286 questions with Azure Web Application Firewall tags

Sort by: Updated
2 answers One of the answers was accepted by the question author.

Azure Web Application Firewal and special characters

Hello Q&A, I`m having issues adding special characters such as À à È è to the WAF exclusion lists. Getting the following error message.

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
asked 2021-01-08T11:38:52.28+00:00
Nibbler 616 Reputation points
accepted 2021-01-20T13:24:11.753+00:00
Nibbler 616 Reputation points
1 answer

Web Application Firewall - Log on blocked IPs

Im want to see the amount of blocked IPs and how many requests each have made from the logs on the Application Gateway + Web Application Firewall. I have custom rules use, geo-blocking and IP blocking. But would expect these IP`s being blocked by the…

Azure Web Application Firewall
asked 2021-01-17T13:15:54.71+00:00
Nibbler 616 Reputation points
commented 2021-01-20T07:35:36.493+00:00
Nibbler 616 Reputation points
2 answers One of the answers was accepted by the question author.

Domain Limits

I have 2 IIS servers on Azure that present content based on the domain name. 280 domains are pointed to it at the moment on our current WAF solution. Looking at the App Gateway WAF v2 but I'm not sure if it can support all the domain names. For SSL I…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
asked 2021-01-05T22:58:19.323+00:00
Danny Chrismas 71 Reputation points
answered 2021-01-19T20:11:49.417+00:00
Mubarak Tanseer 1 Reputation point Microsoft Employee
4 answers One of the answers was accepted by the question author.

Azure Web Applicaiton Firewall CDN Logs?

I have implemented WAF with CDN. The WAF is blocking more than it should. I was wondering where I can find/enable the logs for it to see what rule is blocking my requests? I know there is a logs section in AFD where I view this information but I…

Azure Content Delivery Network
Azure Web Application Firewall
asked 2020-12-22T20:04:59.29+00:00
Jayson Truong 21 Reputation points
commented 2021-01-06T11:47:31.54+00:00
SUNOJ KUMAR YELURU 13,956 Reputation points MVP
1 answer One of the answers was accepted by the question author.

How to setup DNS to my azure Cloud

I've owned a domain Siera.xyz and went to a domain provider and changed the DNS to point to Azure records. Coming back to azure and setup the domain siera.xyz to point to the local web VM but when I nslookup and browse the URL siera.xyz it didn't…

Azure DNS
Azure DNS
An Azure service that enables hosting Domain Name System (DNS) domains in Azure.
603 questions
Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,255 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
asked 2020-12-08T08:53:15.167+00:00
SieraLight 96 Reputation points
commented 2020-12-18T18:24:55.017+00:00
SaiKishor-MSFT 17,206 Reputation points
3 answers

Does Front Door WAF Exclusions work with POST body arguments?

I'm trying to exclude a body post argument from triggering a default set rule - https://learn.microsoft.com/en-us/azure/web-application-firewall/afds/waf-front-door-exclusion In the form, the input name is "content". I've setup an exclusion…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
594 questions
Azure Web Application Firewall
asked 2020-07-26T09:39:25.24+00:00
Praemon 131 Reputation points
answered 2020-12-15T18:26:14.497+00:00
Ruth, Jason 1 Reputation point
1 answer

Fearture differences of WAF in CDN, Frontdoor and Application gateway

I cannot find a good feature comparison between the WAF's that can be set up in Application Gateway (v1 and v2 AND its different states - 1, 2 and 3), Frontdoor and CDN. Features like, rate limiting, bot detection, geo blocking, etc. Also if I…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
594 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Content Delivery Network
Azure Web Application Firewall
asked 2020-10-28T08:26:04.587+00:00
Owin Gruters - iO 46 Reputation points
commented 2020-12-04T09:29:26.357+00:00
suvasara-MSFT 10,011 Reputation points
1 answer

WAFv2 Supporting TLS 1.3 for Lucky13 Vulnerability Fix

Hi Team, Need urgent help with documentation regarding fixing of Lucky-13 Vulnerability [CVE-2013-0169] raised for Azure WAFv2 which is impacting Go-Live for Customer. As per the recommendation, it requires TLS 1.3 to fix but WAF v2 does not support…

Azure Web Application Firewall
asked 2020-10-29T15:52:49.757+00:00
Girish Namala 1 Reputation point
commented 2020-12-04T09:28:45.01+00:00
suvasara-MSFT 10,011 Reputation points
1 answer

Securing Single Web App.

I currently have a single Web App and Durable Functions, 2 VMs and 1 Azure SQL Database and 1 Cosmos DB. I wanted to know what is the best approach to secure the Web App. I have read WAF, or WAF with Application Gateway or Front Door. I would need…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
594 questions
Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,214 questions
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
6,997 questions
asked 2020-11-22T11:51:38.713+00:00
Kman 41 Reputation points
commented 2020-11-23T20:39:34.313+00:00
ajkuma 22,766 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Secure Power BI Web App

We have installed PowerBI Gateway in our VM which is secured by firewall. The PowerBI Web Interface will be accessed by an external vendor, and the data to the PowerBI will be served by the external vendor. In other words, PowerBI in one domain will be…

Azure Web Application Firewall
asked 2020-10-24T23:17:25.723+00:00
Prasenna Kannan 436 Reputation points
accepted 2020-10-28T06:09:28.797+00:00
Prasenna Kannan 436 Reputation points
1 answer One of the answers was accepted by the question author.

Builtin Azure Service that automatically updates the attack signature heuristically ?

Hi Experts, We have the need to secure the Application Gateway and hundreds of API exposed to the Internet as part of our production environment, Using the existing builtin, Azure services, How to make it secure from Unknown Threat or 0-day attack…

Azure Firewall
Azure Firewall
An Azure network security service that is used to protect Azure Virtual Network resources.
581 questions
Azure Web Application Firewall
Azure Firewall Manager
Azure Firewall Manager
An Azure service that provides central network security policy and route management for globally distributed, software-defined perimeters.
85 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,214 questions
asked 2020-09-15T04:39:31.373+00:00
EnterpriseArchitect 4,866 Reputation points
commented 2020-10-06T05:32:04.21+00:00
GitaraniSharma-MSFT 48,011 Reputation points Microsoft Employee
2 answers One of the answers was accepted by the question author.

Protecting a webapp within a Standard App Service plan, using a virtual firewall appliance, rather than an Application Gateway

We have a webapp (a REST API service) that is sitting in a S1 App Service plan. We are protecting the webapp with a WAF policy assigned to a listener on an Application Gateway v2. The WAF policy only protects this one webapp. We have run into a…

Azure Virtual Network
Azure Virtual Network
An Azure networking service that is used to provision private networks and optionally to connect to on-premises datacenters.
2,198 questions
Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
6,997 questions
asked 2020-08-13T22:15:27.957+00:00
Rhett Blach 46 Reputation points
accepted 2020-09-28T01:49:16.893+00:00
Rhett Blach 46 Reputation points
1 answer

WAF Policy

Just starting to learn about WAF policies. If I add a listener to the WAF policy, do I need to remove that same listener from list in the WAF itself? Or does the WAF policy override any basic config within the WAF? Thanks!

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
asked 2020-09-22T18:55:42.193+00:00
Lily 41 Reputation points
commented 2020-09-23T19:13:47.5+00:00
Lily 41 Reputation points
2 answers

Application Gateway and Geo Location Setup

Hey MS world, Our Goal is to restrict access to our Web Application by Country. Basically deny all, and allow access to ONE country. Everything worked great utilizing NSG group with and Dev Team to restrict access and attacks. We installed the…

Azure Web Application Firewall
asked 2020-07-19T08:34:50.33+00:00
Danejahtt 1 Reputation point
answered 2020-09-12T11:56:20.79+00:00
Manish Jha 236 Reputation points
1 answer One of the answers was accepted by the question author.

Vulnerability scan shows "HSTS Missing From HTTPS Server" on some ports, despite HTTPS Only option.

Hello, I have deployed a Web Application - based on a linux container. I have purchased SSL certificate from Azure and added it successfully to the app. The SSL is properly reflecting on the website. I have also ticked the option to use "HTTPS…

Azure Web Application Firewall
Azure App Service
Azure App Service
Azure App Service is a service used to create and deploy scalable, mission-critical web apps.
6,997 questions
asked 2020-09-09T08:58:37.503+00:00
HrTJ 21 Reputation points
accepted 2020-09-11T02:14:10.337+00:00
HrTJ 21 Reputation points
1 answer One of the answers was accepted by the question author.

Does SignalR work over a Web Applicatiomn Firewall?

We are planning to use Azure SignalR service for a mobile app to get real-time updates. We have a requirement that all traffic on Azure go through a Web Application Firewall (Imperva WAF). Will SignalR Service work if the traffic goes through a WAF?

Azure SignalR Service
Azure SignalR Service
An Azure service that is used for adding real-time communications to web applications.
121 questions
Azure Web Application Firewall
asked 2020-08-27T17:14:07.13+00:00
Rai, Mahesh 21 Reputation points
accepted 2020-09-02T18:26:17.157+00:00
Rai, Mahesh 21 Reputation points
2 answers

Azure Application Gateway /WAF v2 provisioning keeps failing

Hi All, We are trying to provision an App Gateway (WAF v2) in a dedciated VNET which is peered with the Transit/Hub Vnet, However the App Gateway provisioning keeps failing with below error "code": "Conflict", "message":…

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
969 questions
Azure Web Application Firewall
asked 2020-08-20T21:46:10.2+00:00
Karthik Chowdary Namburu 1 Reputation point
commented 2020-08-26T20:28:22.613+00:00
TravisCragg-MSFT 5,681 Reputation points Microsoft Employee
1 answer One of the answers was accepted by the question author.

Azure Applicatin Gateway Standard V1 to WAF V2 directly

Hi Experts, I have few existing applications on Standards V1 and we would like to migrate to WAF V2. Is there any way to directly move to WAF V2.

Azure Web Application Firewall
asked 2020-08-10T05:23:08.597+00:00
CloudArch 41 Reputation points
accepted 2020-08-10T18:03:11.77+00:00
CloudArch 41 Reputation points
1 answer One of the answers was accepted by the question author.

Azure WAF V1 to WAF V2 Migration

Hi Experts, I have few existing applications on WAF V1 and we would like to migrate to WAF V2. Is there any way to directly move to WAF V2.

Azure Web Application Firewall
asked 2020-08-10T05:21:53.11+00:00
CloudArch 41 Reputation points
accepted 2020-08-10T05:33:17.047+00:00
CloudArch 41 Reputation points
1 answer

Server firewall setting log

i need to log who is added client ip i firewall setting

Azure Web Application Firewall
asked 2020-07-29T11:16:10.727+00:00
Sameh Gamal 1 Reputation point
commented 2020-08-06T11:28:13.973+00:00
GitaraniSharma-MSFT 48,011 Reputation points Microsoft Employee