Skip to content

Commit 724c027

Browse files
authored
Revise WAF ruleset details to version 2.2
Updated WAF ruleset information to reflect the latest version and additional protections.
1 parent cb03332 commit 724c027

1 file changed

Lines changed: 2 additions & 3 deletions

File tree

articles/web-application-firewall/ag/application-gateway-waf-faq.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ sections:
4444
- question: |
4545
What rules are currently available for the WAF?
4646
answer: |
47-
The WAF currently supports Default Rule Set (DRS) [2.1](application-gateway-crs-rulegroups-rules.md#drs21), Core Rule Set (CRS) [3.2](application-gateway-crs-rulegroups-rules.md#owasp32), and [3.1](application-gateway-crs-rulegroups-rules.md#owasp31). These rules provide baseline security against most of the top 10 vulnerabilities that Open Web Application Security Project (OWASP) identifies:
47+
The latest and most recommended ruleset version of WAF is the Default Rule Set (DRS) [2.2](application-gateway-crs-rulegroups-rules.md#drs22). In addition to the baseline security against most of the top 10 vulnerabilities that Open Web Application Security Project (OWASP) identifies, DRS 2.2 includes additional proprietary protections rules developed by Microsoft Threat Intelligence team, which expand coverage across SQL injection, XSS, and application-security attack patterns:
4848
4949
* Protection against SQL injection
5050
* Protection against cross-site scripting
@@ -56,8 +56,7 @@ sections:
5656
5757
For more information, see the [OWASP top 10 vulnerabilities](https://owasp.org/www-project-top-ten/).
5858
59-
CRS 2.2.9 and 3.0 are no longer supported for new WAF policies. We recommend that you [upgrade to the latest DRS version](/azure/web-application-firewall/ag/upgrade-ruleset-version). You can't use CRS 2.2.9 along with CRS 3.2/DRS 2.1 and later versions.
60-
59+
You can find more information about older ruleset versions and WAF's managed ruleset support policy [here].(ruleset-support-policy)
6160
- question: |
6261
What content types does the WAF support?
6362
answer: |

0 commit comments

Comments
 (0)