@Jimmy9008 said in Virtual WAF:
@Dashrender said in Virtual WAF:
@Jimmy9008 said in Virtual WAF:
@Dashrender said in Virtual WAF:
@Jimmy9008 said in Virtual WAF:
@VoIP_n00b said in Virtual WAF:
Cloudflare Pro has a WAF but it's $20/month.
I don't think that would be a direction we would use. I like CF but it just wont happen here.
They can't afford $20/m to protect this? does whatever they are doing even make sense to do?
Currently correct, no budget for this. What they want to do makes sense for them, but not for an IT perspective. The applications are demo environments which are shown to potential customers. We have many of these environments to demo the solutions globally.
The product team have decided they want to cut their budget this year and have cut out the WAF which sits in front of their demo applications. I believe they had some form of Citrix solution which sat in front of the webservers to do the higher layer checking like XSS/SQL Injection and stuff like that. Due to their decision, this now sits with IT.
Essentially, this is not in the IT budget and it is rigid. So most likely will be until 2022 until any budget is allowed at all for this. Crazy I know.
Hence, wanting something between the internet and their now less protected application at no real cost. ModSecurity or something like that looks like a good start.
So they believed they needed good security - hence why they looked/had Citrix stuff before (didn't know they did that), but now, because of budget, they no longer care about it... this is completely the wrong way to do things.. wow.
Now that's not to say they shouldn't reevaluate what they are doing - and find a solution that is more cost effective, but to go from a hugely expensive system (Citrix) to a free one is just asking to be hacked.
Also, you said this is now for IT to manage - uh.. what? It's always been for IT to manage.
Perhaps in other companies, yes. But not here, until now. The teams are very well defined and IT here is kept to core infrastructure only. As this infrastructure interacts with customers it is with a different team. That team has decided to cut their budget out and remove the component, and has said "IT, its now your problem" which until now had not been the case.
Wow - in that case then, I would say - well you don't care about it, so other than my firewall, I don't care about it either.... and if I do need to care about it - then I need budget to care more than just my firewall about it.
That's a fundamental change to the company - again, that's fine, as long as they put the resources they expect to need in place... they were clearly doing that well enough in the past.. and now what - they just puke on it? what gives that department the right/ability to shift responsibility and cost vector to you?