Review WAF configuration for Azure Application Gateway

Apply required WAF inspection and blocking to web traffic.

Description

When Application Gateway’s WAF is disabled or not applied to a required path, it does not protect those requests. Detection mode logs matches; Prevention mode blocks according to the rules.

Potential impact

Malicious requests that should be filtered by the WAF may reach the backend application.

Remediation

Use a WAF-capable SKU and an effective policy or WAF configuration. Use Prevention when blocking is required and check how rules and exclusions affect legitimate traffic.

Examples

These excerpts change the WAF block’s enabled setting. Configure the WAF_v2 SKU and required listeners, backends, and routing separately.

Before

hcl
resource "azurerm_application_gateway" "example" {
  name                = "example-appgateway"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  waf_configuration {
    firewall_mode    = "Prevention"
    rule_set_version = "3.2"
    enabled = false
  }
}

After

hcl
resource "azurerm_application_gateway" "example" {
  name                = "example-appgateway"
  resource_group_name = azurerm_resource_group.example.name
  location            = azurerm_resource_group.example.location

  waf_configuration {
    firewall_mode    = "Prevention"
    rule_set_version = "3.2"
    enabled = true
  }
}

References