説明
Application GatewayのWAFが無効、または必要な経路に適用されていないと、その要求は保護されません。Detectionは一致した要求を記録し、Preventionはルールに従って遮断します。
想定される影響
WAFで除外すべき悪意のある要求が、バックエンドのアプリケーションに届くおそれがあります。
対処方法
WAF対応SKUと有効なポリシーまたはWAF設定を使用してください。遮断が必要ならPreventionを使い、ルールや除外設定の正常なトラフィックへの影響を確認してください。
例
以下はWAFブロックの有効状態を変更する抜粋例です。WAF_v2 SKUと必要なリスナー・バックエンド・ルーティングは別途構成してください。
変更前
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = false
}
}
変更後
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = true
}
}