Content Delivery Network WAF Policy

azuretechy 21 Reputation points
2021-07-15T02:31:16.573+00:00

Hi

Does Content Delivery Network WAF Policy associated with Microsoft Standard CDN provide protection against

  1. Crawlers and scanners.
  2. Protect applications from bots

If not then is there any document to create custom ruleset for Content Delivery Network WAF Policy?

Regards
AT

Azure Content Delivery Network
Azure Web Application Firewall
0 comments No comments
{count} votes

Accepted answer
  1. GitaraniSharma-MSFT 47,011 Reputation points Microsoft Employee
    2021-07-19T13:19:06.597+00:00

    Hello @azuretechy ,

    Apologies for the delay in response.

    Content Delivery Network WAF Policy associated with Microsoft Standard CDN doesn't provide protection against crawlers, scanners & bots.
    WAF on Azure CDN from Microsoft is currently in public preview and is provided with a preview service level agreement. Certain features may not be supported or may have constrained capabilities.
    The Azure managed Default Rule Set includes rules against a few threat categories as mentioned in the below link:
    https://learn.microsoft.com/en-us/azure/web-application-firewall/cdn/cdn-overview#azure-managed-rule-sets
    The version number of the Default Rule Set increments when new attack signatures are added to the rule set.

    There is a separate bot manager ruleset available in Azure Front Door Premium SKU but it is not available for Azure CDN at the moment. Since WAF on Azure CDN from Microsoft is currently in public preview, the feature for Bot ruleset may be added once it goes GA. If you need specific feature/capabilty, you can feel free to share your feedback in the below forum requesting this feature. All the feedback you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Azure.
    https://feedback.azure.com/forums/217313-networking?category_id=345019

    Azure CDN WAF policy have the possibility of adding custom rules but they only include match rules and rate control rules with capabilities mentioned in the below link:
    https://learn.microsoft.com/en-us/azure/web-application-firewall/cdn/cdn-overview#custom-rules
    https://learn.microsoft.com/en-us/azure/web-application-firewall/cdn/waf-cdn-create-portal#custom-rules

    Kindly let us know if the above helps or you need further assistance on this issue.

    ----------------------------------------------------------------------------------------------------------------

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful