Content
Azure Application Gateway 502 Errors - No IP Address Resolved
I am trying to setup azure application gateway connected to an azure static web site, both using https. I can connect to the backend static website successfully using https. I have everything configured as well as I can tell but when I access the…


WAF Allowed IP restriction with Application Gateway
Hi Team, We are using Azure Application Gateway V2 with WAF and we came across the Warning in the WAF Custom policy that, it can only allow 600 Ips in one custom rule. So I am having a few questions on this, please help with it. Is there any such…


how to implement appgateway with apim (custom domain and ssl root certificate) using bicep
Hello, I am new to the apim and app gateway concepts, could you pleae help me in automating the appgateway with apim (custom domain and ssl root certificate)using bicep code or terraform.
Create inbound SNAT Rule
Is there a way to configure a inbound source NAT rule with some azure service like Azure Load Balancer or similar? Public IP addr. -> Private IP addr. -> virtual Machine. So that the packets arriving at the Virtual Maschine do have the private…


Azure Web Application Firewall (WAF) REGEX for Match Variable Selector
Hi Experts, We are trying to migrate our WAF solution to Azure WAF, and some validation rules use REGEX to match the Variable Selector. We are trying to implement the same on Azure WAF and are not sure if that is supported. The Azure Application Gateway…


API Management root ca invalid using keyvault certificate through ARM but valid manually uploaded
Hi All, I have an issue with APIM and root ca. my APIM connects to appgateway over HTTPS using a self-signed certificate in my dev environment. APIM has a root ca selfsigned.mydomain.co.uk uploaded through the portal and a client certificate referencing…


DDoS Protection of azure services with Application gateway
Hi, I want to protect my app services and other azure services from DDoS attack, for this I wanted to implement DDoS Network Protection with PaaS web application architecture…


Application Gateway Pricing v2
Hello Team, I hope you're doing fine, I have a question about Azure application Gateway v2 Pricing, For the fixed model, the pricing will be an addition of the application gatreway Pricing + the WAF pricing ? Which means it will cost 0.728$ per…


How to remove WAF policy safely.We have an AKAMAI device before the App GW and do not need WAF capability anymore.What is the safest way to do so.
How to remove WAF policy safely or disassociate WAF policy . We have an AKAMAI device before the App GW in our environment hence we do not need WAF capability anymore. What is the safest way to do so. Also can I do it via portal and if I am doing it via…


How to get list of failed requests on Ingress application gateway in AKS
There are continues alert of failed request on ingress app gateway, but unable to track down to the resource causing for failed requests. These alerts are from AKS app gateway. Help me on it. Backend health of app gateway is verified and all are active,…
Geo-location policy in WAF blocks wrong address
We use application gateway with app gateway WAF policy enabled. A custom policy is the geo-location filter, which is blocking everything not originating from white-listed countries. It's been working for years, today it suddenly started blocking our…


Why Azure Application Gateway drops dashes between transactionId and x-appgw-trace-id
The Application Gateway docs state that (source): X-appgw-trace-id is a unique guid generated by application gateway for each client request and presented in the forwarded request to the backend pool member. The guid consists of 32 alphanumeric…


App Gateway, ASEv3 and 2 or more app services with custom domain
Hello All, I am trying to build an App Service Environment with an Application Gateway in front. The ASE is set up with iLB. I want the ASE to host between 2 and 4 App Services with the same Custom Domain. Each App Service will host it's own…


App gateway v2 - unable to remove Server response header with response code 501
I'm having vulnerability when getting response with http code 501. I'm getting the server field in the headers: "Server" key, value "Microsoft-Azure-Application-Gateway/v2" And also I'm using Azure Application Gateway v2 to use…


Redirect Public IP to FQDN Azure App Gateway over https
Hello, I am trying to redirect traffic from public ip to FQDN in Azure over https. I am using a public endpoint to accept traffic and an application gateway to route to backend. I can visit https://mysite.com and all works well. However, I am still able…


How do I add client IP to HTTP logs for Azure App Service sitting behind an Application Gateway
I have an App Service sitting behind an Application Gateway. It is configured to write web logs to both Storage and Analytics. However, the CIp field in these logs only appears to show the internal IPs of the gateway. Not the real client IPs. This makes…


Azure Application gateway pointing to 1 VM with websites on different Ports (8080, 8081)
I have a linux VM that uses Docker to host multiple iterations of a site. Which are loaded all on different ports. Each client would need to access a url that points to a specific port How can that be done in 1 application gateway I currently have all…


What is the correct way to set up a multi tenant app service with custom domain behind an application gateway with path-based routing?
Hello, I have an app service plan with several apps which are currently accessed through an AGW using path-based routing in the following way: mydomain.com -> root.azurewebsites.net mydomain.com/foo -> foo.azurewebsites.net mydomain.com/bar ->…


Application Gateway, Unable to fetch backend data in frontend application
I have deployed with diagram This is all going well in the local azure vnet. When use application gateway to public FE to internet, i can show FE with IP public of App GW, but i can't login from FE, check F12 see request URL is private ip ...


Website Hosted on Azure || L7 Protection
We are looking to migrate a website to Azure and protect from DDoS and Layer 7 attacks. Moreover, and since the website will be accessed globally, we are looking to take advantage of an SDN Solution. As a result, I guess that Azure Front Door will be the…

