Q: Explain how you’d use Azure Application Gateway with Web Application Firewall (WAF) for a sensitive banking application.
Enterprise architectural pattern for implementing Azure Application Gateway v2 with Web Application Firewall (WAF) CRS 3.2 rules, SSL offloading, and mTLS for banking applications.
Master cloud-native security and container runtime defense: Prepare with KodeKloud's CKS course with live browser-based terminal sandboxes.
🛠️ Production Runbook & Step-by-Step Resolution
Deploy in Dedicated Subnet with Private Backend Integration
Provision Application Gateway v2 in a dedicated `/24` subnet within the hub VNet. Route incoming traffic exclusively to private IP endpoints in the AKS spoke VNet (via Private Endpoint or VNet Peering), ensuring zero public IPs on backend worker nodes.
# Backend pool configured with private AKS internal load balancer IP
az network application-gateway address-pool create \
--gateway-name agw-prod-banking \
--resource-group rg-banking \
--name aks-private-backend \
--servers 10.240.0.100
Harden WAF with OWASP Core Rule Set (CRS 3.2) & Custom Rules
Enable WAF in `Prevention` mode running CRS 3.2. Implement custom rules ahead of CRS: - **Geo-Filtering**: Block traffic from non-compliant foreign jurisdictions. - **Rate Limiting**: Restrict login/transfer endpoints to 50 requests per minute per IP. - **IP Whitelisting**: Restrict administrative API endpoints to corporate ExpressRoute / VPN ranges.
# Azure WAF Rate Limit Custom Rule
az network application-gateway waf-policy custom-rule create \
--policy-name waf-banking-policy \
--resource-group rg-banking \
--name RateLimitLogins \
--priority 10 \
--rule-type RateLimit \
--action Block \
--rate-limit-duration OneMinute \
--rate-limit-threshold 50
Enforce End-to-End TLS 1.3 Encryption & Mutual TLS (mTLS)
Do not terminate TLS to plaintext in banking. Terminate external client TLS at the Gateway with EV certificates managed in Key Vault, then re-encrypt traffic over a dedicated internal TLS connection to the AKS ingress controller. Enforce mutual TLS (mTLS) for B2B API integrations.
Enable Centralized Diagnostic Streaming to Azure Sentinel / SIEM
Stream all WAF access logs, firewall blocks, and performance metrics in real time to Azure Log Analytics and Azure Sentinel for automated threat hunting and SOC anomaly detection.
- Deploy App Gateway v2 in a dedicated subnet routing strictly to private backend AKS IP pools.
- Enforce WAF Prevention mode with custom rate-limiting rules on sensitive transaction routes.
- Mandate end-to-end TLS encryption with TLS 1.3 and mTLS client certificate verification.
- Stream WAF telemetry to Azure Sentinel for real-time security operations monitoring.