OHDSI Home | Forums | Wiki | Github

Suddenly started getting 403 mod security action, WAF- azure

We have application (OHDSI Atlas- http) deployed on Azure Cloud (ISAS). We have set up of WAF in prevention mode. The application is working since last 8 months. Suddenly since last 2 weeks we are getting 403 for PUT and POST requests. Mostly looks like SQL injection rules and some Protocol related.

We had also raised request with MS support, and we had disabled some of the rules. It was working properly, but again started getting different rule hits.

Note- Recently, When we had added one more application to same application gateway with https. Is this can affect the other application?

I don’t have specific experience with Asure and WAF, but 403 is an authorization failure. Do you have security enabled? If so, is it possible that some configuration is filtering out the authorization headers sent to the server, and therefore it thinks you are not authenticated?

1 Like
t