Review WAF protection for Azure Application Gateway

Configure both a WAF tier and an effective blocking policy for Application Gateway.

Description

The standard Application Gateway tier has no WAF capability. Using WAF requires a supported WAF tier and an enabled policy with suitable rules.

Potential impact

Without required WAF protection, a layer that filters known web attacks is missing. A WAF does not repair application vulnerabilities.

Remediation

Associate an appropriate WAF policy with the waf_v2 tier. Use Prevention mode when blocking is required, and check the effect on legitimate requests.

Examples

The examples compare v2 SKUs. Supply the ID of an enabled WAF policy in waf_policy_id. A SKU change alone does not complete the blocking policy; listener and network settings are omitted.

Before

yaml
- name: Application Gateway 생성
  azure.azcollection.azure_rm_appgateway:
    resource_group: myResourceGroup
    name: myAppGateway
    sku:
      name: standard_v2
      tier: standard_v2
      capacity: 2

After

yaml
- name: Application Gateway 생성
  azure.azcollection.azure_rm_appgateway:
    resource_group: myResourceGroup
    name: myAppGateway
    sku:
      name: waf_v2
      tier: waf_v2
      capacity: 2
    firewall_policy:
      id: "{{ waf_policy_id }}"

References