362 questions with Azure Web Application Firewall tags

Sort by: Updated
1 answer

going with the application gateway in fornt of azure firewall does it lose the benefit of l7 load balancing

I have an Azure firewall in a hub and spoke architecture, and one of the spokes contains my web servers, for HTTPS filtering I have an application gateway with the WAF feature and l7 load balancing. I have a requirement to keep centralized security…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
781 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
Azure Load Balancer
Azure Load Balancer
An Azure service that delivers high availability and network performance to applications.
506 questions
asked 2024-09-23T06:26:52.93+00:00
Mohammad Nemer 0 Reputation points
answered 2024-09-23T10:20:18.8833333+00:00
KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
0 answers

WAF 2 does not prevent script attack

I have integrated a web application firewall (2) with the application gateway in Prevention mode. However, when I attempt to create a record using FirstName as script tag, the record is successfully created. Ideally, this action should be blocked.…

Azure Web Application Firewall
asked 2024-09-06T09:54:45.77+00:00
Avinash Davkhar 75 Reputation points
commented 2024-09-16T01:47:28.6733333+00:00
Sai Prasanna Sinde 6,645 Reputation points Microsoft External Staff Moderator
1 answer

Request blocked by Microsoft_DefaultRuleSet-2.1-SQLI-942120 for russian language

When we try to submit the leads in our website We figured out that for Russian language characters Azure Front door firewall rule(942120 - SQL Injection Attack: SQL Operator Detected) was blocking the requests. Below is the screenshot of how we find it…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
858 questions
Azure Web Application Firewall
asked 2024-09-13T12:40:48.4533333+00:00
Mohideen Ansari 0 Reputation points
answered 2024-09-13T19:49:39.2666667+00:00
ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
1 answer One of the answers was accepted by the question author.

How to fix blocked:mixed-content error on Application Gateway?

I have configured an application gateway associated to a WAF with my app service, the goal was to use WAF in front of my app; the issue now is that I dont have custom domain for my application gateway or app service. Earlier I was using default domain of…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,970 questions
asked 2024-09-04T07:21:43.22+00:00
Najam ul Saqib 400 Reputation points
accepted 2024-09-09T09:31:21.6366667+00:00
Najam ul Saqib 400 Reputation points
1 answer One of the answers was accepted by the question author.

Is it possible to use .azurewebsites.net domain with application gateway?

Hi, I have integrated azure app gateway with my app service to have WAF in front of my web app. I see that I have app gateway's IP address via which I can access the app service, is there any possibility that I use the default domain of web app even with…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
8,970 questions
asked 2024-09-03T07:22:42.4266667+00:00
Najam ul Saqib 400 Reputation points
accepted 2024-09-09T08:04:01.9766667+00:00
Najam ul Saqib 400 Reputation points
1 answer

Azure NSG rules both for both public and private IPs

Can I apply a public IP to a vm and have it not affect the nsg rules that I have for it's private IPs? I have current nsg rules for the private IP but i want to add a public IP and apply nsg rules to it as well. I will be limiting access to it from…

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,775 questions
Azure Web Application Firewall
asked 2024-08-29T21:57:05.1766667+00:00
Jose Cintron 60 Reputation points
answered 2024-08-30T05:36:13.0666667+00:00
rvinnakota 4,760 Reputation points Moderator
0 answers

Azure WAF rule 920470 blocking the requests with details massage: Pattern match ^[\w\d/\.\-\+]+(?:\s?;\s?(?:boundary|charset)\s?=\s?['"\w\d\.\-]+)?$ at REQUEST_HEADERS:content-type. But we excluded the rule like in the below snip still the rule blocking

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
asked 2024-08-01T12:50:03.74+00:00
Chandu 0 Reputation points
commented 2024-08-30T00:51:31.9933333+00:00
ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
0 answers

Azure WAF Security Features in Standard Tier with Front Door

Hey all - I’m looking for insights regarding the security features offered by the Azure WAF when deployed in the Standard tier with Azure FD, particularly in scenarios where the customer does not want to create any custom rules. Given that the Microsoft…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
858 questions
Azure Web Application Firewall
asked 2024-08-20T04:53:06.4433333+00:00
Bhushan Gawale 331 Reputation points MVP
commented 2024-08-26T09:38:44.1533333+00:00
KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
1 answer One of the answers was accepted by the question author.

How to add correct exclusion on Azure WAF?

Greetings. Please help in creating an exception to the rule: OWASP_3.2 - Possible Remote File Inclusion (RFI) Attack: Off-Domain Reference/Link. My web application generates requests like: …

Azure Web Application Firewall
asked 2024-05-13T11:59:44.36+00:00
Yurii Tsarienko 20 Reputation points
commented 2024-08-26T03:33:39.46+00:00
KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
0 answers

WAF rule - 100200 Malicious bots that have falsified their identity

How often is the list of Google IPs updated to avoid false positives in WAF rule '100200 Malicious bots that have falsified their identity'?

Azure Web Application Firewall
asked 2024-07-24T11:39:13.0333333+00:00
Andrius Vasiliauskas 20 Reputation points
commented 2024-08-22T06:47:06.2833333+00:00
Andrius Vasiliauskas 20 Reputation points
1 answer

Azure AG WAF file upload

We need to upload a file with size is about 100MB and got blocked by Application Gateway WAF, we use the "file upload" method which is described here:…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
asked 2024-08-13T09:29:17.3966667+00:00
Liang, Gene 0 Reputation points
answered 2024-08-16T15:43:08.5233333+00:00
ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
1 answer

Protocol and Port ranges for allow Logic Apps IP

We got the notification about the Logc Apps IP addresses that will need updating by Nov 12th. It doesn't specify any protocol or port ranges on the required IPs that need to be added. Can anyone clarify for me if they have to be any/any or we can limit…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
781 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
97 questions
asked 2024-08-13T19:58:22.3966667+00:00
Shaun M 0 Reputation points
answered 2024-08-13T22:05:24.44+00:00
ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
1 answer

Getting 403 forbidden error when enabling OWASP 3.2 and Enforce request body inspection limit

There is one function in my web site to download the documents also i have 182 rules Enabled in prevention (Mode)

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
Azure | Azure ISV (Independent Software Vendor) and Startups
asked 2024-08-09T06:36:56.9+00:00
Umang Raichura 0 Reputation points
answered 2024-08-09T07:40:48.3366667+00:00
Abiola Akinbade 29,490 Reputation points Volunteer Moderator
1 answer One of the answers was accepted by the question author.

Azure WAF exclusion does not work for Request Cookie Keys

Hi, I have created exclusion in WAF policy for Application Gateway. This exclusion works when I set "matchVariable = Request Cookie Keys" and does not work if I set "matchVariable = Request Cookie Names". I understood that Names and…

Azure Web Application Firewall
asked 2024-04-11T08:51:29.7066667+00:00
Konstantin Kostin 20 Reputation points
edited a comment 2024-08-06T11:47:52.18+00:00
Jarno Leikas 30 Reputation points
1 answer One of the answers was accepted by the question author.

Setting up Azure Function App with Azure Application Gateway (WAF)

Hello! I am currently trying to setup an Azure function application that will be accessed through an Application Gateway that restricts the network level access using the Azure WAF. I want to restrict the network level access by geographical location…

Azure Functions
Azure Functions
An Azure service that provides an event-driven serverless compute platform.
5,936 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
asked 2024-08-05T07:07:02.6833333+00:00
tevin.sales 40 Reputation points
accepted 2024-08-06T04:48:28.53+00:00
tevin.sales 40 Reputation points
0 answers

Azure OpenAi with private endpoints - Web App issue

I am currently experiencing issues after deploying an AI module into a web app. My Azure OpenAI setup includes private endpoints. The web app was tested with both public access and private endpoints. While I can view the chat box and send prompts, I…

Azure Private Link
Azure Private Link
An Azure service that provides private connectivity from a virtual network to Azure platform as a service, customer-owned, or Microsoft partner services.
550 questions
Azure Web Application Firewall
Azure OpenAI Service
Azure OpenAI Service
An Azure service that provides access to OpenAI’s GPT-3 models with enterprise capabilities.
4,101 questions
asked 2024-07-25T02:32:33.1866667+00:00
Nedda Marhoon 6 Reputation points
commented 2024-08-02T10:54:02.3066667+00:00
KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
1 answer

In azure front door WAF policy i ahve created a custom rules with conditions to block the request for particular url based on country(Geo location). It is working as expected but i would like to know accuracy of the waf policy when using geo location

We have azure front door integrated with WAF policy. i have created a custom rules with conditions to block the request for particular url to specific country(Geo location). It is working as expected but i would like to know accuracy of the waf policy…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
858 questions
Azure Web Application Firewall
asked 2024-07-25T13:26:55.0733333+00:00
Mohideen Ansari 0 Reputation points
commented 2024-08-01T01:28:04.6266667+00:00
ChaitanyaNaykodi-MSFT 27,481 Reputation points Microsoft Employee Moderator
0 answers

so F5 awaf? how can I test the deployment without altering the infrastructure?

Hi, I'd like to deploy the F5 A WAF, but I would like to test it without risking or causing any issues. Any ideas?

Azure Web Application Firewall
asked 2024-07-30T19:56:50.7833333+00:00
Ibis N. Torres Santos 0 Reputation points
commented 2024-07-30T20:58:12.4833333+00:00
hossein jalilian 11,055 Reputation points Volunteer Moderator
0 answers

Update Azure application gateway WAF rules to allow request from same ip range in short span

I have a web app hosted on AKS behind an Application Gateway with WAF. My domain is onboarded on Cloudflare. The WAF is blocking network calls to my web app with rule ID 949110. I suspect that Cloudflare is replacing the actual client IP with its own and…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,217 questions
Azure Web Application Firewall
asked 2024-07-24T06:05:22.67+00:00
Anonymous
commented 2024-07-25T09:31:46.5333333+00:00
KapilAnanth-MSFT 49,616 Reputation points Microsoft Employee Moderator
0 answers

Can we add ruleId to the request header

Azure Gateway WAF - we want to add ruleId to every request header

Azure Web Application Firewall
asked 2024-07-22T16:37:44.72+00:00
Salagame, Raghavendra 1 Reputation point
commented 2024-07-24T02:44:28.9333333+00:00
Salagame, Raghavendra 1 Reputation point