Hey everyone !

I’m looking into spinning up a WAF as the number of services I’m hosting is slowly growing. I want to have a better understanding of the traffic and also have a relative peace of mind that if there is a flaw in one of the services I’m hosting, the WAF could help mitigate it.

I’ve seen two big names come up while searching :

  • SafeLine
  • BunkerWeb

They are popular and look quite good all around but I don’t want to just mindlessly take the project with the most GitHub stars.

What WAF are you using / have you used ? Which ones do you recommand ?

  • BlackEco
    link
    fedilink
    English
    2
    edit-2
    1 day ago

    I have been using BunkerWeb for the past 4 years and have been mostly happy with it. Its default settings are sometimes a bit agressive but you can change those globally or service per service.

    • @[email protected]
      link
      fedilink
      English
      31 day ago

      The fact that they lock Letsencrypt DNS-01 behind the pro version is so incredibly annoying.

      • BlackEco
        link
        fedilink
        English
        11 day ago

        Yeah, I use Caddy for that, as I only use DNS-01 for local-only services.

    • @AdmaxOP
      link
      English
      11 day ago

      Thanks that’s good to know :)