Bird
Raised Fist0
Azurecloud~5 mins

WAF with Application Gateway in Azure - Commands & Configuration

Choose your learning style10 modes available

Start learning this pattern below

Jump into concepts and practice - no test required

or
Recommended
Test this pattern10 questions across easy, medium, and hard to know if this pattern is strong
Introduction
Web Application Firewall (WAF) with Azure Application Gateway protects your web apps from common internet threats by filtering and monitoring web traffic. It helps keep your apps safe from attacks like SQL injection or cross-site scripting without changing your app code.
When you want to protect your web app from common security threats without modifying the app itself.
When you need to monitor and control incoming web traffic to your application.
When you want to block malicious requests before they reach your backend servers.
When you want to use a managed service that integrates easily with Azure resources.
When you want to apply security rules globally to multiple web applications behind a gateway.
Config File - application-gateway-waf.json
application-gateway-waf.json
{
  "$schema": "https://schema.management.azure.com/schemas/2019-04-01/deploymentTemplate.json#",
  "contentVersion": "1.0.0.0",
  "parameters": {
    "applicationGatewayName": {
      "type": "string",
      "defaultValue": "myAppGateway"
    },
    "wafConfig": {
      "type": "object",
      "defaultValue": {
        "enabled": true,
        "firewallMode": "Prevention",
        "ruleSetType": "OWASP",
        "ruleSetVersion": "3.2"
      }
    }
  },
  "resources": [
    {
      "type": "Microsoft.Network/applicationGateways",
      "apiVersion": "2023-02-01",
      "name": "[parameters('applicationGatewayName')]",
      "location": "eastus",
      "properties": {
        "sku": {
          "name": "WAF_v2",
          "tier": "WAF_v2",
          "capacity": 2
        },
        "gatewayIPConfigurations": [
          {
            "name": "appGatewayIpConfig",
            "properties": {
              "subnet": {
                "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/virtualNetworks/myVnet/subnets/mySubnet"
              }
            }
          }
        ],
        "frontendIPConfigurations": [
          {
            "name": "appGatewayFrontendIP",
            "properties": {
              "publicIPAddress": {
                "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Network/publicIPAddresses/myPublicIP"
              }
            }
          }
        ],
        "frontendPorts": [
          {
            "name": "appGatewayFrontendPort",
            "properties": {
              "port": 80
            }
          }
        ],
        "backendAddressPools": [
          {
            "name": "appGatewayBackendPool",
            "properties": {
              "backendAddresses": [
                {
                  "ipAddress": "10.0.1.4"
                },
                {
                  "ipAddress": "10.0.1.5"
                }
              ]
            }
          }
        ],
        "backendHttpSettingsCollection": [
          {
            "name": "appGatewayBackendHttpSettings",
            "properties": {
              "port": 80,
              "protocol": "Http",
              "cookieBasedAffinity": "Disabled"
            }
          }
        ],
        "httpListeners": [
          {
            "name": "appGatewayHttpListener",
            "properties": {
              "frontendIPConfiguration": {
                "id": "[concat(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '/frontendIPConfigurations/appGatewayFrontendIP')]"
              },
              "frontendPort": {
                "id": "[concat(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '/frontendPorts/appGatewayFrontendPort')]"
              },
              "protocol": "Http"
            }
          }
        ],
        "requestRoutingRules": [
          {
            "name": "rule1",
            "properties": {
              "ruleType": "Basic",
              "httpListener": {
                "id": "[concat(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '/httpListeners/appGatewayHttpListener')]"
              },
              "backendAddressPool": {
                "id": "[concat(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '/backendAddressPools/appGatewayBackendPool')]"
              },
              "backendHttpSettings": {
                "id": "[concat(resourceId('Microsoft.Network/applicationGateways', parameters('applicationGatewayName')), '/backendHttpSettingsCollection/appGatewayBackendHttpSettings')]"
              }
            }
          }
        ],
        "webApplicationFirewallConfiguration": {
          "enabled": true,
          "firewallMode": "Prevention",
          "ruleSetType": "OWASP",
          "ruleSetVersion": "3.2"
        }
      }
    }
  ]
}

This JSON template creates an Azure Application Gateway with WAF enabled.

  • sku: Chooses the WAF_v2 tier for security features.
  • gatewayIPConfigurations: Connects the gateway to a subnet in your virtual network.
  • frontendIPConfigurations: Assigns a public IP for incoming traffic.
  • frontendPorts: Listens on port 80 for HTTP requests.
  • backendAddressPools: Defines backend servers by IP addresses.
  • httpListeners: Listens for HTTP traffic on the frontend IP and port.
  • requestRoutingRules: Routes incoming requests to backend pools.
  • webApplicationFirewallConfiguration: Enables WAF in prevention mode using OWASP 3.2 rules.
Commands
This command deploys the Application Gateway with WAF enabled using the ARM template. It creates all necessary resources in the specified resource group.
Terminal
az deployment group create --resource-group myResourceGroup --template-file application-gateway-waf.json
Expected OutputExpected
{ "id": "/subscriptions/00000000-0000-0000-0000-000000000000/resourceGroups/myResourceGroup/providers/Microsoft.Resources/deployments/myDeployment", "name": "myDeployment", "properties": { "provisioningState": "Succeeded" }, "resourceGroup": "myResourceGroup", "status": "Succeeded" }
→
--resource-group - Specifies the Azure resource group to deploy into
→
--template-file - Specifies the ARM template file to use for deployment
This command checks the WAF configuration on the deployed Application Gateway to confirm it is enabled and in prevention mode.
Terminal
az network application-gateway show --name myAppGateway --resource-group myResourceGroup --query "webApplicationFirewallConfiguration"
Expected OutputExpected
{ "enabled": true, "firewallMode": "Prevention", "ruleSetType": "OWASP", "ruleSetVersion": "3.2" }
→
--name - Specifies the Application Gateway name
→
--resource-group - Specifies the resource group of the Application Gateway
→
--query - Filters output to show only WAF configuration
Lists any WAF policies in the resource group to verify if custom policies exist or to manage them.
Terminal
az network application-gateway waf-policy list --resource-group myResourceGroup
Expected OutputExpected
[]
→
--resource-group - Specifies the resource group to list WAF policies from
Key Concept

If you remember nothing else from this pattern, remember: enabling WAF on Application Gateway protects your web apps by filtering harmful web traffic before it reaches your servers.

Common Mistakes
Not enabling WAF in the Application Gateway configuration.
Without enabling WAF, the gateway will not filter malicious traffic, leaving your app vulnerable.
Ensure the 'webApplicationFirewallConfiguration' section has 'enabled' set to true.
Using the wrong SKU tier that does not support WAF.
Only WAF_v2 or WAF_v1 SKUs support Web Application Firewall features.
Set the SKU name and tier to 'WAF_v2' in the configuration.
Not assigning a public IP to the frontend IP configuration.
Without a public IP, the Application Gateway cannot receive internet traffic.
Assign a valid public IP resource to the frontendIPConfigurations section.
Summary
Deploy an Azure Application Gateway with WAF enabled using an ARM template.
Verify the WAF configuration is active and set to prevention mode using Azure CLI.
List WAF policies to manage or confirm custom security rules.

Practice

(1/5)
1. What is the main purpose of enabling WAF (Web Application Firewall) on an Azure Application Gateway?
easy
A. To provide a database backup solution
B. To protect web applications from common web attacks like SQL injection and cross-site scripting
C. To increase the speed of the web application by caching content
D. To monitor network traffic at the virtual network level

Solution

  1. Step 1: Understand WAF's role

    WAF is designed to protect web apps by filtering and monitoring HTTP traffic to block common attacks.
  2. Step 2: Compare options

    Only To protect web applications from common web attacks like SQL injection and cross-site scripting describes protection from web attacks, which is the core function of WAF.
  3. Final Answer:

    To protect web applications from common web attacks like SQL injection and cross-site scripting -> Option B
  4. Quick Check:

    WAF protects web apps = C [OK]
Hint: WAF blocks web attacks, not speeds or backups [OK]
Common Mistakes:
  • Confusing WAF with caching or backup services
  • Thinking WAF monitors network traffic broadly
  • Assuming WAF improves app speed
2. Which of the following is the correct way to enable WAF on an Azure Application Gateway using ARM template syntax?
easy
A. "sku": { "name": "WAF_v2" }, "wafConfiguration": { "enabled": true, "firewallMode": "Prevention" }
B. "sku": { "name": "Standard_v2" }, "wafConfiguration": { "enabled": true }
C. "sku": { "name": "Basic" }, "wafConfiguration": { "enabled": false }
D. "sku": { "name": "WAF_v1" }, "wafConfiguration": { "enabled": false, "firewallMode": "Detection" }

Solution

  1. Step 1: Identify correct SKU for WAF

    WAF requires SKU like "WAF_v2" or "WAF_v1"; Standard_v2 or Basic do not enable WAF.
  2. Step 2: Check WAF configuration

    WAF must be enabled with "enabled": true and a valid firewallMode like "Prevention" or "Detection".
  3. Final Answer:

    "sku": { "name": "WAF_v2" }, "wafConfiguration": { "enabled": true, "firewallMode": "Prevention" } -> Option A
  4. Quick Check:

    WAF SKU + enabled true + mode = A [OK]
Hint: WAF needs WAF SKU and enabled true [OK]
Common Mistakes:
  • Using Standard or Basic SKU without WAF
  • Setting enabled to false when enabling WAF
  • Omitting firewallMode or using invalid values
3. Given this snippet of ARM template for Application Gateway WAF configuration:
{
  "sku": { "name": "WAF_v2" },
  "wafConfiguration": {
    "enabled": true,
    "firewallMode": "Detection"
  }
}

What will be the behavior of the Application Gateway regarding detected threats?
medium
A. It will log detected threats but allow traffic to pass through
B. It will block detected threats and return an error to clients
C. It will ignore detected threats and not log them
D. It will shut down the Application Gateway on threat detection

Solution

  1. Step 1: Understand firewallMode 'Detection'

    Detection mode means WAF monitors and logs threats but does not block traffic.
  2. Step 2: Compare options with behavior

    Only It will log detected threats but allow traffic to pass through matches detection mode behavior: logging threats but allowing traffic.
  3. Final Answer:

    It will log detected threats but allow traffic to pass through -> Option A
  4. Quick Check:

    Detection mode = log only, no block = B [OK]
Hint: Detection mode logs but does not block [OK]
Common Mistakes:
  • Confusing Detection with Prevention mode
  • Assuming threats are blocked in Detection mode
  • Thinking Application Gateway shuts down on threats
4. You configured WAF on Application Gateway with this snippet:
{
  "sku": { "name": "WAF_v2" },
  "wafConfiguration": {
    "enabled": true,
    "firewallMode": "Prevention"
  }
}

But the WAF is not blocking malicious requests. What is the most likely cause?
medium
A. The Application Gateway is missing a listener configuration
B. The SKU name "WAF_v2" does not support prevention mode
C. The WAF policy is not associated with the Application Gateway
D. The firewallMode should be set to Detection to block requests

Solution

  1. Step 1: Check WAF policy association

    Even if WAF is enabled, it must have a WAF policy linked to enforce rules and block threats.
  2. Step 2: Validate other options

    Listener is required but unrelated to blocking; prevention mode blocks; WAF_v2 supports prevention mode.
  3. Final Answer:

    The WAF policy is not associated with the Application Gateway -> Option C
  4. Quick Check:

    WAF policy association needed to block = D [OK]
Hint: WAF needs policy linked to block threats [OK]
Common Mistakes:
  • Confusing detection and prevention modes
  • Forgetting to associate WAF policy
  • Assuming SKU limits prevention mode
5. You want to protect your web app with Azure Application Gateway WAF in prevention mode but also need to monitor false positives before blocking. What is the best approach to achieve this?
hard
A. Use Basic SKU Application Gateway with WAF enabled
B. Enable WAF in prevention mode immediately and block all detected threats
C. Disable WAF and rely on network security groups for protection
D. Enable WAF in detection mode first, review logs, then switch to prevention mode

Solution

  1. Step 1: Understand prevention vs detection modes

    Prevention mode blocks threats immediately; detection mode only logs them for review.
  2. Step 2: Plan safe deployment

    Start with detection mode to identify false positives, then switch to prevention to block real threats safely.
  3. Final Answer:

    Enable WAF in detection mode first, review logs, then switch to prevention mode -> Option D
  4. Quick Check:

    Detect first, then prevent = A [OK]
Hint: Detect first, then switch to prevention mode [OK]
Common Mistakes:
  • Blocking immediately without monitoring false positives
  • Disabling WAF and relying on unrelated protections
  • Using Basic SKU which does not support WAF