- Free, stateful, default-deny both directions
- Up to 50 rules; sources by IP/CIDR, droplet, tag, LB or cluster
- Match on IP, port and protocol
- No FQDN, no SNI, no L7 or application matching
- No destination-level audit trail
Egress FQDN filtering for DigitalOcean, with audit-ready logs.
DigitalOcean Cloud Firewalls are free and stateful, but L3/L4 only — IP, port and protocol. No FQDN, no L7, no domain-aware egress, no destination-level audit trail. Enforza adds FQDN/SNI-based outbound control and audit-ready egress logs to your own SIEM, on a droplet in your own DigitalOcean network, with managed lifecycle and compliance-as-code.
DigitalOcean Cloud Firewalls stop at L3/L4
To be fair: for IP, port and protocol segmentation, DigitalOcean's free Cloud Firewalls are genuinely good. The gap is what they cannot express — anything about the destination beyond its address.
- FQDN/SNI-based egress control, without breaking TLS
- Stateful L3/L4 policy and secure source NAT in one appliance
- Audit-ready outbound logs to your own SIEM, by destination
- Advise-or-enforce compliance on publish — 25 frameworks / 210 controls
- Managed lifecycle and one console across your droplets
Govern egress by destination, not just by IP
Enforza runs as a single Linux VM in your DigitalOcean network and takes over outbound. You allow or deny by hostname, keep an audit-grade record of what left, and drive it all from a pipeline or a console.
FQDN/SNI egress filtering
Allow the destinations you trust and deny the rest by name — package registries, partner APIs, update endpoints — with SNI and FQDN rules that never decrypt TLS or hold your keys.
Audit-ready egress logs
Outbound logs stream to your own SIEM, never via Enforza's cloud, so you have a destination-level record for SOC 2, PCI DSS and ISO 27001 outbound-control evidence.
Managed, not a box you babysit
Self-patching, self-upgrading with rollback, and centrally managed across every droplet — policy as code from a GitHub pipeline, or the Cloud Controller console.
How it deploys on DigitalOcean
It installs on a droplet with a registration key. Two DigitalOcean specifics are worth knowing up front — we would rather you weigh them now than be surprised later.
-
Install on a droplet
A single Linux VM in your own DigitalOcean network. Install with a registration key; it registers to the Enforza cloud over an outbound connection and pulls its policy.
-
Route droplets through it
DigitalOcean VPCs have no custom route tables, so you set the default route on each backend droplet to exit via the Enforza droplet — preserving the metadata-service route — and re-apply it as you add droplets. More hands-on than a hyperscaler route change.
-
Filter and log
Enforza does secure source NAT (required, because DigitalOcean drops non-own-source packets), applies your FQDN/SNI egress policy, and streams outbound logs to your SIEM. Turn on compliance checks whenever you are ready.
DigitalOcean egress filtering — common questions
What do DigitalOcean Cloud Firewalls do?
DigitalOcean Cloud Firewalls are a genuinely useful, free, stateful firewall: default-deny in both directions, up to 50 rules, with sources and destinations expressed as IP or CIDR, droplet ID, tag, load balancer or Kubernetes cluster. They are L3/L4 only — IP, port and protocol. DigitalOcean's own docs rule out header or application matching, so there is no FQDN, no SNI, no L7 and no domain-aware egress. For simple network segmentation they are hard to beat; for controlling what leaves your droplets by destination name, they stop short.
Can DigitalOcean firewalls filter outbound traffic by domain or FQDN?
No. Cloud Firewalls match on IP, port and protocol only. If you need to allow or deny outbound traffic by hostname — for example, permit a package registry or a specific API and deny everything else — that is not something the native firewall can express. Enforza adds FQDN and SNI-based egress control on a droplet in your own DigitalOcean network, so outbound is governed by destination name, not just by IP.
How does Enforza add egress filtering on DigitalOcean?
Enforza runs as a single Linux VM (a droplet) in your own DigitalOcean network. You route droplet egress through it, and it applies FQDN/SNI-based L7 egress filtering without breaking TLS, plus stateful L3/L4 policy and secure source NAT — all from one appliance. Policy is driven from a GitHub pipeline (policy-as-code) or the Cloud Controller console, and outbound logs stream to your own SIEM for an audit trail by destination.
Does routing through Enforza need custom route tables on DigitalOcean?
This is the honest friction, and we will not hide it. DigitalOcean VPCs do not support custom route tables the way AWS, Azure and Google Cloud do, so there is no single routing policy to point at the appliance. Instead you set the default route on each backend droplet to send its egress via the Enforza droplet (preserving the metadata-service route), and you re-apply that when you add droplets. It is more hands-on than a route-table change on the hyperscalers — worth weighing up before you commit.
Why does the Enforza droplet need to rewrite the source address?
DigitalOcean's platform drops packets whose source IP is not the droplet's own assigned address — an anti-spoofing measure. A gateway that only forwarded packets unchanged would have them dropped. Enforza does secure source NAT by design, rewriting egress to its own address, so traffic passes cleanly. It is one less thing to configure, but it is worth understanding why plain forwarding does not work on DigitalOcean.
Does Enforza give me audit-ready egress logs for compliance?
Yes. Enforza streams outbound logs to your own SIEM — never via Enforza's cloud — so you have a destination-level record of what left your droplets, which is what SOC 2, PCI DSS and ISO 27001 outbound-control questions ask for. It also runs advise-or-enforce compliance checks on every policy publish across 25 framework packs and 210 firewall-applicable controls.
Is there a free way to try it?
Yes. Enforza has a genuine free tier — one firewall with L3/L4 policy and network objects, no card required — and a 14-day trial that unlocks the full feature set, including FQDN/SNI-based L7 filtering, compliance packs, log export and live logs. See the pricing page for the plan details.
Add FQDN egress filtering and audit-ready logs to your droplets.
FQDN/SNI-based outbound control, secure NAT and audit-grade egress logs on a droplet in your own DigitalOcean network — managed, compliance-checked, driven from a pipeline or a console. Start free, no card.