Settings

Theme

Ask HN: Cloudflare WAF Alternatives?

28 points by rco8786 a month ago · 17 comments · 1 min read


I don't know if we're ready to pull the trigger yet, but curious if other folks are looking at alternatives.

The WAF is great, but recent events have made it obvious that having a single point of failure entirely defeats the purpose of DNS being a distributed/decentralized service.

Is anyone doing anything creative here? We like the features that the WAF provides - but not at the expense of global outages. If you have a 3 9s availability SLA, you've just blown 90% of your allotted downtime because of Cloudflare's WAF.

mappu a month ago

The ability of a WAF to respond to an 0day incident is rapid rollout, 100% of endpoints, which is a SPOF no matter whether it's done via a big company or by a distributed system.

  • poguemahoney a month ago

    Assuming there are still 2 WAF makers they hopefully do two mostly independent rollouts at least with separate reviewers.. It is a little shocking to me how far we have slid down the slope to letting one monopoly decide when each part of of computing environment is up.. But if bigger organizations are down it is socially acceptable to have an outage.

cport1 a month ago

I have been using https://webdecoy.com and integrating it with Cloudflare WAF.

server_man3000 a month ago

Not worth. Competitors like Bunny CDN which is much smaller will inevitably have a much worse incident as they grow. Every large company will inevitably have a couple bad incidents so asking “what other large company will never have incidents” is a moronic perspective IMO

mindcrash a month ago

some alternatives which can be self hosted:

open-appsec (by checkpoint), their proxy/gateway integration and your favorite firewall daemon:

https://docs.openappsec.io/getting-started/start-with-linux

appsec (by crowdsec), their proxy/gateway integration and your favorite firewall daemon:

https://docs.crowdsec.net/u/getting_started/installation/lin...

stevefan1999 a month ago

What about open source alternative built with Nginx/OpenResty? I forgot the name but that's the spirit

yearolinuxdsktp a month ago

AWS Route53, built-in DDoS basic protections, plus AWS WAF (can be expensive depending on your budget).

  • synack a month ago

    I've been using Cloudfront Functions to do some of the filtering that a WAF would do. It's quite flexible, but you've gotta figure out your own rules.

Carriethebest a month ago

I would recommend SafeLine. It's self-hosted and easy to setup

dennis16384 a month ago

Google Cloud Armor plus Load Balancer?

You can balance traffic to external networks or clouds with it too.

grim_io a month ago

Being down because half the internet is down is an easier sell than being down because you fucked it up yourself.

3rube a month ago

Fastly (US) and BunnyCDN (EU) are excellent options

882542F3884314B a month ago

Akamai is a decent alternative.

BOOSTERHIDROGEN a month ago

CrowdSec

tguvot a month ago

imperva

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection