Hey everyone !

I’m looking into spinning up a WAF as the number of services I’m hosting is slowly growing. I want to have a better understanding of the traffic and also have a relative peace of mind that if there is a flaw in one of the services I’m hosting, the WAF could help mitigate it.

I’ve seen two big names come up while searching :

  • SafeLine
  • BunkerWeb

They are popular and look quite good all around but I don’t want to just mindlessly take the project with the most GitHub stars.

What WAF are you using / have you used ? Which ones do you recommand ?

BlackEco
link
fedilink
English
2
edit-2
13d

I have been using BunkerWeb for the past 4 years and have been mostly happy with it. Its default settings are sometimes a bit agressive but you can change those globally or service per service.

The fact that they lock Letsencrypt DNS-01 behind the pro version is so incredibly annoying.

BlackEco
link
fedilink
English
113d

Yeah, I use Caddy for that, as I only use DNS-01 for local-only services.

@Admax@lemmy.world
creator
link
fedilink
English
113d

Thanks that’s good to know :)

Crowdsec

@Admax@lemmy.world
creator
link
fedilink
English
113d

I just read a bit about it and it sounds quite interesting with the community aspect of it all. I’ll give it a deeper look later, thanks !

Admiral Patrick
link
fedilink
English
3
edit-2
13d

I run a custom build of Nginx with a few extra modules compiled in:

Some guidance can be found here: https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/

That guidance is for NginxPlus, but you can compile the dynamic module yourself with the community versions.

Create a post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

  • 1 user online
  • 331 users / day
  • 684 users / week
  • 1.49K users / month
  • 3.91K users / 6 months
  • 1 subscriber
  • 4.09K Posts
  • 84.2K Comments
  • Modlog