π‘οΈ Azure Application Gateway Web Application Firewall is not enabledπ’
- Contextual name: π‘οΈ Application Gateway Web Application Firewall is not enabledπ’
- ID:
/ce/ca/azure/application-gateway/web-application-firewall - Tags:
- π’ Policy with categories
- π’ Policy with type
- π’ Production policy
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Logicβ
- π§ prod.logic.yamlπ’
Descriptionβ
Descriptionβ
This policy identifies Azure Application Gateways that do not have a Web Application Firewall Policy. Azure WAF helps protect applications from common exploits and attacks by inspecting and filtering incoming traffic.
Rationaleβ
Using Azure Web Application Firewall with Azure Application Gateway reduces exposure to external threats by mitigating attacks on public facing applications.
Impactβ
The
WAF V2tier for Azure Application Gateways costs more than theBasicandStandard V2tiers. Pricing includes a fixed hourly charge plus a charge per capacity-unit hour. Refer to https://azure.microsoft.com/en-gb/pricing/details/application-gateway/ for details.Auditβ
This policy flags an Azure Application Gateway as
INCOMPLIANTif itsWAF Policyis not Enabled.Default Valueβ
Azure Web Application Firewall is enabled by default for the
WAF V2tier of Azure Application Gateway. It is not available in theBasictier. Application gateways deployed using theStandard V2tier can be upgraded to theWAF V2tier to enable Azure Web Application Firewall.... see more
Remediationβ
Remediationβ
Note:
Basictier application gateways cannot be upgraded to theWAF V2tier. Create a newWAF V2tier application gateway to replace aBasictier application gateway.From Azure Portalβ
To remediate a
Standard V2tier application gateway:
- Go to
Application gateways.- Click
Add filter.- From the
Filterdrop-down menu, selectSKU size.- Check the box next to
Standard_v2only.- Click
Apply.- Click the name of an application gateway.
- Under
Settings, clickWeb application firewall.- Under
Configure, next toTier, clickWAF V2.- Select an existing or create a new
WAF policy.- Click
Save.- Repeat steps 1-10 for each
Standard V2tier application gateway requiring remediation.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Azure v5.0.0 β πΌ 7.10 Ensure Azure Web Application Firewall (WAF) is enabled on Azure Application Gateway (Automated) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Threat Protection | 48 | no data |