설명
Front Door에 유효한 WAF 정책이 연결되지 않으면 해당 지점에서 WAF 규칙으로 요청을 검사하거나 차단할 수 없습니다. 정책 연결 후에도 활성화 상태와 적용 모드를 확인해야 합니다.
잠재적 영향
악성 웹 요청이 WAF에서 차단되지 않고 원본 애플리케이션에 도달할 수 있습니다.
해결 방법
필요한 엔드포인트에 정책을 연결하고 규칙과 예외를 검토하세요. Detection 모드는 기록용이므로 차단이 필요하면 Prevention 모드를 사용하고 정상 요청에 미치는 영향을 확인하세요.
예시
기존 Front Door Classic의 정책 연결 부분을 보여 주는 예시입니다. 새 구성에는 Standard/Premium을 사용하고 원본·라우팅·정책은 별도로 구성하세요.
변경 전
hcl
resource "azurerm_frontdoor" "example" {
name = "example-frontdoor"
resource_group_name = azurerm_resource_group.example.name
backend_pool_settings {
enforce_backend_pools_certificate_name_check = true
}
frontend_endpoint {
name = "exampleFrontendEndpoint1"
host_name = "example-frontdoor.azurefd.net"
}
}
변경 후
hcl
resource "azurerm_frontdoor" "example" {
name = "example-frontdoor"
resource_group_name = azurerm_resource_group.example.name
backend_pool_settings {
enforce_backend_pools_certificate_name_check = true
}
frontend_endpoint {
name = "exampleFrontendEndpoint1"
host_name = "example-frontdoor.azurefd.net"
web_application_firewall_policy_link_id = azurerm_frontdoor_firewall_policy.example.id
}
}