Skip to content

Commit 8db0cb1

Browse files
Merge pull request #312721 from yuvalpery/patch-12
Revise WAF ruleset details to version 2.2
2 parents 5e6bd4d + 724c027 commit 8db0cb1

1 file changed

Lines changed: 2 additions & 3 deletions

File tree

articles/web-application-firewall/ag/application-gateway-waf-faq.yml

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,7 @@ sections:
4444
- question: |
4545
What rules are currently available for the WAF?
4646
answer: |
47-
The WAF currently supports Default Rule Set (DRS) [2.1](application-gateway-crs-rulegroups-rules.md#drs21), Core Rule Set (CRS) [3.2](application-gateway-crs-rulegroups-rules.md#owasp32), and [3.1](application-gateway-crs-rulegroups-rules.md#owasp31). These rules provide baseline security against most of the top 10 vulnerabilities that Open Web Application Security Project (OWASP) identifies:
47+
The latest and most recommended ruleset version of WAF is the Default Rule Set (DRS) [2.2](application-gateway-crs-rulegroups-rules.md#drs22). In addition to the baseline security against most of the top 10 vulnerabilities that Open Web Application Security Project (OWASP) identifies, DRS 2.2 includes additional proprietary protections rules developed by Microsoft Threat Intelligence team, which expand coverage across SQL injection, XSS, and application-security attack patterns:
4848
4949
* Protection against SQL injection
5050
* Protection against cross-site scripting
@@ -56,8 +56,7 @@ sections:
5656
5757
For more information, see the [OWASP top 10 vulnerabilities](https://owasp.org/www-project-top-ten/).
5858
59-
CRS 2.2.9 and 3.0 are no longer supported for new WAF policies. We recommend that you [upgrade to the latest DRS version](/azure/web-application-firewall/ag/upgrade-ruleset-version). You can't use CRS 2.2.9 along with CRS 3.2/DRS 2.1 and later versions.
60-
59+
You can find more information about older ruleset versions and WAF's managed ruleset support policy [here].(ruleset-support-policy)
6160
- question: |
6261
What content types does the WAF support?
6362
answer: |

0 commit comments

Comments
 (0)