Ask HN: Cloudflare WAF Alternatives?
17 points
4 hours ago
| 5 comments
I don't know if we're ready to pull the trigger yet, but curious if other folks are looking at alternatives.The WAF is great, but recent events have made it obvious that having a single point of failure entirely defeats the purpose of DNS being a distributed/decentralized service.
Is anyone doing anything creative here? We like the features that the WAF provides - but not at the expense of global outages. If you have a 3 9s availability SLA, you've just blown 90% of your allotted downtime because of Cloudflare's WAF.
▲The ability of a WAF to respond to an 0day incident is rapid rollout, 100% of endpoints, which is a SPOF no matter whether it's done via a big company or by a distributed system.
reply▲Being down because half the internet is down is an easier sell than being down because you fucked it up yourself.
reply▲AWS Route53, built-in DDoS basic protections, plus AWS WAF (can be expensive depending on your budget).
reply▲I've been using Cloudfront Functions to do some of the filtering that a WAF would do. It's quite flexible, but you've gotta figure out your own rules.
reply