Sitecore - On-Premises to Azure PaaS (ASE) Cloud Migration - Part 2
Sitecore - On-Premises to Azure PaaS (ASE) Cloud Migration - Part 2 Security aspects considered while designing the new Azure PaaS infrastructure Sitecore Web applications are hosted inside Azure App Service Environment (ASE) which is an Azure App Service feature that provides a fully isolated, dedicated and secure environment to run App Service applications WAF protection o WAF feature of the Application Gateway provides centralized protection for your web applications from common exploits and vulnerabilities. o WAF is based on rules from the Open Web Application Security Project (OWASP) core rule sets 3.0 or 2.2.9. o Sitecore Content Delivery server runs behind WAF and IP restrictions on the Web App. These limits access only from the Application Gateway · With Application Gateway, only IPs from certain countries were allowed (based on previous Ddos attack). IP restriction will be an ongoing activity and any malicious IPs will be added to the