Everyone's got a firewall. Everyone says it's "enterprise-grade." Then they deploy it and treat it like a magical barrier. I'm curious about actual offensive security against CloudGen WAF specifically.
We inherited one. The sales deck was full of "AI-powered" this and "zero-trust" that. I'm less interested in that and more in: when a competent red team actually targeted an app behind it, what did they find? Did the default policies mean anything, or was it trivial to bypass? I assume we'll have to write custom signatures for anything real.
What I've seen so far in our staging tests:
* The out-of-the-box OWASP CRS equivalents blocked basic stuff. Obviously.
* Any slightly obfuscated payload sailed right through until we manually tuned paranoia levels to "annoying."
* The management interface itself feels like a liability.
Keep it simple