Azure FrontDoor and Application Gateway Request Size limits

Alex 515 Reputation points
2025-07-07T10:09:38.0233333+00:00

Hello,

Good day!

I have a few queries as below, can anyone kindly help me with it?

  1. What is the request size limit of Azure Front door (premium) and Application Gateway (WAF v2) - include file upload requests as well?
    1. From the docs, it says AppGw CRS3.1 is 128KB and CRS3.2 is 2MB. Can it not be more than that?
    2. And I couldn't find the similar details for Front Door.
  2. Are request size limit and request inspection limit different? where to configure these two in Front door and Application gateway?
Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Ganesh Patapati 9,985 Reputation points Microsoft External Staff Moderator
    2025-07-07T10:46:28.43+00:00

    Hello Alex

    According to some documentation, it seems to be also 128KB. When I try, and I have a request lager than 128KB, the request isn't blocked, so that would mean that the 128KB is not the limit. The only think I can think of is that it only checks the first 128KB of data.

    Azure Front Door WAF only inspects the first 128KB of the data and the remaining data is allowed through without inspection.

    As per Azure WAF Request size limits: The maximum request body size field is specified in kilobytes and controls overall request size limit excluding any file uploads. This field has a minimum value of 1 KB and a maximum value of 128 KB. The default value for request body size is 128 KB.

    However, For CRS 3.2 (on the WAF_v2 SKU) and newer, these limits are as follows:

    2MB request body size limit

    4GB file upload limit.

    User's image

    Request Size Limit: This is the maximum size of the request that can be processed by the service. For Azure Front Door and Application Gateway, this is the total size of the request, including headers and body.

    Request Inspection Limit: This refers to the maximum size of the request body that the WAF can inspect for security threats. In the case of Application Gateway, the inspection limits you mentioned (128 KB for CRS 3.1 and 2 MB for CRS 3.2) are specifically for the WAF's ability to analyze the request for potential attacks


    I hope this has been helpful!

    If the above is unclear or you are unsure about something, please add a comment below.

    please don’t forget to close the thread by clicking Accept the answer wherever the information provided helps you, as this can be beneficial to other community members.Accepted answer


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.