> One company I worked with had an innovative idea for a firewall: build it with programmable logic and it works at wire speed
Ah, that's the idea I had at Cloudflare and we then built it as Firewall Rules. Externally it looks like it's a HTTP feature only and just a WAF type tool, but internally it's an extremely fast matcher that can work on any traffic and at different OSI layers so it forms part of the DDoS protection, bot protection, magic transit, etc. It's also in things like the URI rewrite... because fundamentally it's all just "match things" and associate actions with the matched things, usually the actions are deny, rate limit, allow, challenge... but no reason the actions can't be to transform, duplicate, log, etc too.
Just wireshark like matching at the equivalent of wire speed (for what that means at whatever layer you're working on) without having to have buffering or that pcap phase normally associated with firewalls or wireshark.
The same wireshark-like rules can also be translated into SQL easily enough, so it's possible to run a firewall rule over the logs and see what would've matched (it isn't perfect, logging isn't that complete... but for the most common scenarios it works well enough).
This work is OSS, the language syntax and a table matcher (used for the HTTP part) is all here https://github.com/cloudflare/wirefilter/tree/cloudflare and it's in Rust. For other systems the rule may be translated to eBPF for the matching part, etc. A blog post with an overview is here https://blog.cloudflare.com/how-we-made-firewall-rules/ .