<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Azure App Gateway WAF ruleset in Esri Software Security &amp; Privacy Questions</title>
    <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/179573#M25</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;Is there a rule set availability for ArcGIS Enterprise deployments deployed in Azure behind an App Gateway with WAF enabled? Can these be loaded via the custom rule set functionality? Looking for some official Esri documentation if it is around.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 09 Mar 2020 02:29:38 GMT</pubDate>
    <dc:creator>FraserHand</dc:creator>
    <dc:date>2020-03-09T02:29:38Z</dc:date>
    <item>
      <title>Azure App Gateway WAF ruleset</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/179573#M25</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;Is there a rule set availability for ArcGIS Enterprise deployments deployed in Azure behind an App Gateway with WAF enabled? Can these be loaded via the custom rule set functionality? Looking for some official Esri documentation if it is around.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Mar 2020 02:29:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/179573#M25</guid>
      <dc:creator>FraserHand</dc:creator>
      <dc:date>2020-03-09T02:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: Azure App Gateway WAF ruleset</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/179574#M26</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have the same question. Since we deployed enterprise ArcGIS onto Azure, with the network structure like Internet -&amp;gt; Traffic Manager -&amp;gt; App Gateway -&amp;gt;&amp;nbsp; Filewall -&amp;gt; VMs, there have been inaccessible issues with some services, especially when using Dashboards with some secured feature services. Cloud team is asking for such WAF policy profile rule set provided by ESRI that can be downloaded.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Oct 2020 23:21:09 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/179574#M26</guid>
      <dc:creator>JYI</dc:creator>
      <dc:date>2020-10-30T23:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Azure App Gateway WAF ruleset</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1058549#M127</link>
      <description>&lt;P&gt;Did you ever get any information from Esri&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 14:58:49 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1058549#M127</guid>
      <dc:creator>BenWalker1</dc:creator>
      <dc:date>2021-05-17T14:58:49Z</dc:date>
    </item>
    <item>
      <title>Re: Azure App Gateway WAF ruleset</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1113173#M138</link>
      <description>&lt;P&gt;So far no... It seems that we have moved away from traffic manager. The infrastructure is changed to use FortiGate.. How this will have effect on the WAF policy not known yet until next year when migrating to the new env.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Nov 2021 13:26:31 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1113173#M138</guid>
      <dc:creator>JYI</dc:creator>
      <dc:date>2021-11-02T13:26:31Z</dc:date>
    </item>
    <item>
      <title>Re: Azure App Gateway WAF ruleset</title>
      <link>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1125921#M139</link>
      <description>&lt;P&gt;ESRI support just sent me the document which is available in December only, entitled "&lt;STRONG&gt;ArcGIS Enterprise Web Application Filter Rules&lt;/STRONG&gt;". It says "&lt;STRONG&gt;&lt;U&gt;This is required reading if you are implementing a WAF.&lt;/U&gt;&lt;/STRONG&gt;" To us, "OWASP Core Ruleset Guidance" is the most important part that we have been waiting for, although Azure team is not happy with so many rules that need to be disabled. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; It also says "do not distribute or post publicly" so ask ESRI support for it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 15:56:17 GMT</pubDate>
      <guid>https://community.esri.com/t5/esri-software-security-privacy-questions/azure-app-gateway-waf-ruleset/m-p/1125921#M139</guid>
      <dc:creator>JYI</dc:creator>
      <dc:date>2021-12-14T15:56:17Z</dc:date>
    </item>
  </channel>
</rss>

