<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Publishing from ArcGIS Pro triggers Azure WAF mandatory rule. in Esri Software Security &amp; Privacy Questions</title>
    <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1048610#M117</link>
    <description>&lt;P&gt;We have a base ArcGIS Enterprise deployment behind an Azure Application Gateway with WAF enabled using the OWASP 3.1 ruleset. We have run this in detection mode for a few months while we build the exceptions for valid requests. We have managed to build the exceptions for all of our valid requests except one that is triggers when publishing a hosted feature layer from ArcGIS Pro or ArcMap. The only way of overcoming this is by turning body inspection off in the WAF which defeats the purpose of having a WAF in the first place.&lt;/P&gt;&lt;P&gt;This is the WAF log for the mandatory rule.&lt;/P&gt;&lt;TABLE border="1" width="71.107160809389%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;OperationName&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;ApplicationGatewayFirewall&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;requestUri_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;/portal/sharing/rest/content/users/&amp;lt;redactedemail&amp;gt;/addItem&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;Message&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Mandatory rule. Cannot be disabled. Failed to parse request body.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleSetType_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;OWASP_CRS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleSetVersion_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;3.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleId_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;200002&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;action_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Blocked&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;site_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Global&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_message_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Access denied with code 400 (phase 2). Match of \"eq 0\" against \"REQBODY_ERROR\" required.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_data_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Multipart: Invalid boundary in C-T (characters).&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_file_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;\"/etc/nginx/modsec/&amp;lt;redacted&amp;gt;/modsecurity.conf&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_line_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;72&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Mon, 19 Apr 2021 22:21:43 GMT</pubDate>
    <dc:creator>HéctorMeléndez</dc:creator>
    <dc:date>2021-04-19T22:21:43Z</dc:date>
    <item>
      <title>Publishing from ArcGIS Pro triggers Azure WAF mandatory rule.</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1048610#M117</link>
      <description>&lt;P&gt;We have a base ArcGIS Enterprise deployment behind an Azure Application Gateway with WAF enabled using the OWASP 3.1 ruleset. We have run this in detection mode for a few months while we build the exceptions for valid requests. We have managed to build the exceptions for all of our valid requests except one that is triggers when publishing a hosted feature layer from ArcGIS Pro or ArcMap. The only way of overcoming this is by turning body inspection off in the WAF which defeats the purpose of having a WAF in the first place.&lt;/P&gt;&lt;P&gt;This is the WAF log for the mandatory rule.&lt;/P&gt;&lt;TABLE border="1" width="71.107160809389%"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;OperationName&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;ApplicationGatewayFirewall&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;requestUri_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;/portal/sharing/rest/content/users/&amp;lt;redactedemail&amp;gt;/addItem&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;Message&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Mandatory rule. Cannot be disabled. Failed to parse request body.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleSetType_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;OWASP_CRS&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleSetVersion_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;3.1.0&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;ruleId_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;200002&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;action_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Blocked&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;site_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Global&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_message_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Access denied with code 400 (phase 2). Match of \"eq 0\" against \"REQBODY_ERROR\" required.&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_data_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;Multipart: Invalid boundary in C-T (characters).&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_file_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;\"/etc/nginx/modsec/&amp;lt;redacted&amp;gt;/modsecurity.conf&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD width="15.092402464065707%"&gt;&lt;P&gt;details_line_s&lt;/P&gt;&lt;/TD&gt;&lt;TD width="80.69815195071868%"&gt;&lt;P&gt;72&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Mon, 19 Apr 2021 22:21:43 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1048610#M117</guid>
      <dc:creator>HéctorMeléndez</dc:creator>
      <dc:date>2021-04-19T22:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing from ArcGIS Pro triggers Azure WAF mandatory rule.</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1049946#M118</link>
      <description>&lt;P&gt;Troubleshooting this issue further we where able to capture the offending request using Fiddler and troubleshoot it using Postman to change the request. We found that the issue appears to be how ArcGIS Pro formats the boundary in the Content-Type header. The curly brackets in the boundary cause the WAF to block the request. If we removed the brackets from both the Content-Type boundary and the body of the request the WAF does not block the request and Portal for ArcGIS returns&amp;nbsp; "success":true.&lt;/P&gt;&lt;P&gt;This is how ArcGIS Pro formats the Content-Type request that gets blocked by the WAF:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;multipart/form-data; Charset=UTF-8; boundary={588ECA44-A34E-4798-B4A2-9AA511C17A46}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HéctorMeléndez_1-1619063914558.png" style="width: 795px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/11517i32BD989A57A4DF16/image-dimensions/795x282?v=v2" width="795" height="282" role="button" title="HéctorMeléndez_1-1619063914558.png" alt="HéctorMeléndez_1-1619063914558.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HéctorMeléndez_1-1619063914558.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This is how the WAF allows the request to go through:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;multipart/form-data; charset=UTF-8; boundary=588ECA44-A34E-4798-B4A2-9AA511C17A46&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HéctorMeléndez_0-1619063877959.png" style="width: 789px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/11516i6732740C19DCC8C4/image-dimensions/789x251?v=v2" width="789" height="251" role="button" title="HéctorMeléndez_0-1619063877959.png" alt="HéctorMeléndez_0-1619063877959.png" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;HéctorMeléndez_0-1619063877959.png&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Reading the&amp;nbsp;&lt;SPAN&gt;W3C standard for the content type&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://www.w3.org/Protocols/rfc1341/4_Content-Type.html" target="_blank" rel="noopener"&gt;https://www.w3.org/Protocols/rfc1341/4_Content-Type.html&lt;/A&gt;&amp;nbsp;It appears that it is limited to alphanumerical and the following special characters:&lt;/P&gt;&lt;PRE&gt;tspecials :=  "(" / ")" / "&amp;lt;" / "&amp;gt;" / "@"  ; Must be in 
           /  "," / ";" / ":" / "\" / &amp;lt;"&amp;gt;  ; quoted-string, 
           /  "/" / "[" / "]" / "?" / "."  ; to use within 
           /  "="                        ; parameter values&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Apr 2021 03:59:50 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1049946#M118</guid>
      <dc:creator>HéctorMeléndez</dc:creator>
      <dc:date>2021-04-22T03:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing from ArcGIS Pro triggers Azure WAF mandatory rule.</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1053060#M119</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Update Esri support referred me to these bugs -&amp;nbsp;&lt;A href="https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEwOTU4Mg==" target="_self"&gt;&lt;FONT size="4"&gt;BUG-000109582 ,&lt;/FONT&gt;&lt;/A&gt;&lt;/STRONG&gt;&lt;STRONG&gt;&amp;nbsp;&lt;A title="The uploads request while publishing a service to ArcGIS Server incorrectly passes the boundary subpart value within the Content-Type request header, thus failing in environments behind Azure WAF." href="https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEzMjE1NA==" target="_blank" rel="noopener"&gt;BUG-000132154&lt;/A&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 22:27:21 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1053060#M119</guid>
      <dc:creator>HéctorMeléndez</dc:creator>
      <dc:date>2021-05-26T22:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing from ArcGIS Pro triggers Azure WAF mandatory rule.</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1264820#M145</link>
      <description>&lt;P&gt;wow - fixed at Pro 2.9&lt;/P&gt;&lt;P&gt;&lt;A href="https://support.esri.com/en/bugs/nimbus/QlVHLTAwMDEwOTU4Mg==" target="_blank"&gt;BUG-000109582: When publishing from ArcGIS Pro, the client sets inv.. (esri.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Mar 2023 04:11:04 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1264820#M145</guid>
      <dc:creator>DavidHoy</dc:creator>
      <dc:date>2023-03-07T04:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Publishing from ArcGIS Pro triggers Azure WAF mandatory rule.</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1353802#M157</link>
      <description>&lt;P&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/357165"&gt;@HéctorMeléndez&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any chance you can share the WAF exceptions?&lt;/P&gt;&lt;P&gt;Nirmal&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 21:20:20 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/publishing-from-arcgis-pro-triggers-azure-waf/m-p/1353802#M157</guid>
      <dc:creator>NirmalOjha1</dc:creator>
      <dc:date>2023-11-27T21:20:20Z</dc:date>
    </item>
  </channel>
</rss>

