ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Choosing a WAF

    Scheduled Pinned Locked Moved IT Discussion
    12 Posts 3 Posters 362 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • stacksofplatesS
      stacksofplates
      last edited by

      Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

      IRJI 1 Reply Last reply Reply Quote 2
      • IRJI
        IRJ @stacksofplates
        last edited by

        @stacksofplates said in Choosing a WAF:

        Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

        I hadn't thought about that. It would be interesting to compare cost with AWS.

        stacksofplatesS dbeatoD 2 Replies Last reply Reply Quote 0
        • stacksofplatesS
          stacksofplates @IRJ
          last edited by

          @IRJ said in Choosing a WAF:

          @stacksofplates said in Choosing a WAF:

          Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

          I hadn't thought about that. It would be interesting to compare cost with AWS.

          Yeah and it would probably be easier to use if you switched providers. The Terraform provider stays the same so no config changes.

          The other downside to modsecurity is you would probably have to get another ATO right?

          IRJI 1 Reply Last reply Reply Quote 0
          • IRJI
            IRJ @stacksofplates
            last edited by

            @stacksofplates said in Choosing a WAF:

            @IRJ said in Choosing a WAF:

            @stacksofplates said in Choosing a WAF:

            Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

            I hadn't thought about that. It would be interesting to compare cost with AWS.

            Yeah and it would probably be easier to use if you switched providers. The Terraform provider stays the same so no config changes.

            The other downside to modsecurity is you would probably have to get another ATO right?

            Cloudflare doesnt have an ATO so that's not an option...

            I dont think modsecurity would be considered a big enough change to trigger the process, but I could be wrong. Since we are already using NGINX in our application, it would just be recompiling it from source that would be needed. Even if it is considered a major change, we would just implement it when doing our yearly audit and kill two birds with one stone.

            stacksofplatesS 1 Reply Last reply Reply Quote 0
            • stacksofplatesS
              stacksofplates @IRJ
              last edited by

              @IRJ said in Choosing a WAF:

              @stacksofplates said in Choosing a WAF:

              @IRJ said in Choosing a WAF:

              @stacksofplates said in Choosing a WAF:

              Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

              I hadn't thought about that. It would be interesting to compare cost with AWS.

              Yeah and it would probably be easier to use if you switched providers. The Terraform provider stays the same so no config changes.

              The other downside to modsecurity is you would probably have to get another ATO right?

              Cloudflare doesnt have an ATO so that's not an option...

              I dont think modsecurity would be considered a big enough change to trigger the process, but I could be wrong. Since we are already using NGINX in our application, it would just be recompiling it from source that would be needed. Even if it is considered a major change, we would just implement it when doing our yearly audit and kill two birds with one stone.

              Ah ok. I never looked into whether Cloudflare was a possibility for that or not. It seems ridiculous that they aren't but oh well.

              Ah, man compiling that from source will be annoying for your patching cycles.

              IRJI 1 Reply Last reply Reply Quote 0
              • IRJI
                IRJ @stacksofplates
                last edited by

                @stacksofplates said in Choosing a WAF:

                Ah, man compiling that from source will be annoying for your patching cycles.

                That is definitely an initial CON I need to add to my list.

                1 Reply Last reply Reply Quote 0
                • dbeatoD
                  dbeato @IRJ
                  last edited by

                  @IRJ said in Choosing a WAF:

                  @stacksofplates said in Choosing a WAF:

                  Another option is to use Cloudflare. You can use Terraform to define your WAF rules with them also.

                  I hadn't thought about that. It would be interesting to compare cost with AWS.

                  Well AWS Shield can be expensive in a “sense” about 3K or so a month.

                  1 Reply Last reply Reply Quote 0
                  • dbeatoD
                    dbeato
                    last edited by

                    I use AWS WAF with Cloudfront, Terraform, Cognito and any functions for the applications so it is very powerful.

                    IRJI 1 Reply Last reply Reply Quote 1
                    • IRJI
                      IRJ @dbeato
                      last edited by

                      @dbeato said in Choosing a WAF:

                      I use AWS WAF with Cloudfront, Terraform, Cognito and any functions for the applications so it is very powerful.

                      @dbeato said in Choosing a WAF:

                      I use AWS WAF with Cloudfront, Terraform, Cognito and any functions for the applications so it is very powerful.

                      Are you using owasp top 10 rules?

                      dbeatoD 1 Reply Last reply Reply Quote 0
                      • dbeatoD
                        dbeato @IRJ
                        last edited by

                        @IRJ said in Choosing a WAF:

                        @dbeato said in Choosing a WAF:

                        I use AWS WAF with Cloudfront, Terraform, Cognito and any functions for the applications so it is very powerful.

                        @dbeato said in Choosing a WAF:

                        I use AWS WAF with Cloudfront, Terraform, Cognito and any functions for the applications so it is very powerful.

                        Are you using owasp top 10 rules?

                        Yes

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post