Should You Switch? Deployment Guide and Initial Thoughts

Поделиться
HTML-код
  • Опубликовано: 23 ноя 2024

Комментарии • 51

  • @DarrylGibbs
    @DarrylGibbs 22 дня назад +40

    I always thought WAF = wife approval factor

    • @Jims-Garage
      @Jims-Garage  22 дня назад +7

      Haha! Very apt in the homelab space ! 😂 "Is the internet down again?"

  • @bluesquadron593
    @bluesquadron593 22 дня назад +25

    Well I stopped at the elephant in the room @3:10

    • @Jims-Garage
      @Jims-Garage  22 дня назад +13

      I can understand that, hence why I felt it was important to mention it.

    • @bluesquadron593
      @bluesquadron593 22 дня назад +6

      @ very nice and thanks for the transparency.

    • @PowerUsr1
      @PowerUsr1 22 дня назад +4

      and................im done here......

  • @1111s-y6j
    @1111s-y6j 20 дней назад +3

    But I tried and it did work well and I got positive results after a pen test. Every software collect data. Telemetry is very often used to understand usage patterns.

  • @gaz1978
    @gaz1978 20 дней назад +7

    This sounds like an intersting product right up until the throwawy line "they're based in China" Oh well onto the next.

    • @Jims-Garage
      @Jims-Garage  18 дней назад

      BunkerWeb next (albeit checkout my CrowdSec video - it's probably the best option)

  • @chrisumali9841
    @chrisumali9841 17 дней назад +1

    Thanks for the demo and info. Another great fantastic video Jim. Have a wonderful day

  • @davidwestra8181
    @davidwestra8181 22 дня назад +15

    Would love a video of more advanced crowdsec/traefik configuration.

    • @Jims-Garage
      @Jims-Garage  22 дня назад +3

      Noted! I have been meaning to revisit for a while now

    • @ghangj
      @ghangj 22 дня назад +3

      Same as well. I am building my homelab around these two products Traefik and Crowdsec and getting that data to show on Grafana will be great

  • @Glatze603
    @Glatze603 21 день назад +2

    Very interesting, thanks for your work with this video Jim!

  • @asksearchknock
    @asksearchknock 22 дня назад +9

    3:10 - it looks interesting but combining Chinese software with something that can read encrypted packets is a bit too much for me. Great review though and thanks for sharing it

  • @chrisumali9841
    @chrisumali9841 18 дней назад +1

    Thanks for the demo and info. Have a great day

  • @ency98
    @ency98 22 дня назад +2

    Been looking for a decent WAF for awhile. Sophos is a pain and crowdsec isn't much better. I appreciate the transparency on the origin, i wont be testing this out because of the origin but its nice to see other options coming out that might get support going for other projects.

  • @Sli3py
    @Sli3py 21 день назад +4

    Very nice indeed! I wonder would this possibly replace traefik+crowdsec+ let's encrypt combo? 🤔

    • @Jims-Garage
      @Jims-Garage  21 день назад +1

      @@Sli3py it can, but you'll have to decide if you should

  • @ghangj
    @ghangj 22 дня назад +1

    *Contemplating on setting up WAF for external services*....Jim's Garage "Should You Switch? Deployment Guide and Initial Thought"............. 3:10 ...glad to know.

  • @michaeldziegiel4954
    @michaeldziegiel4954 17 дней назад

    I have Nginx configured as a reverse proxy for my web applications, and I'm now trying to integrate SafeLine into this setup. I’ve set port 80 to forward to SafeLine, and then configured Nginx to route traffic to SafeLine on port 9443. In theory, this setup should work, but I keep running into a certificate error. Any ideas on what might be causing this?

  • @An78toi13ne
    @An78toi13ne 21 день назад +3

    Great video as always ! The chinese factor being a problem, Bunkerweb seems to be a good (French) alternative from what I saw. Maybe you could give it a try to do a WAF comparison ?

    • @Jims-Garage
      @Jims-Garage  20 дней назад +2

      Oui oui, I'll check that out. Thanks

  • @altimeterlabs
    @altimeterlabs 22 дня назад +4

    May I ask why you always use VMs as opposed to LXCs? A video on the pros / cons would be great!

    • @Jims-Garage
      @Jims-Garage  20 дней назад +1

      @@altimeterlabs sure, a VM has an isolated kernel (more secure albeit LXC should be sufficient). I also prefer a VM as there's no dependency on the underlying OS (it will run on anything KVM).

    • @panthonyy
      @panthonyy 18 дней назад

      ​@@Jims-Garage I,m with you on this one, I do the exact same. Although, I have a lot of CPU cores and RAM and electricity is dirt cheap where I live. So if those were issues I might've considered LXCs a lot more

  • @alepouna
    @alepouna 11 дней назад

    Looks like a great app, the UI is pretty nice (-light theme), ,bit bummed of the elephant in the room. I wonder if there is anything similar (ui wise) to this

  • @amrhegazy7221
    @amrhegazy7221 21 день назад +2

    kindly compare it to Crowdsec waf

    • @Jims-Garage
      @Jims-Garage  19 дней назад

      I already have a video on crowdsec (both docker and kubernetes) but it might be worth a refresh.

  • @crypto-city859
    @crypto-city859 13 дней назад +1

    Subbed :)

    • @Jims-Garage
      @Jims-Garage  13 дней назад

      @@crypto-city859 thanks 👍

  • @jole23b
    @jole23b 22 дня назад +1

    compare it to firewalla software / firewall

    • @Jims-Garage
      @Jims-Garage  18 дней назад

      Thanks, I'm yet to test firewalla

  • @eelrepus
    @eelrepus 7 дней назад

    No Mainland China project....give up for this....

  • @masterroot24
    @masterroot24 19 дней назад +1

    Honestly, I tried to move past the Chinese origin. However, seeing that it doesn't even default to IPv6 being on was the final nail in the coffin for me.

    • @Jims-Garage
      @Jims-Garage  18 дней назад

      That's a fair criticism.

    • @Carrie-f5b
      @Carrie-f5b 17 дней назад

      If you enable IPv6 on docker, it actually supports.

    • @masterroot24
      @masterroot24 17 дней назад

      @@Carrie-f5b I can see that, but the fact that this is being offered as a WAF and it's not defaulting to IPv6 being on suggests that IPv6 is a secondary concern to (legacy) IPv4. In other words: Out of the box, it's only filtering on legacy traffic.

    • @Carrie-f5b
      @Carrie-f5b 16 дней назад +1

      @@masterroot24 Tengine is host network and supports to filter IPv6 traffic by default. But if you mean accessing SafeLine Management Console with IPv6, that is port 9443, you need to enable IPv6 on docker.

  • @BenjaminBenStein
    @BenjaminBenStein 21 день назад +1

    Chinese, nope thx

  • @roehlaguila7930
    @roehlaguila7930 22 дня назад +3

    Please review BunkerWeb.

    • @Jims-Garage
      @Jims-Garage  20 дней назад

      @@roehlaguila7930 I'll have a look

    • @panthonyy
      @panthonyy 18 дней назад +1

      Thanks for the heads up, didn't know about this one, and will definitely check it out :)