Azure Web Application Firewall on Azure Front Door Service - frequently asked questions (2024)

This article answers common questions about Azure Web Application Firewall (WAF) on Azure Front Door Service features and functionality.

What is Azure WAF?

Azure WAF is a web application firewall that helps protect your web applications from common threats such as SQL injection, cross-site scripting, and other web exploits. You can define a WAF policy consisting of a combination of custom and managed rules to control access to your web applications.

An Azure WAF policy can be applied to web applications hosted on Application Gateway or Azure Front Doors.

What is WAF on Azure Front Door?

Azure Front Door is a highly scalable, globally distributed application and content delivery network. Azure WAF, when integrated with Front Door, stops denial-of-service and targeted application attacks at the Azure network edge, close to attack sources before they enter your virtual network, offers protection without sacrificing performance.

Does Azure WAF support HTTPS?

Front Door offers TLS offloading. WAF is natively integrated with Front Door and can inspect a request after it's decrypted.

Does Azure WAF support IPv6?

Yes. You can configure IP restriction for IPv4 and IPv6.

How up-to-date are the managed rule sets?

We do our best to keep up with changing threat landscape. Once a new rule is updated, it's added to the Default Rule Set with a new version number.

What is the propagation time if I make a change to my WAF policy?

Most WAF policy deployments complete under 20 minutes. You can expect the policy to take effect as soon as the update is completed across all edge locations globally.

Can WAF policies be different for different regions?

When integrated with Front Door, WAF is a global resource. Same configuration applies across all Front Door locations.

How do I limit access to my back-end to be from Front Door only?

You may configure IP Access Control List in your back-end to allow for only Front Door outbound IP address ranges using Azure Front Door service tag and deny any direct access from Internet. Service tags are supported for you to use on your virtual network. Additionally, you can verify that the X-Forwarded-Host HTTP header field is valid for your web application.

Which Azure WAF options should I choose?

There are two options when applying WAF policies in Azure. WAF with Azure Front Door is a globally distributed, edge security solution. WAF with Application Gateway is a regional, dedicated solution. We recommend you choose a solution based on your overall performance and security requirements. For more information, see Load-balancing with Azure’s application delivery suite.

What's the recommended approach to enabling WAF on Front Door?

When you enable the WAF on an existing application, it's common to have false positive detections where the WAF rules detect legitimate traffic as a threat. To minimize the risk of an impact to your users, we recommend the following process:

  • Enable the WAF in Detection mode to ensure that the WAF doesn't block requests while you are working through this process. This step is recommended for testing purposes on WAF.

    Important

    This process describes how to enable the WAF on a new or existing solution when your priority is to minimize the disturbance to your application's users. If you are under attack or imminent threat, you may want to instead deploy the WAF in Prevention mode immediately, and use the tuning process to monitor and tune the WAF over time. This will probably cause some of your legitimate traffic to be blocked, which is why we only recommend doing this when you are under threat.

  • Follow our guidance for tuning the WAF. This process requires that you enable diagnostic logging, review the logs regularly, and add rule exclusions and other mitigations.
  • Repeat this whole process, checking the logs regularly, until you're satisfied that no legitimate traffic is being blocked. The whole process may take several weeks. Ideally you should see fewer false positive detections after each tuning change you make.
  • Finally, enable the WAF in Prevention mode.
  • Even once you're running the WAF in production, you should keep monitoring the logs to identify any other false-positive detections. Regularly reviewing the logs will also help you to identify any real attack attempts that have been blocked.

Do you support same WAF features in all integrated platforms?

Currently, ModSec CRS 3.0, CRS 3.1 and CRS 3.2 rules are only supported with WAF on Application Gateway. Rate limiting and Azure managed Default Rule Set rules are supported only with WAF on Azure Front Door.

Is DDoS protection integrated with Front Door?

Globally distributed at Azure network edges, Azure Front Door can absorb and geographically isolate large volume attacks. You can create custom WAF policy to automatically block and rate limit http(s) attacks that have known signatures. Further more, you can enable DDoS Network Protection on the VNet where your back-ends are deployed. Azure DDoS Protection customers receive additional benefits including cost protection, SLA guarantee, and access to experts from DDoS Rapid Response Team for immediate help during an attack. For more information, see DDoS protection on Front Door.

Why do additional requests above the threshold configured for my rate limit rule get passed to my backend server?

You might not see requests immediately blocked by the rate limit when requests are processed by different Front Door servers. For more information, see Rate limiting and Front Door servers.

What content types does WAF support?

Front Door WAF supports the following content types:

  • DRS 2.0

    Managed rules

    • application/json
    • application/xml
    • application/x-www-form-urlencoded
    • multipart/form-data

    Custom rules

    • application/x-www-form-urlencoded
  • DRS 1.x

    Managed rules

    • application/x-www-form-urlencoded
    • text/plain

    Custom rules

    • application/x-www-form-urlencoded

Can I apply a Front door WAF policy to front-end hosts in different Front Door premium (AFDX) profiles that belong to different subscriptions?

No, you can't. The AFD profile and the WAF policy need to be in the same subscription.

Next steps

  • Learn about Azure Web Application Firewall.
  • Learn more about Azure Front Door.
Azure Web Application Firewall on Azure Front Door Service - frequently asked questions (2024)
Top Articles
Giardia duodenalis: Biology and Pathogenesis
How does your browser knows that the TLS certificate presented by the web server is a legit one signed by a trusted C.A ?
Play FETCH GAMES for Free!
Katie Pavlich Bikini Photos
AllHere, praised for creating LAUSD’s $6M AI chatbot, files for bankruptcy
Santa Clara College Confidential
Otis Department Of Corrections
Craigslist - Pets for Sale or Adoption in Zeeland, MI
When Is the Best Time To Buy an RV?
Zoebaby222
Sams Gas Price Fairview Heights Il
2021 Lexus IS for sale - Richardson, TX - craigslist
Diablo 3 Metascore
Wisconsin Women's Volleyball Team Leaked Pictures
I Wanna Dance with Somebody : séances à Paris et en Île-de-France - L'Officiel des spectacles
Missed Connections Dayton Ohio
Paradise leaked: An analysis of offshore data leaks
Elemental Showtimes Near Cinemark Flint West 14
Where to Find Scavs in Customs in Escape from Tarkov
bode - Bode frequency response of dynamic system
Teacup Yorkie For Sale Up To $400 In South Carolina
Morristown Daily Record Obituary
Putin advierte que si se permite a Ucrania usar misiles de largo alcance, los países de la OTAN estarán en guerra con Rusia - BBC News Mundo
The Tower and Major Arcana Tarot Combinations: What They Mean - Eclectic Witchcraft
Kirsten Hatfield Crime Junkie
Sound Of Freedom Showtimes Near Movie Tavern Brookfield Square
Preggophili
Pensacola Tattoo Studio 2 Reviews
N.J. Hogenkamp Sons Funeral Home | Saint Henry, Ohio
FSA Award Package
Lawrence Ks Police Scanner
Dubois County Barter Page
Citibank Branch Locations In Orlando Florida
Mrstryst
Rocksteady Steakhouse Menu
Lil Durk's Brother DThang Killed in Harvey, Illinois, ME Confirms
Craigslist Hamilton Al
Missouri State Highway Patrol Will Utilize Acadis to Improve Curriculum and Testing Management
Asian Grocery Williamsburg Va
Andhra Jyothi Telugu News Paper
Dr. John Mathews Jr., MD – Fairfax, VA | Internal Medicine on Doximity
USB C 3HDMI Dock UCN3278 (12 in 1)
Philadelphia Inquirer Obituaries This Week
Publictributes
Sukihana Backshots
Traumasoft Butler
Toomics - Die unendliche Welt der Comics online
Advance Auto.parts Near Me
Craigslist Sparta Nj
tampa bay farm & garden - by owner "horses" - craigslist
Missed Connections Dayton Ohio
Craigslist Pet Phoenix
Latest Posts
Article information

Author: Prof. An Powlowski

Last Updated:

Views: 5908

Rating: 4.3 / 5 (64 voted)

Reviews: 87% of readers found this page helpful

Author information

Name: Prof. An Powlowski

Birthday: 1992-09-29

Address: Apt. 994 8891 Orval Hill, Brittnyburgh, AZ 41023-0398

Phone: +26417467956738

Job: District Marketing Strategist

Hobby: Embroidery, Bodybuilding, Motor sports, Amateur radio, Wood carving, Whittling, Air sports

Introduction: My name is Prof. An Powlowski, I am a charming, helpful, attractive, good, graceful, thoughtful, vast person who loves writing and wants to share my knowledge and understanding with you.