| reviewed | 2022-09-20 |
|---|---|
| severity | Critical |
| pillar | Security |
| category | SE:06 Network controls |
| resource | Front Door |
| resourceType | Microsoft.Network/FrontDoorWebApplicationFirewallPolicies |
| online version | https://azure.github.io/PSRule.Rules.Azure/en/rules/Azure.FrontDoorWAF.Exclusions/ |
Use recommended rule groups in Front Door Web Application Firewall (WAF) policies to protect back end resources. Avoid configuring rule exclusions.
Front Door WAF supports exclusions lists.
Sometimes Web Application Firewall (WAF) might block a request that you want to allow for your application. WAF exclusion lists allow you to omit certain request attributes from a WAF evaluation. However, it should be allowed and only used as a last resort.
Avoid configuring Front Door WAF rule exclusions.
To deploy WAF policies that pass this rule:
- Remove any rule exclusions by:
- Set the
exclusionsproperty for each managed rule group to an empty array. OR - Remove the
exclusionsproperty for each managed rule group.
- Set the
For example:
{
"type": "Microsoft.Network/FrontDoorWebApplicationFirewallPolicies",
"apiVersion": "2022-05-01",
"name": "[parameters('name')]",
"location": "Global",
"sku": {
"name": "Premium_AzureFrontDoor"
},
"properties": {
"managedRules": {
"managedRuleSets": [
{
"ruleSetType": "Microsoft_DefaultRuleSet",
"ruleSetVersion": "2.0",
"ruleSetAction": "Block",
"exclusions": [],
"ruleGroupOverrides": []
},
{
"ruleSetType": "Microsoft_BotManagerRuleSet",
"ruleSetVersion": "1.0",
"ruleSetAction": "Block",
"exclusions": [],
"ruleGroupOverrides": []
}
]
},
"policySettings": {
"enabledState": "Enabled",
"mode": "Prevention"
}
}
}To deploy WAF policies that pass this rule:
- Remove any rule exclusions by:
- Set the
exclusionsproperty for each managed rule group to an empty array. OR - Remove the
exclusionsproperty for each managed rule group.
- Set the
For example:
resource waf 'Microsoft.Network/FrontDoorWebApplicationFirewallPolicies@2022-05-01' = {
name: name
location: 'Global'
sku: {
name: 'Premium_AzureFrontDoor'
}
properties: {
managedRules: {
managedRuleSets: [
{
ruleSetType: 'Microsoft_DefaultRuleSet'
ruleSetVersion: '2.0'
ruleSetAction: 'Block'
exclusions: []
ruleGroupOverrides: []
}
{
ruleSetType: 'Microsoft_BotManagerRuleSet'
ruleSetVersion: '1.0'
ruleSetAction: 'Block'
exclusions: []
ruleGroupOverrides: []
}
]
}
policySettings: {
enabledState: 'Enabled'
mode: 'Prevention'
}
}
}