- Cost
How to reduce AWS NAT Gateway costs: 7 ways, ranked by savings
Seven ways to cut the AWS NAT Gateway bill, ranked by how much of it each one typically removes: free S3 and DynamoDB gateway endpoints, PrivateLink for busy services, hunting top talkers with flow logs, per-AZ routing, non-prod consolidation, NAT instances, and a flat-priced NVA. With the break-even maths.
Read article → - Cost
How to reduce Azure Firewall costs: 7 ways, ranked by savings
Seven ways to cut the Azure Firewall bill, ranked by how much of it each one typically removes: right-sizing the SKU, deallocating idle firewalls, consolidating deployments, keeping Azure-bound traffic off the meter, hunting top talkers, pruning forgotten floors, and a flat-priced NVA. With the break-even maths.
Read article → - Cost
AWS NAT Gateway: what it actually costs, and the alternatives
A line-by-line look at AWS NAT Gateway pricing. The $0.045/hr plus $0.045/GB you don't budget for, why it multiplies per Availability Zone, and the honest alternatives: VPC endpoints, NAT instances and fck-nat, a flat-priced NVA, and when a plain NAT Gateway is simply right.
Read article → - Firewalls
enforza-cockpit: a free web GUI for nftables on your homelab
enforza-cockpit is a free, open-source Cockpit plugin that gives you a browser GUI for nftables: build a firewall policy, turn one Linux box into a router and NAT gateway, and watch per-rule logs, with no cloud account and nothing phoning home.
Read article → - Firewalls
AWS Gateway Load Balancer firewall: how GWLB inspection works
What AWS Gateway Load Balancer is, how the GENEVE datapath works, which firewalls work behind GWLB, how to use a third-party NVA — and the cost of GWLB inspection.
Read article → - Cloud networking
Azure Service Tags vs AWS IP Ranges for cloud network security
How Azure Service Tags and AWS IP Ranges work, how they differ, and how to manage both from one place when you build firewall and NAT policy across clouds.
Read article → - Azure
Azure default outbound access retirement: what changed, who's affected, and how to migrate
Azure's retirement of default outbound access is now live: new virtual networks get private subnets by default. Who is affected, the symptoms when a new VM has no internet, how to migrate legacy VNets — and why a plain NAT gateway leaves the pipe unfiltered.
Read article → - Firewalls
Understand Cloud Firewalls & Your Options
The four ways to firewall a cloud network — FWaaS, native cloud firewalls, third-party NVAs, and open source — with the trade-offs and where each fits.
Read article → - FQDN filtering
Egress FQDN Filtering in the Cloud
How egress FQDN filtering differs from URL category filtering, when to use each, and why hostname rules are the right control for cloud workloads.
Read article → - Cloud networking
Traffic Flows in the Cloud
The four traffic flows that matter in cloud networks — east-west, ingress, egress, and traffic to service endpoints — and how to control each one.
Read article → - NAT gateways
How NAT Gateways Work
How NAT gateways translate private addresses to public ones, why RFC 1918 ranges need translation, port-mapping limits, and what the gateway costs you.
Read article → - Firewalls
The Problem with Cloud-Native Firewalls and NAT Gateways
Cloud-native firewalls and NAT gateways meter you per gigabyte and lock you into one provider. Here's the cost wedge and the flat-priced alternative.
Read article → - Firewalls
Understanding AWS Network Firewall
How AWS Network Firewall works, its Suricata-based rule engine, the per-endpoint and per-GB pricing model, and where a flat-priced alternative fits.
Read article → - Cost
Reducing Cloud NAT Costs
Practical ways to cut cloud NAT gateway spend, compare the alternatives, and improve outbound security without the per-GB data-processing tax.
Read article →
Ditch the data-processing charges.
Flat, per-firewall pricing — and no per-GB data-processing charges, ever. The same egress filtering, FQDN/SNI-based L7 and NAT, in any cloud or on-prem. Start free, no card.