Public Service Announcement:

Have you checked out Sophos XG Firewall for home use lately?

It’s basically an enterprise firewall fully licensed for personal use.

  • All the firewall stuff
  • Normal IPS
  • Built-In easy transparent SSL/TLS proxy
  • Web Application Firewall

I like it better than PF/Open Sense right now.

https://youtu.be/Ui8UC8-MeJU

  • StarkZarn@infosec.pub
    link
    fedilink
    English
    arrow-up
    6
    ·
    2 days ago

    They place arbitrary limits on home users as well, which is a secondary reason to not use it compared to open source offerings. For instance:

    • you are limited to 1Gbps line speed
    • you are limited to one week of analytics, with no export option, so you can’t even ship them elsewhere
    • there are also resource limits that prevent ram and CPU utilization
    • RedFox@infosec.pubOP
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      1
      ·
      10 hours ago

      This is true, the 6 GB RAM limit and four cores.

      I run a pretty enterprise home lab, and I haven’t ever seen the devices hit the resource limit.

      I have around 3k IPS rules and TLS inspection for most categories of sites except the normal stuff like streaming, banking, etc that you’d not want or need to inspect.

      For anyone it might help, I use these as inline proxies rather than as the gateway at the moment. So they have more than just internet traffic going through them, they also have segments of my LANs getting evaluated. Performance has been great so far.