question

Peter-6517 avatar image
1 Vote"
Peter-6517 asked TravisCragg-MSFT answered

SignalR and the WAF in Application Gateway

If I host a Blazor server side website in Azure using an App Service and the Azure SignalR service, and in front of this website there is the Azure Application Gateway. Will the SignalR packages go through the WAF? Plus will the WAF be able to detect any SQL injection attacks by examining the packages, like it can do for normal HTTP requests?

azure-application-gatewayazure-web-application-firewall
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

TravisCragg-MSFT avatar image
0 Votes"
TravisCragg-MSFT answered

Application Gateway does support WebSockets, however the WAF for Application Gateway will typically block it by default. You will likely need to add an exclusion rule to allow the WebSocket connections.

These rules will not be checked for SQL Injection attacks, so you might need additional protection in your application.



5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.