Azure WAF frontdoor vs Azure WAF application gateway - Microsoft Q&A (2024)

@RAIHANKHAN-2722
Thank you for your post!

Since I'm part of the Azure Security Center team and this looks like a networking issue, I've removed the "azure-security-center" tag and have reached out to our Networking team to look into this issue.

In the meantime, I was able to do some research on this and will post my colleague's answer below.

Azure Front Door WAF and Azure App Gateway WAF are very similar in functionality, one of the main differences is where the WAF is applied.

Azure Front Door applies the WAF filters at edge locations, way before it gets to the datacenter. App Gateway applies the filter when it enters your VNET via the App Gateway.

Your best bet is to choose between the 2 in an application delivery perspective, and then apply whichever WAF you choose.

If what you are using is inside of a VNET and inside a single region, App Gateway will be your best bet. For a multi-regional deployment or global route filtering, use Azure Front Door.

Source: https://social.msdn.microsoft.com/Forums/en-US/77c6c55a-203f-4d8a-b1b9-0c54dfcfd530/comparison-between-application-gateway-waf-and-front-door-waf

Additional Links:
Application Gateway pricing
Azure Front Door pricing
How WAF features differ with Azure Front Door, Azure Application Gateway and Azure CDN.

Please allow some time for our networking team to look into your issue and answer any questions I missed.
Thank you for your time and patience throughout this issue.

Please remember to "Accept Answer" if any answer/reply helped, so that others in the community facing similar issues can easily find the solution.

Azure WAF frontdoor vs Azure WAF application gateway - Microsoft Q&A (2024)

FAQs

What is the difference between Azure Application Gateway WAF and Azure front door WAF? ›

Azure Front Door and Azure Application Gateway are both load balancers for HTTP/HTTPS traffic, but they have different scopes. Front Door is a global service that can distribute requests across regions, while Application Gateway is a regional service that can balance requests within a region.

What is the difference between Azure front door and traffic manager and Application Gateway? ›

Azure Front Door helps load balance traffic across regions. Application Gateway routes and load-balances traffic internally in the application to the various services that satisfy client business needs. A multiregion N-tier application that uses Traffic Manager to route incoming requests to a primary region.

What are the different types of WAF in Azure? ›

There are two options when applying WAF policies in Azure. WAF with Azure Front Door is a globally distributed, edge security solution. WAF with Application Gateway is a regional, dedicated solution. We recommend you choose a solution based on your overall performance and security requirements.

What is the difference between Azure WAF and WAF V2? ›

Azure Application Gateway and Web Application Firewall (WAF) V2 now offer additional features such as autoscaling, availability, zone redundancy, higher performance, faster operations and improved throughput compared to V1.

Why use an Azure front door? ›

Azure Front Door helps provide fast, secure, and scalable access to web applications. It also helps protect cloud-based apps and provides high-bandwidth content.

What are the different types of WAF? ›

The web application firewall (WAF) marketplace is diverse, with various deployment options based on an organization's application and security requirements. There are three primary types of WAFs: a cloud-based WAF, software-based WAF, and hardware-based WAF. Each type of WAF has its own advantages and disadvantages.

What is the difference between Azure firewall and Application Gateway? ›

Firewall and Application Gateway in parallel

Azure WAF in Azure Application Gateway protects inbound traffic to the web workloads, and the Azure Firewall inspects inbound traffic for the other applications. The Azure Firewall will cover outbound flows from both workload types.

Why use Azure Application Gateway? ›

Application Gateway is integrated with several Azure services. Azure Traffic Manager supports multiple-region redirection, automatic failover, and zero-downtime maintenance. Use Azure Virtual Machines, virtual machine scale sets, or the Web Apps feature of Azure App Service in your back-end pools.

What is the difference between Azure Application Gateway and load balancer? ›

Azure Application Gateway is a web traffic (OSI layer 7) load balancer that enables you to manage traffic to your web applications. Traditional load balancers operate at the transport layer (OSI layer 4 - TCP and UDP) and route traffic based on source IP address and port, to a destination IP address and port.

What is the difference between a gateway and a WAF? ›

WAFs are crucial to any. By integrating API gateways and WAFs, the gateway efficiently handles traffic, while the WAF focuses on securing against potential threats, creating a comprehensive solution for API management and security.

What is Application Gateway WAF? ›

The Azure Web Application Firewall (WAF) on Azure Application Gateway actively safeguards your web applications against common exploits and vulnerabilities.

What are the two modes that a WAF policy can use? ›

You can configure a WAF policy to run in two modes:
  • Detection: When a WAF runs in detection mode, it only monitors and logs the request and its matched WAF rule to WAF logs. It doesn't take any other actions. ...
  • Prevention: In prevention mode, a WAF takes the specified action if a request matches a rule.
Oct 4, 2023

What is the difference between Application Gateway and front door WAF? ›

Both services offer different security features depending on your use case. The Front Door handles DDOS protection and WAF for security. On the other hand, the Application Gateway provides Centralized Authentication and protects your app against DDOS attacks, Cross-Site Scripting, and SQL Injection.

What is the limitation of Azure Application Gateway WAF v2? ›

Azure Application gateway V2 has a maximum file upload limit of 4 GB for both Standard and WAF SKU (when you are using the new WAF engine with CRS 3.2 or newer). So, it doesn't matter if you are using WAF or not, the maximum limit for file upload remains at 4 GB as of today.

Does a WAF replace a firewall? ›

Choosing an Application or Network Firewall

However, a WAF cannot protect from attacks at the network layer, so it should supplement a network firewall rather than replace it.

What is the difference between Azure CDN and Application Gateway? ›

Front Door is also a Content Delivery Network (CDN) platform designed for global traffic management and acceleration while Application Gateway is primarily focused on application-level routing and load balancing within a specific region or virtual network.

What is the difference between application level gateway and WAF? ›

In simpler language: the API gateway provides basic access point control to the API endpoint, ensuring that those accessing it are likely to be legitimate and/or accredited users. WAFs, by contrast, are more security-oriented, adding an additional layer of protection.

What is Application Gateway with WAF? ›

WAF is a feature of the Application Gateway that provides centralized protection for your web applications from common exploits and vulnerabilities. WAF is based on rules from the Open Web Application Security Project (OWASP) core rule sets 3.0 or 2.2.

What is the difference between Azure Front Door and Azure CDN? ›

Microsoft Azure presents two services, Azure Front Door which is a cloud-based service that delivers a scalable and safe entry point for the applications, and Azure CDN (Content Delivery Network) which is a service that allows enterprises to deliver content to users fast and efficiently.

Top Articles
Latest Posts
Article information

Author: Corie Satterfield

Last Updated:

Views: 6548

Rating: 4.1 / 5 (42 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Corie Satterfield

Birthday: 1992-08-19

Address: 850 Benjamin Bridge, Dickinsonchester, CO 68572-0542

Phone: +26813599986666

Job: Sales Manager

Hobby: Table tennis, Soapmaking, Flower arranging, amateur radio, Rock climbing, scrapbook, Horseback riding

Introduction: My name is Corie Satterfield, I am a fancy, perfect, spotless, quaint, fantastic, funny, lucky person who loves writing and wants to share my knowledge and understanding with you.