5 ms·
Yes, also Ivanti. And Palo Alto. And Cisco. And Dell (unless they spun that off already). Most of the devices that rely on a scheme similar to inkjet printers
by oneplane 2y ago
Yes, also Ivanti. And Palo Alto. And Cisco. And Dell (unless they spun that off already).
Most of the devices that rely on a scheme similar to inkjet printers (but with an even shorter shelf life) are going to be that way. This is because the money is not in the software, but in administrative choices (licensing, support contracts based on lifespan of hardware etc).
Since most deployment scenarios don't really need a proprietary ASIC to handle filtering, you'd almost universally be better off with a system that is built around generic white box hardware and an OS that is kept up-to-date. But that requires more knowledge and skills, and most people and companies would rather not invest in that for various reasons.
As for where you'd get your money's worth: it's mostly in the threat feeds. A well-tested, verified feed of known bad things (subnets, packet contents, behaviour) is much more useful than paying someone to keep a spare fan on the shelf so they can bring it to you "just in case".
- bigfatkitten 2y agoThe main thing the commercial players offer that open source doesn't do well is application level filtering. I want to be able to allow RTP across this giant port range but not just any UDP, or allow TLS exchanges with only certain SNI domains, not Cloudflare's entire address space. If you want to do this, you need to select the least bad vendor. In my experience, site categorisation is about the only 'feed' worth paying for.
- transpute 2y agoIs application filtering always bundled with hardware? Open-source software already ingests URLs for adblock. https://zvelo.com/about/company-history/ https://zvelo.com/about/company-history/
- megous 2y agoOpensource has dynamic RTP port opening based on SIP/SDP communication. https://wiki.nftables.org/wiki-nftables/index.php/Conntrack_helpers https://wiki.nftables.org/wiki-nftables/index.php/Conntrack_... You can also send packets to userspace from nftables and do your SNI parsing/deep inspection/decision there. I used that a few times to do various things, like duplicate packet removal, etc. It's very flexible.
- bigfatkitten 2y agoThe Lego pieces are indeed available for you go build this stuff yourself, but the engineering effort required to do so quickly make Palo Alto or Checkpoint's licensing look extremely cheap.
- megous 2y agoYeah, until you hit some turd in fortinet (see how they mangle SDP if you send re-INVITE in a SIP dialog, even with all SIP protocol handling checkboxes disabled) and have to spend weeks with support and many hours of debugging and back and forth just trying to convince them they have an issue, after initially spending ~ 10h of dev/debugging time on trying to convince SIP phone manufacturer they have buggy SIP phone, before realizing different SIP packets are arriving on a SIP phone then are comming from PBX, because of this amazing forticrap middlebox. All the while whole company has issues with SIP telephony during attended transfers for months on end, disrupting commuincation with customers. That shit pays for itself. :D
- oneplane 2y agoIIRC that's all under the NGFW umbrella, you can use things like zenarmor for that, it's essentially the 'paid feed' I was referring to, but as a plugin to existing FOSS firewalls. Other useful feeds might be known malicious IPs and ASNs, dropping any packets matching those is very cheap and very effective. But they have to be reliable and not have false positives. You could get a white box firewall put something like OpnSense business edition on it, and add Zenarmor. Works forever until FreeBSD no longer supports the hardware or until the hardware dies. And you get all the support and vetting/testing from those software options as well. But realistically, if you're doing NGFW things you're probably in a compliance regime that doesn't allow for much choice of hardware and software and you're screwed anyway (compliance might require you to buy something like a Cisco or Palo Alto device + subscription, but then it turns out they run PHP as root under the hood and gets pwned monthly by a teenager on the other side of the world).