# Review WAF custom-rule coverage before adding Application Gateway IPv6

> Dual-stack frontend support does not imply IPv6 support for every IP-address or geographic WAF custom rule.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:25:20+00:00
- Modified: 2026-09-10T02:01:57+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Dual-stack frontend support does not imply IPv6 support for every IP-address or geographic WAF custom rule.

## Potentially affected

Azure Application Gateway v2 dual-stack frontend designs using WAF custom rules.

## DSE recommendation

Validate IPv6 rule support and the accepted traffic policy before approving a dual-stack gateway.

## Article

## Source facts

Application Gateway’s documented dual-stack limitations exclude IPv6 traffic from IP-address-based custom-rule matching and geographic custom rules. A WAF policy containing geographic rules can also fail association with a dual-stack gateway.

Dual-stack frontends require v2 and a new gateway; existing IPv4 gateways cannot be upgraded in place. IPv6-only gateways and IPv6 backends are not supported. The IPv6 frontend therefore does not establish an end-to-end IPv6 backend design. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal).

## Applicability

Identify the proposed frontend address families, current WAF policy and exact custom-rule conditions. Review current limitations before assuming an IPv4 security test also covers IPv6.

## DSE recommendation

DSE recommends documenting how each required access restriction will be enforced for both client address families. Resolve unsupported IP or geographic conditions with the security owner before deployment. Include the new-gateway requirement in change planning rather than describing the work as adding one address to the existing resource. Do not silently remove a required restriction simply to associate the policy.

## Verification

Use approved IPv4 and IPv6 clients to test the intended permitted and rejected requests. First establish that the IPv6 client itself has suitable connectivity. Inspect actual policy association and relevant request outcomes, then record any unsupported requirement as an unresolved design issue. Keep frontend connectivity evidence separate from proof of WAF enforcement and backend reachability.

## Official references

[Microsoft Learn: Configure Application Gateway with a frontend public IPv6 address using the Azure portal](https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal). Source retrieved September 9, 2026.

## Primary reference

- Name: Configure Application Gateway with a frontend public IPv6 address using the Azure portal - Azure Application Gateway | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/application-gateway/ipv6-application-gateway-portal
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review WAF custom-rule coverage before adding Application Gateway IPv6,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-396-review-waf-custom-rule-coverage-before-adding-application-gateway-ipv6/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
