Description
When Application Gateway’s WAF is disabled or not applied to a required path, it does not protect those requests. Detection mode logs matches; Prevention mode blocks according to the rules.
Potential impact
Malicious requests that should be filtered by the WAF may reach the backend application.
Remediation
Use a WAF-capable SKU and an effective policy or WAF configuration. Use Prevention when blocking is required and check how rules and exclusions affect legitimate traffic.
Examples
These excerpts change the WAF block’s enabled setting. Configure the WAF_v2 SKU and required listeners, backends, and routing separately.
Before
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = false
}
}
After
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = true
}
}