-| 7 | **Ingress security** | Application Gateway WAF_v2 with public IP, WAF policy, and Key Vault TLS certificates (in spoke) | With the network foundation, peering, NSG rules, and DDoS protection in place, the Application Gateway can deploy into a spoke subnet that's already locked down. The WAF policy inspects traffic before it reaches any backend. | [Quickstart: Direct web traffic with Azure Application Gateway](/azure/application-gateway/quick-create-portal) and [Create WAF policies for Application Gateway](/azure/web-application-firewall/ag/create-waf-policy-ag) |
0 commit comments