Home

Az Application Gateway WAF Policy - Custom Rule exclusions can't be created for specific WAF Rules?

%3CLINGO-SUB%20id%3D%22lingo-sub-897923%22%20slang%3D%22en-US%22%3EAz%20Application%20Gateway%20WAF%20Policy%20-%20Custom%20Rule%20exclusions%20can't%20be%20created%20for%20specific%20WAF%20Rules%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-897923%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3E%3CFONT%20face%3D%22inherit%22%3EHave%20been%20playing%20with%20the%20AAG%20Web%20Application%20Firewall%20for%20some%20time%20now%20and%20found%20what%20I%20%3C%2FFONT%3Ebelieve%3CFONT%20face%3D%22inherit%22%3E%26nbsp%3Bto%20be%20some%20rather%20major%20flaws%20in%20%3C%2FFONT%3Efunctionality%3CFONT%20face%3D%22inherit%22%3E.%3C%2FFONT%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3CFONT%20face%3D%22inherit%22%3EMainly%2C%20the%20lack%20of%20ability%20to%20exclude%20a%20specific%20URI%20from%20%3CSTRONG%3E%3CEM%3Ecertain%20WAF%20rule%20checks%3C%2FEM%3E%3C%2FSTRONG%3E%20%2C%20instead%20it%20very%20much%20seems%20like%20when%20you%20add%20an%20exception%20via%20an%20Application%20Gateway%20WAF%20Policy%2C%20that%20it%20exlcudes%20the%20URI%20from%20the%20WAF%20%3CEM%3E%3CSTRONG%3Eentirely.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FSTRONG%3E%3C%2FEM%3EAnyone%20have%20any%20info%2C%20clues%2C%20tips%20or%20ways%20I%20have%20not%20found%20to%20exclude%20a%20certain%20URI%20from%20specific%20rule%20checks%3F%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-897923%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EApplication%20Gateway%20WAF%20Policy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Application%20Gateway%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20Web%20Application%20Firewall%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-918994%22%20slang%3D%22en-US%22%3ERe%3A%20Az%20Application%20Gateway%20WAF%20Policy%20-%20Custom%20Rule%20exclusions%20can't%20be%20created%20for%20specific%20WAF%20Rul%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-918994%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F417171%22%20target%3D%22_blank%22%3E%40chrisbutler%3C%2FA%3E%2C%20t%3CFONT%20style%3D%22background-color%3A%20%23ffffff%3B%22%3Ehank%20you%20for%20your%20feedback!%20Checking%20with%20the%20AAG%20WAF%20team%2C%20this%20is%20on%20their%20roadmap%20already.%20For%20your%20information%2C%20we're%20targeting%20to%20host%20a%20webinar%20%3CSTRONG%3E%22Azure%20Network%20Security%3A%20Introduction%20to%20WAF%22%20on%20Nov%2014%2C%202019%3C%2FSTRONG%3E.%20Stay%20tuned%20as%20I%20will%20be%20posting%20registration%20details%20in%20a%20couple%20of%20weeks%20here%20on%20this%20page.%3C%2FFONT%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
chrisbutler
Occasional Contributor

Hi,

Have been playing with the AAG Web Application Firewall for some time now and found what I believe to be some rather major flaws in functionality.

Mainly, the lack of ability to exclude a specific URI from certain WAF rule checks , instead it very much seems like when you add an exception via an Application Gateway WAF Policy, that it exlcudes the URI from the WAF entirely.

Anyone have any info, clues, tips or ways I have not found to exclude a certain URI from specific rule checks?

 

 

1 Reply

Hi @chrisbutler, thank you for your feedback! Checking with the AAG WAF team, this is on their roadmap already. For your information, we're targeting to host a webinar "Azure Network Security: Introduction to WAF" on Nov 14, 2019. Stay tuned as I will be posting registration details in a couple of weeks here on this page.

Related Conversations