Zorp – Open source proxy firewall with deep protocol analysis
balasys.github.io
balasys.github.io
I kinda thought about it but the 50-100 bucks expenditure just for curiosity seems a bit heavy
https://github.com/Balasys/zorp/blob/master/lib/proxyssl.cc https://github.com/Balasys/zorp/blob/master/lib/pyx509.cc
It's able to inspect and relay the connection as well as passing it to another proxy
https://github.com/Balasys/zorp/blob/master/lib/proxystack.c...
https://www.balasys.hu/content/documents/zorp-gpl-guide-refe...
The architecture is modular, and you can write plug-ins that analyse the structure of communications beyond packet headers: the content is inspected. The open source version includes out of the box support for inspecting HTTP, FTP, SMTP, POP3, Finger, Whois, Telnet (+TLS). But you can write plugins that couple the engine with anything, from an IDS such as Snort, Bro or Suricata, to something like nDPI or AssemblyLine.
https://www.ntop.org/products/deep-packet-inspection/ndpi/ https://bitbucket.org/cse-assemblyline/assemblyline
Based on the results of the analysis, you can choose to apply firewall rules.
looks like zorp is a all-in-one solution, hope i have time to play with it soon
If I don't agree with you: Do you think IP/port based firewalls are censorship? That any kind of cyber-border security is an affront to rights? If not, then how do you govern access as a private organization when everything is tcp/443 on AWS? Gotta know what it's going to.
I am considering it as a tool to provide another layer of protection for my small business network. That would make your summary a positive for me.
Or it could be privacy software that lets you look at data you're sending to the cloud, modify it, or prevent it altogether.
It just depends who is in control of the software.