310 questions with Azure Web Application Firewall tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

How to add correct exclusion on Azure WAF?

Greetings. Please help in creating an exception to the rule: OWASP_3.2 - Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link. My web application generates requests like: …

Azure Web Application Firewall
asked 2024-05-13T11:59:44.36+00:00
Yurii Tsarienko 20 Reputation points
commented 2024-08-23T03:14:04.51+00:00
Nayot Tientong 0 Reputation points
0 answers

WAF rule - 100200 Malicious bots that have falsified their identity

How often is the list of Google IPs updated to avoid false positives in WAF rule '100200 Malicious bots that have falsified their identity'?

Azure Web Application Firewall
asked 2024-07-24T11:39:13.0333333+00:00
Andrius Vasiliauskas 0 Reputation points
commented 2024-08-22T06:47:06.2833333+00:00
Andrius Vasiliauskas 0 Reputation points
0 answers

Azure Web Application and ChatPlayground giving different responses?

Hi, I am working on Azure AI Search. I want to use Web Application/Chat Playground for Q/A from bunch of documents at a time. I have created azure ai search service with Basic tier package for West US Region. After this, I created skillset using Text…

Azure AI Search
Azure AI Search
An Azure search service with built-in artificial intelligence capabilities that enrich information to help identify and explore relevant content at scale.
919 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,557 questions
asked 2024-08-21T05:45:08.8133333+00:00
Tanuj Verma 0 Reputation points
0 answers

Azure WAF Security Features in Standard Tier with Front Door

Hey all - I’m looking for insights regarding the security features offered by the Azure WAF when deployed in the Standard tier with Azure FD, particularly in scenarios where the customer does not want to create any custom rules. Given that the Microsoft…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
651 questions
Azure Web Application Firewall
asked 2024-08-20T04:53:06.4433333+00:00
Bhushan Gawale 316 Reputation points
commented 2024-08-20T10:36:35.13+00:00
Bhushan Gawale 316 Reputation points
0 answers

Azure AG WAF file upload

We need to upload a file with size is about 100MB and got blocked by Application Gateway WAF, we use the "file upload" method which is described here:…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-08-13T09:29:17.3966667+00:00
Liang, Gene 0 Reputation points
commented 2024-08-16T15:43:08.5233333+00:00
ChaitanyaNaykodi-MSFT 25,371 Reputation points Microsoft Employee
1 answer

Protocol and Port ranges for allow Logic Apps IP

We got the notification about the Logc Apps IP addresses that will need updating by Nov 12th. It doesn't specify any protocol or port ranges on the required IPs that need to be added. Can anyone clarify for me if they have to be any/any or we can limit…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
636 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
90 questions
asked 2024-08-13T19:58:22.3966667+00:00
Shaun M 0 Reputation points
answered 2024-08-13T22:05:24.44+00:00
ChaitanyaNaykodi-MSFT 25,371 Reputation points Microsoft Employee
0 answers

Getting 403 forbidden error when enabling OWASP 3.2 and Enforce request body inspection limit

There is one function in my web site to download the documents also i have 182 rules Enabled in prevention (Mode)

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
Azure ISV (Independent Software Vendors) and Startups
Azure ISV (Independent Software Vendors) and Startups
Azure: A cloud computing platform and infrastructure for building, deploying and managing applications and services through a worldwide network of Microsoft-managed datacenters.ISV (Independent Software Vendors) and Startups: A Microsoft program that helps customers adopt Microsoft Cloud solutions and drive user adoption.
92 questions
asked 2024-08-09T06:36:56.9+00:00
Umang Raichura 0 Reputation points
commented 2024-08-13T05:00:41.3866667+00:00
KapilAnanth-MSFT 43,221 Reputation points Microsoft Employee
2 answers

How do I configure the Azure Application Gateway / backend pool to drop requests that are blocked by the WAF as the log file indicate the request was blocked but the script ends up in the database.

requests blocked by the WAF are being forwarded to the backend API servers. How do you configure the backend pool or WAF to drop requests that are blocked by the WAF.

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-05-16T08:21:12.23+00:00
Derek Green 5 Reputation points
answered 2024-08-07T13:41:46.8133333+00:00
Jimmy Mattsson 0 Reputation points
1 answer One of the answers was accepted by the question author.

Azure WAF exclusion does not work for Request Cookie Keys

Hi, I have created exclusion in WAF policy for Application Gateway. This exclusion works when I set "matchVariable = Request Cookie Keys" and does not work if I set "matchVariable = Request Cookie Names". I understood that Names and…

Azure Web Application Firewall
asked 2024-04-11T08:51:29.7066667+00:00
Konstantin Kostin 20 Reputation points
edited a comment 2024-08-06T11:47:52.18+00:00
Jarno Leikas 20 Reputation points
1 answer One of the answers was accepted by the question author.

Setting up Azure Function App with Azure Application Gateway (WAF)

Hello! I am currently trying to setup an Azure function application that will be accessed through an Application Gateway that restricts the network level access using the Azure WAF. I want to restrict the network level access by geographical location…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
4,814 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-08-05T07:07:02.6833333+00:00
tevin.sales 40 Reputation points
accepted 2024-08-06T04:48:28.53+00:00
tevin.sales 40 Reputation points
1 answer

How to preserve the Client IP that is amended by Azure Front Door, another amendment by App Gateway before reaching Azure APIM

Hi, My setup is configured with Azure Front Door + Azure WAF --> Azure App Gateway + WAF --> Azure API Management. The diagnostic data logs are kept with Azure Monitor. I am trying to configure in bound throttling policy on APIM to rate limit user…

Azure API Management
Azure API Management
An Azure service that provides a hybrid, multi-cloud management platform for APIs.
2,034 questions
Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
651 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-07-16T00:28:41.8333333+00:00
Bi Tan 0 Reputation points
edited an answer 2024-08-06T00:28:45.8066667+00:00
ChaitanyaNaykodi-MSFT 25,371 Reputation points Microsoft Employee
0 answers

Azure WAF rule 920470 blocking the requests with details massage: Pattern match ^[\w\d/\.\-\+]+(?:\s?;\s?(?:boundary|charset)\s?=\s?['"\w\d\.\-]+)?$ at REQUEST_HEADERS:content-type. But we excluded the rule like in the below snip still the rule blocking

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-08-01T12:50:03.74+00:00
Chandu 0 Reputation points
commented 2024-08-05T10:51:18.0466667+00:00
Chandu 0 Reputation points
0 answers

Azure OpenAi with private endpoints - Web App issue

I am currently experiencing issues after deploying an AI module into a web app. My Azure OpenAI setup includes private endpoints. The web app was tested with both public access and private endpoints. While I can view the chat box and send prompts, I…

Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
502 questions
Azure Web Application Firewall
Azure OpenAI Service
Azure OpenAI Service
An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
2,807 questions
asked 2024-07-25T02:32:33.1866667+00:00
Nedda Marhoon 6 Reputation points
commented 2024-08-02T10:54:02.3066667+00:00
KapilAnanth-MSFT 43,221 Reputation points Microsoft Employee
1 answer

In azure front door WAF policy i ahve created a custom rules with conditions to block the request for particular url based on country(Geo location). It is working as expected but i would like to know accuracy of the waf policy when using geo location

We have azure front door integrated with WAF policy. i have created a custom rules with conditions to block the request for particular url to specific country(Geo location). It is working as expected but i would like to know accuracy of the waf policy…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
651 questions
Azure Web Application Firewall
asked 2024-07-25T13:26:55.0733333+00:00
Mohideen Ansari 0 Reputation points
commented 2024-08-01T01:28:04.6266667+00:00
ChaitanyaNaykodi-MSFT 25,371 Reputation points Microsoft Employee
0 answers

so F5 awaf? how can I test the deployment without altering the infrastructure?

Hi, I'd like to deploy the F5 A WAF, but I would like to test it without risking or causing any issues. Any ideas?

Azure Web Application Firewall
asked 2024-07-30T19:56:50.7833333+00:00
Ibis N. Torres Santos 0 Reputation points
commented 2024-07-30T20:58:12.4833333+00:00
hossein jalilian 6,190 Reputation points
0 answers

Update Azure application gateway WAF rules to allow request from same ip range in short span

I have a web app hosted on AKS behind an Application Gateway with WAF. My domain is onboarded on Cloudflare. The WAF is blocking network calls to my web app with rule ID 949110. I suspect that Cloudflare is replacing the actual client IP with its own and…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,035 questions
Azure Web Application Firewall
asked 2024-07-24T06:05:22.67+00:00
Prashanth Nagaraj 0 Reputation points
commented 2024-07-25T09:31:46.5333333+00:00
KapilAnanth-MSFT 43,221 Reputation points Microsoft Employee
0 answers

Can we add ruleId to the request header

Azure Gateway WAF - we want to add ruleId to every request header

Azure Web Application Firewall
asked 2024-07-22T16:37:44.72+00:00
Salagame, Raghavendra 1 Reputation point
commented 2024-07-24T02:44:28.9333333+00:00
Salagame, Raghavendra 1 Reputation point
2 answers

Best Methods for Diagnosing Azure Hosted Web App Communication Issues by Adjusting or Disabling Firewall Settings

Hi community, For a web app on Azure constructed using various Azure services, the design typically blocks a lot of communication for security reasons. However, to diagnose issues, it's necessary to allow inbound and outbound communication. I am…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
636 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
90 questions
asked 2024-07-21T13:16:22.1833333+00:00
KindCompute-6524 85 Reputation points
commented 2024-07-23T08:24:58.2366667+00:00
KapilAnanth-MSFT 43,221 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

new Ubuntu deployed today, still had old openssh-server, will Azure update the base container? CVE-2006-5051

I deployed a new Ubuntu 24.04 this morning. This base image right from Azure still has OpenSSH 9.6 (SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.4), isn't that a problem? CVE-2006-5051 How many Azure containers are at risk if they were installed and not…

Azure Web Application Firewall
asked 2024-07-19T15:14:43.8766667+00:00
Paul Bent 20 Reputation points
commented 2024-07-20T03:02:25.7266667+00:00
Paul Bent 20 Reputation points
1 answer

Customize Managed Rules

Hi, I am using Application gateway with WAF V2, I am facing one issue with a user input being blocked by WAF managed rules. The backend application allows user to special characters but the request is getting blocked by WAF only. More specifically, if…

Azure Web Application Firewall
asked 2024-07-16T10:03:37.0533333+00:00
Satyam Chauhan 547 Reputation points
answered 2024-07-16T10:57:28.4766667+00:00
KapilAnanth-MSFT 43,221 Reputation points Microsoft Employee