289 questions with Azure Web Application Firewall tags

Sort by: Updated
1 answer

Azure FrontDoor (classic) and WAF can not stop brute-attacks! There is no global rate-limit configuration!

Hello, Questions first; Is there any way of configuring FrontDoor/WAF to stop brute-attacks with Global Rate Limit or some other way? If we can not stop brute-attacks via FrontDoor/WAF, then what is Microsoft's offer to apply those logic,…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
602 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
582 questions
Azure Web Application Firewall
asked 2021-09-26T10:20:27.02+00:00
Nuri Engin 31 Reputation points
answered 2021-09-27T18:32:49.767+00:00
ChaitanyaNaykodi-MSFT 23,816 Reputation points Microsoft Employee
1 answer

How to configure WAF v2

Im trying to reach a Onprem Web Service: vm.domain.com:44300/sap/bc/ui2/flp/Launchpad.html?sap-language=es I have my WAF v2 (azure application gateway) and it works, but wehn I try to configure to reach…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-09-21T18:24:25.477+00:00
Rogelio Pérez Antonio 1 Reputation point
answered 2021-09-21T20:07:35.437+00:00
ChaitanyaNaykodi-MSFT 23,816 Reputation points Microsoft Employee
0 answers

WAF for protect onprem website - hosted- website

Good morning. We have many websites hosted on different solutions currently protected by a physical web application firewall onpremise. I would like to dispose this device to use the azure waf to protect all corporate websites and apps, is it…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-09-13T13:48:41.767+00:00
Gianluca Tarq 1 Reputation point
commented 2021-09-13T18:06:25.653+00:00
Alan Kinane 16,796 Reputation points MVP
2 answers

Application Gateway WAF policy and geo location mess

What a mess... So I wanted to add an application gateway with WAF in front of my internal load balancer so it will be accessible from the internet via the app gw public IP and protected with WAF and accessible only from Israel via a geo location…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-08-25T12:45:40.167+00:00
Ori Gil 6 Reputation points
commented 2021-09-09T09:50:09.607+00:00
SaiKishor-MSFT 17,216 Reputation points
1 answer

Azure application gateway (WAF Policy)

If possible could you please give me a quick solution regarding Application Gateway (WAF Policies). i have a scenario like my client given me task about to keep close required URLs (Eg: facebook,net, youtube.com etc) for external use and only…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-08-31T12:42:25.167+00:00
Peela Vinod 1 Reputation point
answered 2021-09-09T09:44:00.53+00:00
SaiKishor-MSFT 17,216 Reputation points
1 answer

Azure App Gateway v2 WAF difference?

I have a v2 sku app gateway with several URLS and back end pools works great. There is a message that says "Upgrade to the WAF tier to increase your app's security." which, "looks" like you simple hit the slider over and then press…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-08-26T20:57:05.307+00:00
Rich Roy 26 Reputation points
answered 2021-08-31T20:19:33.787+00:00
ChaitanyaNaykodi-MSFT 23,816 Reputation points Microsoft Employee
1 answer

What is the best way to pass data to an API through an Azure Application Gateway and WAF and avoid false positives

I have a back-end API that I am sending data to and some data triggers the WAF to BLOCK that should not. I am considering base64 encoding the data but that seems unnecessary. Example payload that fails: { "username":…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-08-19T20:47:32.037+00:00
rex 1 Reputation point
answered 2021-08-26T13:08:52.983+00:00
SaiKishor-MSFT 17,216 Reputation points
1 answer One of the answers was accepted by the question author.

Content Delivery Network WAF Policy

Hi Does Content Delivery Network WAF Policy associated with Microsoft Standard CDN provide protection against Crawlers and scanners. Protect applications from bots If not then is there any document to create custom ruleset for Content…

Azure Content Delivery Network
Azure Web Application Firewall
asked 2021-07-15T02:31:16.573+00:00
azuretechy 21 Reputation points
commented 2021-08-02T06:24:47.91+00:00
GitaraniSharma-MSFT 48,111 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

enable diagnostics on WAF with ARM template

I was looking for enabling diagnostics on WAF for ApplicationGatewayFirewallLog in ARM template, to send them to Log Analytics workspace, however I haven't find any reasonable solution. Could you please advise what is the best way of achieving this?

Azure Web Application Firewall
asked 2021-06-11T19:09:08.427+00:00
Jan Kosmala 121 Reputation points
accepted 2021-07-13T06:59:29.26+00:00
Jan Kosmala 121 Reputation points
1 answer

Connecting VM to apps in a seperate resource group

I need some insight on how to connect a VM in a separate resource group to apps in another resource group that is fire-walled off with a public ip. Is it as simple as creating rules on the firewall to allow inbound traffic from the VM's public IP? or is…

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,318 questions
Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
582 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
85 questions
asked 2021-07-07T13:02:09.39+00:00
Ronald Harvey 1 Reputation point
answered 2021-07-08T00:05:08.447+00:00
Susheel Bhatt 351 Reputation points
1 answer

Azure Web Applicion Gateway and Firewall

This is all a bit confusing. I think I know what I need, but can't figure out pricing. Azure is not very transparent with pricing. This is what I am trying to accomplish. Our application is simply a Web Application that also services API's from…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-05-25T17:10:33.58+00:00
Ben Levy 61 Reputation points
commented 2021-06-15T08:46:57.783+00:00
Sruthi Saranya Karthikeyan 231 Reputation points Microsoft Employee
1 answer

Permit a few sites to operate on Auze VM

We want traffic blocked on our VMs and limited to only a few trusted sites. How to configure / make such a rule. A handful of 10 sites should only open from the internet on the VM and the rest should be all blocked.

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
582 questions
Azure Web Application Firewall
asked 2021-05-28T12:15:33.053+00:00
Akshay Shah 1 Reputation point
answered 2021-06-01T14:00:10.843+00:00
msrini-MSFT 9,261 Reputation points Microsoft Employee
1 answer

Application Gateway Update HTTP_HOST server variable

Hi Team, is it possible to update HTTP_HOTS SERVER variable value in azure application gateway or apache2?

Azure Web Application Firewall
asked 2021-04-30T07:34:13.103+00:00
Mohit Kumar Sharma 86 Reputation points
commented 2021-05-11T12:28:35.187+00:00
GitaraniSharma-MSFT 48,111 Reputation points Microsoft Employee
1 answer

Use Fortigate Nextgent firewall vm to Protect AKS

Hi All, Can help suggestion me for implement following reference solution architecture below? i want to use Application gateway WAF v2 recieve traffic from internat and then snat to Fortogate firewall and dnat to AKS and Web App service. …

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
Azure Kubernetes Service (AKS)
Azure Kubernetes Service (AKS)
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
1,902 questions
asked 2021-04-25T13:49:09.207+00:00
Thanakrit Rungchatkamol 1 Reputation point
answered 2021-05-07T19:45:23.31+00:00
msrini-MSFT 9,261 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Why doesn't the portal UI work for multiple hostnames, and why only 5 hostnames allowed?

The Application Gateway v2 / WAF V2 allows listeners with multiple hostnames, but only using the CLI interface. Why isn't the portal updated to allow this yet? It's fairly fundamental functionality isn't it? Why only 5 hostnames? We have (for…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-04-26T15:36:41.67+00:00
Nigel Morse 191 Reputation points
commented 2021-05-07T11:13:59.583+00:00
Nigel Morse 191 Reputation points
0 answers

tailing slash redirection app service

Hi All, My app service added tailing slash on the URL and re

Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
7,072 questions
asked 2021-04-30T07:31:33.027+00:00
Mohit Kumar Sharma 86 Reputation points
commented 2021-05-05T00:13:11.87+00:00
SaiKishor-MSFT 17,216 Reputation points
1 answer

WAF policy on application gateway to limit access to only few IP ranges ?

Hi All, Would you mind to help me to configure my application gateway with WAF to limit access to one of my web apps. I would like to allow traffic to this web apps from only few IP ranges. Do you have any idea to achieve this requirement Thank…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-04-08T19:52:40.297+00:00
Cloud 2021 1 Reputation point
commented 2021-04-23T14:19:11.837+00:00
suvasara-MSFT 10,016 Reputation points
1 answer

Altough I disable the Rules in the WAF still appears matches to this particular rules.

Since some weeks, althoug I have some rules disable in the Web Application Policies, the logs are still showing matching in this rules. Is this a new behaviour or there is somehting wrong?.

Azure Web Application Firewall
asked 2021-04-09T11:04:23.423+00:00
Alejandro Alcaide Figuero 1 Reputation point
answered 2021-04-16T10:00:41.21+00:00
suvasara-MSFT 10,016 Reputation points
2 answers

Difference between WAF in Application Gateway and WAF Policy assigned to Application Gateway

If I create a new Azure Application Gateway, I can enable Web Application Firewall via the Settings | Web application firewall page. e.g. If I do that, I don't see a separate WAF resource created, and I also don't see a way to do things…

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,207 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
980 questions
Azure Web Application Firewall
asked 2021-04-08T07:14:41.847+00:00
David Gardiner 36 Reputation points MVP
answered 2021-04-14T19:59:58.047+00:00
SaiKishor-MSFT 17,216 Reputation points
2 answers One of the answers was accepted by the question author.

Route API(Hosted on a Azure VM) through App Gateway - WAF || No API Managemennt Service to use

Hi Support team., Use Case : I have Host couple of my API's on a Azure VM and now I want to route the inbound and outbound traffic of Accessing API via. Application Gateway WAF., question for the same are as follows.: Is it possible to achieve…

Azure Web Application Firewall
asked 2021-03-29T10:44:08.117+00:00
Ankit Rathod 371 Reputation points
commented 2021-04-07T19:48:50.72+00:00
SaiKishor-MSFT 17,216 Reputation points