Spyke

Syndicated from the fediverse. Read and engage on the original instance.

View original on lemmy.world
selfhosted·SelfhostedbyAdmax

Looking for Recommendations - FOSS WAF

Hey everyone !

I'm looking into spinning up a WAF as the number of services I'm hosting is slowly growing. I want to have a better understanding of the traffic and also have a relative peace of mind that if there is a flaw in one of the services I'm hosting, the WAF could help mitigate it.

I've seen two big names come up while searching :

  • SafeLine
  • BunkerWeb

They are popular and look quite good all around but I don't want to just mindlessly take the project with the most GitHub stars.

What WAF are you using / have you used ? Which ones do you recommand ?

View original on lemmy.world
20

9 replies

I just read a bit about it and it sounds quite interesting with the community aspect of it all. I'll give it a deeper look later, thanks !

1

I run a custom build of Nginx with a few extra modules compiled in:

Some guidance can be found here: https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/

That guidance is for NginxPlus, but you can compile the dynamic module yourself with the community versions.

3

I have been using BunkerWeb for the past 4 years and have been mostly happy with it. Its default settings are sometimes a bit agressive but you can change those globally or service per service.

2
Taasz/Woofreply
lemmy.blahaj.zone

The fact that they lock Letsencrypt DNS-01 behind the pro version is so incredibly annoying.

4
lemmy.world

I’ve been looking for a good self-hosted WAF for a while. I tried Open AppSec — way too buggy. Then I gave BunkerWeb a shot, but the setup was just too complicated (maybe I’m just not that good 😅). SafeLine has a lot of paid features, but honestly, the Lite version already covers most of what I need. $100/year is pretty reasonable, rich features, the setup and configs are super simple.

1

I ended up going with Crowdsec.

The setup was a bit of a challenge as I like to do it the RTFM way abd that there is a bunch of concepts to grasp before you really understand what you are doing, but since then it's been working pretty great ! And it's free (as in you are providing them with data on the occurence of threats etc, so you don't pay)

2

You reached the end

Looking for Recommendations - FOSS WAF | Spyke