Use cases
HTTP/S TLS / SSL Offload Built-in WAF Cookie affinity URL routing
Design considerations for Application Gateway
Only use if encryption it not needed from App Gateway to backend
Stateful apps should be avoided (apps that need client to connect to the same server)
Configuration
1 - Frontend IP 2 - Listener HTTP/S, Cert SSL 3 - Rule/s 4 - Backend Pools Health probes created automatically
WAF Protection (5)
SQL injection Cross-site scripting HTTP request smuggling Remote file inclusion HTTP protocol anomalies
WAF Mode and logs
Prevention Detection - Azure Monitor - Azure Security Centre - Log Analytics
3rd Party Firewalls
Place in DMZ