I take this to mean "don't buy Fortinet products."
https://www.cvedetails.com/vulnerability-list/vendor_id-3080...
I take this to mean "don't buy Fortinet products."
https://www.cvedetails.com/vulnerability-list/vendor_id-3080...
Most of the devices that rely on a scheme similar to inkjet printers (but with an even shorter shelf life) are going to be that way. This is because the money is not in the software, but in administrative choices (licensing, support contracts based on lifespan of hardware etc).
Since most deployment scenarios don't really need a proprietary ASIC to handle filtering, you'd almost universally be better off with a system that is built around generic white box hardware and an OS that is kept up-to-date. But that requires more knowledge and skills, and most people and companies would rather not invest in that for various reasons.
As for where you'd get your money's worth: it's mostly in the threat feeds. A well-tested, verified feed of known bad things (subnets, packet contents, behaviour) is much more useful than paying someone to keep a spare fan on the shelf so they can bring it to you "just in case".
If you want to do this, you need to select the least bad vendor.
In my experience, site categorisation is about the only 'feed' worth paying for.
https://wiki.nftables.org/wiki-nftables/index.php/Conntrack_...
You can also send packets to userspace from nftables and do your SNI parsing/deep inspection/decision there. I used that a few times to do various things, like duplicate packet removal, etc.
It's very flexible.
That shit pays for itself. :D
Other useful feeds might be known malicious IPs and ASNs, dropping any packets matching those is very cheap and very effective. But they have to be reliable and not have false positives.
You could get a white box firewall put something like OpnSense business edition on it, and add Zenarmor. Works forever until FreeBSD no longer supports the hardware or until the hardware dies. And you get all the support and vetting/testing from those software options as well.
But realistically, if you're doing NGFW things you're probably in a compliance regime that doesn't allow for much choice of hardware and software and you're screwed anyway (compliance might require you to buy something like a Cisco or Palo Alto device + subscription, but then it turns out they run PHP as root under the hood and gets pwned monthly by a teenager on the other side of the world).
https://www.cvedetails.com/vulnerability-list/vendor_id-1283...
https://www.theregister.com/2025/01/14/miscreants_mass_explo...
I think the only good options are something flashed with up-to-date OpenWRT, or a PC running something like Opnsense.