Should You Switch? Deployment Guide and Initial Thoughts

Поделиться
HTML-код
  • Опубликовано: 25 дек 2024
  • НаукаНаука

Комментарии • 57

  • @DarrylGibbs
    @DarrylGibbs Месяц назад +42

    I always thought WAF = wife approval factor

    • @Jims-Garage
      @Jims-Garage  Месяц назад +7

      Haha! Very apt in the homelab space ! 😂 "Is the internet down again?"

  • @Glatze603
    @Glatze603 Месяц назад +2

    Very interesting, thanks for your work with this video Jim!

  • @bluesquadron593
    @bluesquadron593 Месяц назад +27

    Well I stopped at the elephant in the room @3:10

    • @Jims-Garage
      @Jims-Garage  Месяц назад +13

      I can understand that, hence why I felt it was important to mention it.

    • @bluesquadron593
      @bluesquadron593 Месяц назад +6

      @ very nice and thanks for the transparency.

    • @PowerUsr1
      @PowerUsr1 Месяц назад +5

      and................im done here......

  • @chrisumali9841
    @chrisumali9841 Месяц назад +1

    Thanks for the demo and info. Another great fantastic video Jim. Have a wonderful day

  • @davidwestra8181
    @davidwestra8181 Месяц назад +15

    Would love a video of more advanced crowdsec/traefik configuration.

    • @Jims-Garage
      @Jims-Garage  Месяц назад +3

      Noted! I have been meaning to revisit for a while now

    • @ghangj
      @ghangj Месяц назад +3

      Same as well. I am building my homelab around these two products Traefik and Crowdsec and getting that data to show on Grafana will be great

  • @gaz1978
    @gaz1978 Месяц назад +7

    This sounds like an intersting product right up until the throwawy line "they're based in China" Oh well onto the next.

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      BunkerWeb next (albeit checkout my CrowdSec video - it's probably the best option)

  • @chrisumali9841
    @chrisumali9841 Месяц назад +1

    Thanks for the demo and info. Have a great day

  • @1111s-y6j
    @1111s-y6j Месяц назад +3

    But I tried and it did work well and I got positive results after a pen test. Every software collect data. Telemetry is very often used to understand usage patterns.

  • @asksearchknock
    @asksearchknock Месяц назад +9

    3:10 - it looks interesting but combining Chinese software with something that can read encrypted packets is a bit too much for me. Great review though and thanks for sharing it

  • @Sli3py
    @Sli3py Месяц назад +4

    Very nice indeed! I wonder would this possibly replace traefik+crowdsec+ let's encrypt combo? 🤔

    • @Jims-Garage
      @Jims-Garage  Месяц назад +1

      @@Sli3py it can, but you'll have to decide if you should

  • @ency98
    @ency98 Месяц назад +2

    Been looking for a decent WAF for awhile. Sophos is a pain and crowdsec isn't much better. I appreciate the transparency on the origin, i wont be testing this out because of the origin but its nice to see other options coming out that might get support going for other projects.

  • @romayojr
    @romayojr 22 дня назад +3

    just saw dbtech’s video on this. i did not know this application phones back home to china and collects your data without your consent but they since disclosed this recently. i was already not a fan of the paywall features and now this, this is a hard pass for me

    • @Jims-Garage
      @Jims-Garage  22 дня назад +2

      Thanks for replying. I'll contact them and see if they are willing to disclose the facts. This is likely the nail in the coffin for most people (rightfully so!).

    • @romayojr
      @romayojr 21 день назад +2

      @@Jims-Garage they just recently published a disclaimer on their website but not at the time this video was uploaded

    • @Jims-Garage
      @Jims-Garage  21 день назад +1

      @romayojr ok, thanks

  • @crypto-city859
    @crypto-city859 Месяц назад +1

    Subbed :)

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      @@crypto-city859 thanks 👍

  • @Popcorncandy09
    @Popcorncandy09 15 дней назад +1

    if it wasn't $600 a year for basic free functionality you can get elsewhere i would've considered this.

  • @ghangj
    @ghangj Месяц назад +1

    *Contemplating on setting up WAF for external services*....Jim's Garage "Should You Switch? Deployment Guide and Initial Thought"............. 3:10 ...glad to know.

  • @altimeterlabs
    @altimeterlabs Месяц назад +4

    May I ask why you always use VMs as opposed to LXCs? A video on the pros / cons would be great!

    • @Jims-Garage
      @Jims-Garage  Месяц назад +1

      @@altimeterlabs sure, a VM has an isolated kernel (more secure albeit LXC should be sufficient). I also prefer a VM as there's no dependency on the underlying OS (it will run on anything KVM).

    • @panthonyy
      @panthonyy Месяц назад

      ​@@Jims-Garage I,m with you on this one, I do the exact same. Although, I have a lot of CPU cores and RAM and electricity is dirt cheap where I live. So if those were issues I might've considered LXCs a lot more

  • @michaeldziegiel4954
    @michaeldziegiel4954 Месяц назад

    I have Nginx configured as a reverse proxy for my web applications, and I'm now trying to integrate SafeLine into this setup. I’ve set port 80 to forward to SafeLine, and then configured Nginx to route traffic to SafeLine on port 9443. In theory, this setup should work, but I keep running into a certificate error. Any ideas on what might be causing this?

  • @amrhegazy7221
    @amrhegazy7221 Месяц назад +2

    kindly compare it to Crowdsec waf

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      I already have a video on crowdsec (both docker and kubernetes) but it might be worth a refresh.

  • @An78toi13ne
    @An78toi13ne Месяц назад +4

    Great video as always ! The chinese factor being a problem, Bunkerweb seems to be a good (French) alternative from what I saw. Maybe you could give it a try to do a WAF comparison ?

    • @Jims-Garage
      @Jims-Garage  Месяц назад +2

      Oui oui, I'll check that out. Thanks

  • @alepouna
    @alepouna Месяц назад

    Looks like a great app, the UI is pretty nice (-light theme), ,bit bummed of the elephant in the room. I wonder if there is anything similar (ui wise) to this

  • @eelrepus
    @eelrepus Месяц назад +1

    No Mainland China project....give up for this....

  • @jole23b
    @jole23b Месяц назад +1

    compare it to firewalla software / firewall

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      Thanks, I'm yet to test firewalla

  • @BenjaminBenStein
    @BenjaminBenStein Месяц назад +3

    Chinese, nope thx

  • @masterroot24
    @masterroot24 Месяц назад +1

    Honestly, I tried to move past the Chinese origin. However, seeing that it doesn't even default to IPv6 being on was the final nail in the coffin for me.

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      That's a fair criticism.

    • @Carrie-f5b
      @Carrie-f5b Месяц назад

      If you enable IPv6 on docker, it actually supports.

    • @masterroot24
      @masterroot24 Месяц назад

      @@Carrie-f5b I can see that, but the fact that this is being offered as a WAF and it's not defaulting to IPv6 being on suggests that IPv6 is a secondary concern to (legacy) IPv4. In other words: Out of the box, it's only filtering on legacy traffic.

    • @Carrie-f5b
      @Carrie-f5b Месяц назад +1

      @@masterroot24 Tengine is host network and supports to filter IPv6 traffic by default. But if you mean accessing SafeLine Management Console with IPv6, that is port 9443, you need to enable IPv6 on docker.

  • @roehlaguila7930
    @roehlaguila7930 Месяц назад +3

    Please review BunkerWeb.

    • @Jims-Garage
      @Jims-Garage  Месяц назад

      @@roehlaguila7930 I'll have a look

    • @panthonyy
      @panthonyy Месяц назад +1

      Thanks for the heads up, didn't know about this one, and will definitely check it out :)