The Azure Application Gateway offers a web application firewall (WAF) that provides central protection for web applications from common feats and exposures. The WAF automatically updates to include protection against new vulnerabilities, without the need for additional configuration. Application Gateway operates as an application delivery controller (ADC).
Some of the features of the Azure Application Gateway:
- SQL-injection guard
- Protection against HTTP protocol destructions
- Protection against bots, crawlers, and scanners
- Detection of common application misconfigurations (for example, Apache and IIS)
- Configurable request size limits with lower and upper bounds
- Exclusion lists let you omit certain request attributes from a WAF evaluation. A common example is Active Directory-inserted tokens that are used for authentication or password fields.