An Azure service that provides protection for web apps.
Azure WAF bot protection distinguishes between Good, Bad, and Unknown bots and treats verified search engine crawlers (such as Googlebot) as Good bots. By default, Good bots are allowed, while Bad and some Unknown bots can be blocked or logged depending on configuration.
To investigate and mitigate Google crawler blocking:
- Confirm bot protection configuration
- In the WAF policy (Front Door or Application Gateway), check whether the Bot Protection / Bot Manager rule set is enabled.
- Verify the action configured for Good bots. It should be Allow, not Block or Redirect.
- On Azure Front Door, the bot protection rule set supports custom actions per bot category (Bad, Good, Unknown) and WAF actions include Allow, Block, Log, and Redirect. Ensure no custom rule is overriding Good bots with a more restrictive action.
- Check for custom rules taking precedence (Front Door)
- Custom rules are evaluated before the Default Rule Set and bot protection rules.
- If a request matches a custom rule, that rule’s action is applied and no other rules are processed.
- Review custom rules for conditions that might inadvertently match Googlebot traffic (e.g., IP ranges, paths, rate limiting, geo-filtering) and block or redirect it.
- Review WAF logs specifically for Googlebot traffic
- WAF logs show every request that is matched or blocked.
- Ensure WAF logging is enabled and query:
- For Front Door Standard/Premium:
AzureDiagnostics | where Category == "FrontDoorWebApplicationFirewallLog" | where TimeGenerated > ago(1d) | where action_s == "Block" - For Front Door Classic:
AzureDiagnostics | where Category == "FrontdoorWebApplicationFirewallLog" | where TimeGenerated > ago(1d) | where action_s == "Block"
- For Front Door Standard/Premium:
- Narrow further by:
- Request URI paths Google is crawling.
- Known Googlebot user-agent strings.
- If Googlebot is being blocked, the log entry will show which rule (custom, DRS, or bot rule) is responsible.
- Validate that Googlebot is classified as a Good bot
- Good bots include verified search engine bots (such as Googlebot and Bingbot).
- If Googlebot requests are being treated as Unknown or Bad bots, they might be coming from IPs not recognized as legitimate Googlebot sources or with modified user agents.
- In that case, adjust bot protection actions so that Unknown bots are logged instead of blocked, then analyze logs to see how Googlebot traffic is being categorized.
- Use exclusions or tuning if a rule is causing false positives
- If a specific WAF rule (from the Default Rule Set or a custom rule) is blocking legitimate Googlebot traffic, tune the WAF:
- Create exclusions for specific request attributes (paths, query parameters, headers) that Googlebot uses.
- Disable or adjust only the problematic rule for the affected site/URI.
- Tuning is expected and normal for OWASP-based rule sets.
- If a specific WAF rule (from the Default Rule Set or a custom rule) is blocking legitimate Googlebot traffic, tune the WAF:
- Check for other WAF features impacting crawlers
- Geo-filtering: If enabled, ensure the countries/regions where Google’s crawlers operate are not blocked.
- IP restriction: Confirm that IP restriction rules are not blocking Googlebot IP ranges.
- Rate limiting: Ensure rate limiting rules are not throttling or blocking Google’s crawl patterns on busy endpoints.
- Verify mode on Application Gateway WAF
- If using Application Gateway WAF, confirm whether it is in Detection or Prevention mode.
- In Detection mode, WAF will only log; if Google reports blocking but logs show only detections, the block might be elsewhere (e.g., app, network, or another security layer).
By correlating Google’s reported crawl failures with WAF logs (timestamp, URI, client IP, user agent) and reviewing bot protection and custom rules, it is possible to identify whether Azure WAF is actually blocking Googlebot and then either allow Good bots, relax Unknown bot handling, or tune specific rules.
References:
- Azure Web Application Firewall on Azure Front Door
- What is Azure Web Application Firewall on Azure Application Gateway?
- Tune Azure Web Application Firewall for Azure Front Door (front-door-standard-premium)
- Tune Azure Web Application Firewall for Azure Front Door (front-door-classic)
- Troubleshoot Web Application Firewall (WAF) for Azure Application Gateway
- Web Application Firewall (WAF) on Azure Front Door
and “up-vote” wherever the information provided helps you, this can be beneficial to other community members.