Description
The standard Application Gateway tier has no WAF capability. Using WAF requires a supported WAF tier and an enabled policy with suitable rules.
Potential impact
Without required WAF protection, a layer that filters known web attacks is missing. A WAF does not repair application vulnerabilities.
Remediation
Associate an appropriate WAF policy with the waf_v2 tier. Use Prevention mode when blocking is required, and check the effect on legitimate requests.
Examples
The examples compare v2 SKUs. Supply the ID of an enabled WAF policy in waf_policy_id. A SKU change alone does not complete the blocking policy; listener and network settings are omitted.
Before
yaml
- name: Application Gateway 생성
azure.azcollection.azure_rm_appgateway:
resource_group: myResourceGroup
name: myAppGateway
sku:
name: standard_v2
tier: standard_v2
capacity: 2
After
yaml
- name: Application Gateway 생성
azure.azcollection.azure_rm_appgateway:
resource_group: myResourceGroup
name: myAppGateway
sku:
name: waf_v2
tier: waf_v2
capacity: 2
firewall_policy:
id: "{{ waf_policy_id }}"