378 questions with Azure Web Application Firewall tags

Sort by: Updated
1 answer

Azure WAF exclude specific content-type header

Hi community, I am trying to make an exclusion for a ruleid which is triggered for [REQUEST_HEADERS:Content-Type:application/scim+json; charset=UTF-8]}. It seems pretty straightforward: Match on RequestHeaderValues contains: scim+json However the rule…

Azure Web Application Firewall
asked 2025-09-19T08:56:07.43+00:00
eenchev 10 Reputation points
answered 2025-10-24T21:31:59.88+00:00
Camilo Santana 0 Reputation points
0 answers

Why WAF policy settings "Enforce maximum request body limit" setting is not the same as in WAF policy json property: properties.policySettings.requestBodyEnforcement

Why WAF policy settings "Enforce maximum request body limit" setting is not the same as in WAF policy json property: properties.policySettings.requestBodyEnforcement

Azure Web Application Firewall
asked 2025-10-23T09:54:12.9433333+00:00
Elisa 0 Reputation points
commented 2025-10-23T11:48:24.07+00:00
Priya ranjan Jena 1,510 Reputation points Microsoft External Staff Moderator
0 answers

Azure Web Application Firewall Bot Manager Rule set 1.1

Can we please have further information on the "Good Bots" detection with the rule set 1.1? Which AI crawlers would be identified as "Good Bots"? The main reason behind this is that we are managing a public facing website and are…

Azure Web Application Firewall
asked 2025-10-23T05:13:24.66+00:00
Ma, Le 0 Reputation points
commented 2025-10-23T08:36:40.3066667+00:00
Harish Peddapally 1,330 Reputation points Microsoft External Staff Moderator
1 answer

Azure WAF best practice for specific rules

Hi, Looking for some very specific help regarding Azure Web application rules. Some URI'S are hitting various WAF rules within the OWASP Ruleset (using version 3.2 currently) and I am looking to exclude these from those specific rules (2 in question…

Azure Web Application Firewall
asked 2025-09-18T15:17:19.12+00:00
Eddie Vincent 205 Reputation points
answered 2025-10-17T12:07:48.5033333+00:00
Praveen Bandaru 8,765 Reputation points Microsoft External Staff Moderator
0 answers

Application gateway WAF can protect all attacks listed>

Hi all, May I confirm if WAF in Application gateway can protect from the attacks listed below? Buffer overflow SSI injection Directory Traversal I cannot find these in the document below. …

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,271 questions
Azure Web Application Firewall
asked 2022-12-01T13:54:38.593+00:00
Testa 571 Reputation points
commented 2025-10-08T02:02:25+00:00
Alfredzo Nash 0 Reputation points
2 answers

App Service cannot connect to Azure SQL Database despite firewall and VNet rules

We have an Azure App Service that is unable to connect to an Azure SQL Database. The following configuration steps have already been completed, but the issue persists: All App Service outbound IPs are added to the SQL Server Firewall and Virtual Networks…

Azure Web Application Firewall
asked 2025-10-01T07:49:23.57+00:00
Adel M 0 Reputation points
answered 2025-10-01T09:37:54.39+00:00
Harish Peddapally 1,330 Reputation points Microsoft External Staff Moderator
2 answers One of the answers was accepted by the question author.

Application Gateway with WAF performance degradation

We are very often experiencing crashes/performance degradation of our Application Gateway with associated WAF in detection mode. Throughput on the AGW is just about 100 req/s and it doesn't change much throughout the day (IoT devices requests, all across…

Azure Web Application Firewall
asked 2025-09-22T11:01:13.0233333+00:00
Martin Kutlák 20 Reputation points
commented 2025-09-29T07:47:08.9133333+00:00
Martin Kutlák 20 Reputation points
0 answers

Local ISP - New /23 IP Block Restricted by Azure - How to fix?

We are a local ISP in SE Oklahoma. We have a new /23 of ip's that are all experiencing the same blocks from Azure, the one website that we are aware of is activeandfitdirect.com, yet i assume there are others. When accessing the website from any of the…

Azure Web Application Firewall
asked 2025-09-25T20:14:55.7333333+00:00
CircleBWireless 0 Reputation points
commented 2025-09-25T21:08:16.48+00:00
TP 141.6K Reputation points Volunteer Moderator
2 answers

Rate limiting does not work

We are trying a custom rule: Rate 100 priority 100 hits 1 minute IP address range 0.0.00/255.255.255.255 The application goes rightaway into Forbidden 403 and never comes back

Azure Web Application Firewall
asked 2025-09-14T13:26:58.2033333+00:00
Todd Covert 0 Reputation points
commented 2025-09-17T04:39:19.9233333+00:00
Harish Peddapally 1,330 Reputation points Microsoft External Staff Moderator
1 answer

Rate Limit on Azure WAF Frontdoor Premium not working as expected

We have created an Azure Frontdoor Premim Tier with a Web Application Firewall associated with it and we are having some issues with a specific rule we created to apply rate limiting. The rule is looking for a specific URL and specifies a limit of 2 http…

Azure Front Door
Azure Front Door
An Azure service that provides a cloud content delivery network with threat protection.
954 questions
Azure Web Application Firewall
asked 2024-03-19T14:55:39.86+00:00
Fabián Avilés 80 Reputation points
edited a comment 2025-09-17T02:43:09.9033333+00:00
Matthew Mckenzie 0 Reputation points
2 answers One of the answers was accepted by the question author.

Question on TLS 1.2 Enforcement Deadline (31-Aug) and Azure WAF Upgrade

Hi Community, We are currently preparing to upgrade our Azure Web Application Firewall (WAF) from V1 to V2 and transition all connections to TLS 1.2 in line with Microsoft’s enforcement deadline of 31 August. I would like to clarify a few points: What…

Azure Web Application Firewall
asked 2025-08-28T08:28:53.9566667+00:00
Nang Shwe Yea Oo 20 Reputation points
accepted 2025-09-03T08:26:34.85+00:00
Nang Shwe Yea Oo 20 Reputation points
1 answer

Clarification on Addition and Updates of Rules in Azure WAF Managed Rule Sets (OWASP CRS) and Impact on Exclusions

Hello Azure Support Team, We have some questions regarding the management and update process of Azure Web Application Firewall (WAF) managed rule sets, specifically around the OWASP Core Rule Set (CRS) versions: How are new rules added to the managed…

Azure Web Application Firewall
asked 2025-08-11T18:37:38.1233333+00:00
Amritpal Brar 0 Reputation points
edited an answer 2025-08-20T09:17:14.5333333+00:00
Jeevan Shanigarapu 2,375 Reputation points Microsoft External Staff Moderator
2 answers

Why does Azure application gateway rate limit WAF return a 403 and not a 429?

When Azure Application gateway rate limiter functions as expected, we were expecting a 429, but instead, a 403 is returned. Why is this?

Azure Application Gateway
Azure Application Gateway
An Azure service that provides a platform-managed, scalable, and highly available application delivery controller as a service.
1,271 questions
Azure Web Application Firewall
asked 2024-03-04T13:57:27.39+00:00
Levi 40 Reputation points
commented 2025-07-28T10:39:38.33+00:00
Nishant Chauhan 0 Reputation points Microsoft Employee
1 answer

One of my home IP addresses can't access sites hosted in Azure

Hi, I have a slightly odd issue - traffic coming from my default home IP address (82.68.8.222) seems to be being dropped by some websites hosted on Azure (Microsoft learn, Nationwide Building Society). If I masquerade my laptops as coming from a…

Azure Web Application Firewall
asked 2025-04-06T11:21:58.96+00:00
Launchbury, Phil 0 Reputation points
commented 2025-08-18T15:34:37.0433333+00:00
Anonymous
1 answer

What is the best practice to add exclusion in WAF

Hi Team, We are currently working on tuning the Azure WAF rules based on Microsoft’s documentation. While we have followed the recommended guidelines, we would like to confirm whether our current configuration approach is aligned with best practices. The…

Azure Web Application Firewall
asked 2025-07-07T20:22:27.0833333+00:00
Johnson 5 Reputation points
edited an answer 2025-07-15T18:38:54.9666667+00:00
Anonymous
1 answer One of the answers was accepted by the question author.

Azure App Gateway WAF_v2 Custom Rule evaluation of RequestUri fails to limit allowed paths

I have an Azure App Gateway (AppGW) whose public listener I configured with a Path-based routing rule. That Routing Rule has a default backend configured (which is required, even though I would prefer not to), and several routes, e.g. Path…

Azure Web Application Firewall
asked 2025-07-16T09:53:04.4166667+00:00
Marius Shekow 45 Reputation points
accepted 2025-07-25T07:45:21.6433333+00:00
Marius Shekow 45 Reputation points
1 answer One of the answers was accepted by the question author.

An error when trying to delete a firewall rule

Hello. We get an error when trying to delete a rule from IP restrictions that states "virtual network was not found" even though it exists. Failed to perform 'read' on resource(s) of type 'virtualNetworks/taggedTrafficConsumers', because the…

Azure Web Application Firewall
asked 2025-07-19T20:12:30.2933333+00:00
dockedferret800 20 Reputation points
commented 2025-07-22T13:04:21.57+00:00
dockedferret800 20 Reputation points
1 answer

Azure WAF exclusions clarity of 920420

Hello,Good day! In Azure Frontdoor and AppGw WAF logs, I recently saw some requests were getting blocked by the ruleID 920420. Upon checking the logs, it said matchVariableName 'Header Value: Content-type' and matchVariableValue 'application/gzip' is not…

Azure Web Application Firewall
asked 2025-07-23T13:30:50.3566667+00:00
Alex 515 Reputation points
commented 2025-07-28T19:00:55.1433333+00:00
Anonymous
1 answer One of the answers was accepted by the question author.

Azure front door waf rate limiting algorithm

Hello, What's the rate limiting algorithm Frontdoor and AppGw waf uses? In the docs, appgw waf v2 mentioned it uses sliding window algorithm. Is that right? And how about Frontdoor waf?

Azure Web Application Firewall
asked 2025-07-25T16:18:22.4566667+00:00
Alex 515 Reputation points
accepted 2025-07-25T16:46:42.6666667+00:00
Alex 515 Reputation points
1 answer One of the answers was accepted by the question author.

How can I find the original client IP address of a log entry in my WAF?

When I go into the logs for our Application Gateway and run a KQL query to see what items were caught (based on OWASP rules), I can see that the request logs have a column clientIp_s that shows the IP address of the requestee. However, the IP addresses I…

Azure Web Application Firewall
asked 2025-07-30T20:22:34.91+00:00
Josh Cantie 20 Reputation points
accepted 2025-07-31T12:48:27.7233333+00:00
Josh Cantie 20 Reputation points