설명
Application Gateway의 WAF가 꺼져 있거나 필요한 경로에 적용되지 않으면 해당 요청에 WAF 보호가 제공되지 않습니다. Detection 모드는 일치하는 요청을 기록하고 Prevention 모드는 규칙에 따라 차단합니다.
잠재적 영향
WAF에서 걸러야 할 악성 요청이 백엔드 애플리케이션에 전달될 수 있습니다.
해결 방법
WAF 지원 SKU와 유효한 정책 또는 WAF 설정을 사용하세요. 차단이 필요하면 Prevention 모드로 운영하고 규칙·예외가 정상 트래픽에 미치는 영향을 확인하세요.
예시
WAF 설정 블록의 활성화 여부를 바꾸는 발췌 예시입니다. WAF_v2 SKU와 필요한 수신기·백엔드·라우팅 설정은 별도로 구성하세요.
변경 전
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = false
}
}
변경 후
hcl
resource "azurerm_application_gateway" "example" {
name = "example-appgateway"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
waf_configuration {
firewall_mode = "Prevention"
rule_set_version = "3.2"
enabled = true
}
}