Front Door Standard/Premium with geo-filtering
This template deploys a Front Door Standard/Premium with a geo-filtering policy.
Sample overview and deployed resources
This sample template creates a Front Door profile with a geo-filtering policy. To keep the sample simple, Front Door is configured to direct traffic to a static website configured as an origin, but this could be any origin supported by Front Door.
The following resources are deployed as part of the solution:
Front Door Standard/Premium
- Front Door profile, endpoint, origin group, origin, and route to direct traffic to the static website.
- Note that you can use either the standard or premium Front Door SKU for this sample. The geo-filtering custom rule for the WAF are supported in either SKU (note that managed rule sets require the premium SKU though). By default, the standard SKU is used.
- Front Door WAF policy with a custom geo-filtering rule. By default this is configured to allow requests from the United States, Australia, and New Zealand, as well as 'Unknown'.
- You must specify the list of allowed country codes using ISO 3166-1 alpha-2 format. See here for a list of country codes. All requests from outside the specified list of countries will be blocked.
- Use country code
ZZ
to allow requests from IP addresses that haven't been associated with a country (i.e. the 'Unknown' country).
- Front Door security policy to attach the WAF policy to the Front Door endpoint.
Deployment steps
You can click the "deploy to Azure" button at the beginning of this document or follow the instructions for command line deployment using the scripts in the root of this repo.
Usage
Connect
Once you have deployed the Azure Resource Manager template, wait a few minutes before you attempt to access your Front Door endpoint to allow time for Front Door to propagate the settings throughout its network.
You can then access the Front Door endpoint. The hostname is emitted as an output from the deployment - the output is named frontDoorEndpointHostName
. If you access the base hostname you should see a page saying Welcome. If you see a different error page, wait a few minutes and try again.
As long as you are making requests from IP addresses within the specified country, your request will succeed.
Tags: Microsoft.Cdn/profiles, Microsoft.Cdn/profiles/afdEndpoints, Microsoft.Cdn/profiles/originGroups, Microsoft.Cdn/profiles/originGroups/origins, Microsoft.Cdn/profiles/afdEndpoints/routes, Microsoft.Network/FrontDoorWebApplicationFirewallPolicies, Microsoft.Cdn/profiles/securityPolicies