were previously done inside the Application Gateway are now done through the WAF Policy.

    After doing a random search on internet I found this Youtube video(7:20) which you can refer for how to set-up this WAF policy.

    Please let me know if you have any additional concerns. Thank you!

    ----------

    Please do not forget to "Accept the answer" wherever the information provided helps you to help others in the community.

    0 comments No comments