{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
        "slug": "dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/"
        },
        "title": "Review WAF custom-rule coverage before adding Application Gateway IPv6",
        "summary": "Dual-stack frontend support does not imply IPv6 support for every IP-address or geographic WAF custom rule.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:20+00:00",
        "modified_at": "2026-09-10T02:01:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 235,
        "potentially_affected": "Azure Application Gateway v2 dual-stack frontend designs using WAF custom rules.",
        "dse_recommendation": "Validate IPv6 rule support and the accepted traffic policy before approving a dual-stack gateway.",
        "primary_source": {
            "name": "Configure Application Gateway with a frontend public IPv6 address using the Azure portal - Azure Application Gateway | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Application Gateway&#8217;s documented dual-stack limitations exclude IPv6 traffic from IP-address-based custom-rule matching and geographic custom rules. A WAF policy containing geographic rules can also fail association with a dual-stack gateway.</p>\n<p>Dual-stack frontends require v2 and a new gateway; existing IPv4 gateways cannot be upgraded in place. IPv6-only gateways and IPv6 backends are not supported. The IPv6 frontend therefore does not establish an end-to-end IPv6 backend design. <a href=\"https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the proposed frontend address families, current WAF policy and exact custom-rule conditions. Review current limitations before assuming an IPv4 security test also covers IPv6.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends documenting how each required access restriction will be enforced for both client address families. Resolve unsupported IP or geographic conditions with the security owner before deployment. Include the new-gateway requirement in change planning rather than describing the work as adding one address to the existing resource. Do not silently remove a required restriction simply to associate the policy.</p>\n<h2>Verification</h2>\n<p>Use approved IPv4 and IPv6 clients to test the intended permitted and rejected requests. First establish that the IPv6 client itself has suitable connectivity. Inspect actual policy association and relevant request outcomes, then record any unsupported requirement as an unresolved design issue. Keep frontend connectivity evidence separate from proof of WAF enforcement and backend reachability.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Configure Application Gateway with a frontend public IPv6 address using the Azure portal</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nApplication Gateway’s documented dual-stack limitations exclude IPv6 traffic from IP-address-based custom-rule matching and geographic custom rules. A WAF policy containing geographic rules can also fail association with a dual-stack gateway.\nDual-stack frontends require v2 and a new gateway; existing IPv4 gateways cannot be upgraded in place. IPv6-only gateways and IPv6 backends are not supported. The IPv6 frontend therefore does not establish an end-to-end IPv6 backend design. Microsoft Learn.\nApplicability\nIdentify the proposed frontend address families, current WAF policy and exact custom-rule conditions. Review current limitations before assuming an IPv4 security test also covers IPv6.\nDSE recommendation\nDSE recommends documenting how each required access restriction will be enforced for both client address families. Resolve unsupported IP or geographic conditions with the security owner before deployment. Include the new-gateway requirement in change planning rather than describing the work as adding one address to the existing resource. Do not silently remove a required restriction simply to associate the policy.\nVerification\nUse approved IPv4 and IPv6 clients to test the intended permitted and rejected requests. First establish that the IPv6 client itself has suitable connectivity. Inspect actual policy association and relevant request outcomes, then record any unsupported requirement as an unresolved design issue. Keep frontend connectivity evidence separate from proof of WAF enforcement and backend reachability.\nOfficial references\nMicrosoft Learn: Configure Application Gateway with a frontend public IPv6 address using the Azure portal. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nApplication Gateway’s documented dual-stack limitations exclude IPv6 traffic from IP-address-based custom-rule matching and geographic custom rules. A WAF policy containing geographic rules can also fail association with a dual-stack gateway.\n\nDual-stack frontends require v2 and a new gateway; existing IPv4 gateways cannot be upgraded in place. IPv6-only gateways and IPv6 backends are not supported. The IPv6 frontend therefore does not establish an end-to-end IPv6 backend design. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal).\n\n## Applicability\n\nIdentify the proposed frontend address families, current WAF policy and exact custom-rule conditions. Review current limitations before assuming an IPv4 security test also covers IPv6.\n\n## DSE recommendation\n\nDSE recommends documenting how each required access restriction will be enforced for both client address families. Resolve unsupported IP or geographic conditions with the security owner before deployment. Include the new-gateway requirement in change planning rather than describing the work as adding one address to the existing resource. Do not silently remove a required restriction simply to associate the policy.\n\n## Verification\n\nUse approved IPv4 and IPv6 clients to test the intended permitted and rejected requests. First establish that the IPv6 client itself has suitable connectivity. Inspect actual policy association and relevant request outcomes, then record any unsupported requirement as an unresolved design issue. Keep frontend connectivity evidence separate from proof of WAF enforcement and backend reachability.\n\n## Official references\n\n[Microsoft Learn: Configure Application Gateway with a frontend public IPv6 address using the Azure portal](https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review WAF custom-rule coverage before adding Application Gateway IPv6",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/",
                "headline": "Review WAF custom-rule coverage before adding Application Gateway IPv6",
                "description": "Dual-stack frontend support does not imply IPv6 support for every IP-address or geographic WAF custom rule.",
                "abstract": "Dual-stack frontend support does not imply IPv6 support for every IP-address or geographic WAF custom rule.",
                "articleBody": "Source facts\nApplication Gateway’s documented dual-stack limitations exclude IPv6 traffic from IP-address-based custom-rule matching and geographic custom rules. A WAF policy containing geographic rules can also fail association with a dual-stack gateway.\nDual-stack frontends require v2 and a new gateway; existing IPv4 gateways cannot be upgraded in place. IPv6-only gateways and IPv6 backends are not supported. The IPv6 frontend therefore does not establish an end-to-end IPv6 backend design. Microsoft Learn.\nApplicability\nIdentify the proposed frontend address families, current WAF policy and exact custom-rule conditions. Review current limitations before assuming an IPv4 security test also covers IPv6.\nDSE recommendation\nDSE recommends documenting how each required access restriction will be enforced for both client address families. Resolve unsupported IP or geographic conditions with the security owner before deployment. Include the new-gateway requirement in change planning rather than describing the work as adding one address to the existing resource. Do not silently remove a required restriction simply to associate the policy.\nVerification\nUse approved IPv4 and IPv6 clients to test the intended permitted and rejected requests. First establish that the IPv6 client itself has suitable connectivity. Inspect actual policy association and relevant request outcomes, then record any unsupported requirement as an unresolved design issue. Keep frontend connectivity evidence separate from proof of WAF enforcement and backend reachability.\nOfficial references\nMicrosoft Learn: Configure Application Gateway with a frontend public IPv6 address using the Azure portal. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:25:20+00:00",
                "dateModified": "2026-09-10T02:01:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review WAF custom-rule coverage before adding Application Gateway IPv6"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 235,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Configure Application Gateway with a frontend public IPv6 address using the Azure portal - Azure Application Gateway | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal"
                }
            }
        ]
    }
}