4 ms·
IIRC that's all under the NGFW umbrella, you can use things like zenarmor for that, it's essentially the 'paid feed' I was referring to, but as a plugin to exis
by oneplane 2y ago
IIRC that's all under the NGFW umbrella, you can use things like zenarmor for that, it's essentially the 'paid feed' I was referring to, but as a plugin to existing FOSS firewalls.
Other useful feeds might be known malicious IPs and ASNs, dropping any packets matching those is very cheap and very effective. But they have to be reliable and not have false positives.
You could get a white box firewall put something like OpnSense business edition on it, and add Zenarmor. Works forever until FreeBSD no longer supports the hardware or until the hardware dies. And you get all the support and vetting/testing from those software options as well.
But realistically, if you're doing NGFW things you're probably in a compliance regime that doesn't allow for much choice of hardware and software and you're screwed anyway (compliance might require you to buy something like a Cisco or Palo Alto device + subscription, but then it turns out they run PHP as root under the hood and gets pwned monthly by a teenager on the other side of the world).