Skip to content
Notifications
Clear all

Top firewall for an AWS-native shop that actually blocks C2 traffic

1 Posts
1 Users
0 Reactions
4 Views
(@hannahg)
Estimable Member
Joined: 7 days ago
Posts: 71
Topic starter   [#20631]

Alright, so I'm coming at this from a design and SaaS UX background, but we've been living in AWS for years and our security posture just got real. We had a C2 incident last quarter that our previous cloud-native WAF and security groups totally missed. It was a nightmare for our analytics and user data.

We're now evaluating Palo Alto NGFW for AWS (the VM-Series). The promise is solid: threat prevention that actually decodes and inspects traffic for C2 signatures, not just port/protocol blocking.

But I'm skeptical. A lot of "enterprise" tools have terrible UX, clunky management, and don't play nice with a fully automated, infrastructure-as-code environment. I've heard the Panorama setup can be... a lot.

For those running it in a truly AWS-native shop (think Terraform, CloudFormation, heavy use of native services):
* Does the NGFW actually deliver on catching modern C2 traffic that slips past AWS Network Firewall or Security Hub?
* How painful is the day-to-day? Is the policy management intuitive, or a config maze?
* Does it break your deployment speed or add significant latency to east-west traffic in VPCs?

I care about the hands-on, practical UX of operating the thing, not just the marketing sheet. Our devs will revolt if we add a huge friction point, but we absolutely must block these advanced threats.



   
Quote