新Azure Web应用防火墙能否按IP地址限定FTP端口访问范围?
Hey there! Let's clear this up first: Azure Web Application Firewall (WAF) is designed specifically for filtering HTTP/HTTPS traffic — it doesn't handle access control for FTP/FTPS ports directly. FTP uses a separate protocol channel, and its access restrictions are managed through the Web App's native settings, not WAF.
The good news is that Azure Web App now fully supports IP address restrictions for FTP/FTPS access, which solves the "open to all IPs" problem you faced a year ago. Here are the two main ways to set this up:
- Azure Portal GUI: Navigate to your Web App's "Network" settings, find the "Configure IP restrictions" section. Add a new rule, specify the allowed IP address/range, set the action to "Allow", and make sure to select
All(which includes FTP) or explicitly target FTP in the rule's scope. Give it a high priority (like 100) to ensure it takes precedence over any default rules. - Azure CLI Command: If you prefer command-line tools, use this snippet to add an FTP-specific IP allowlist:
az webapp config access-restriction add --resource-group <your-resource-group> --name <your-webapp-name> --rule-name "Allow_FTP_Trusted_IPs" --ip-address <your-allowed-ip/cidr> --priority 100 --action Allow --targets ftp
A quick note: Azure Web App uses port 21 for FTP and 990 for FTPS by default. These ports' access is tied directly to the Web App's IP restriction rules — you don't need to mess with WAF rules here, since WAF only governs traffic on HTTP/HTTPS ports (80/443).
To wrap it up: You absolutely can lock down FTP access to specific IP addresses/ranges on Azure Web App now. WAF isn't involved in this particular scenario, but the Web App's built-in features have you covered, so you won't have to worry about open FTP access anymore.
内容的提问来源于stack exchange,提问作者codefish

