Hello @Matheus Silva ,
Welcome to Microsoft Q&A Platform. Thank you for reaching out & hope you are doing well.
I understand that you would like to know if there is a limit of IP groups and IPs in a group for WAF exclusion?
The limit of WAF IP address ranges per match condition is:
- 540 with CRS 3.1 or lower
- 600 with CRS 3.2 or newer
Maximum WAF custom rules that can be configured in a WAF is 100.
And WAF IP address ranges per match condition is 600.
So, that gives you a total of 60000 IP address ranges.
NOTE: This limit is same for both Application gateway WAF and Azure Front Door WAF.
If one custom rule already has 600 IP addresses/ranges, you can create another custom rule and add the new IPs/ranges.
One IP range is considered as 1 entry. And you can add 600 IP ranges in one custom rule. But you need to make sure that none of the address ranges has overlapping IP addresses and all the ranges have unique IP addresses.
Kindly let us know if the above helps or you need further assistance on this issue.
Please "Accept the answer" if the information helped you. This will help us and others in the community as well.