- Cloud networking
Azure Service Tags vs AWS IP Ranges for cloud network security
How Azure Service Tags and AWS IP Ranges work, how they differ, and how to manage both from one place when you build firewall and NAT policy across clouds.
Read article → - Azure
Azure default outbound retirement: NAT, firewall and cost options
Azure has retired default outbound internet access for VMs. Here's what changed, the options for replacing it, and how the costs compare.
Read article → - Firewalls
Understand Cloud Firewalls & Your Options
The four ways to firewall a cloud network — FWaaS, native cloud firewalls, third-party NVAs, and open source — with the trade-offs and where each fits.
Read article → - FQDN filtering
Egress FQDN Filtering in the Cloud
How egress FQDN filtering differs from URL category filtering, when to use each, and why hostname rules are the right control for cloud workloads.
Read article → - Cloud networking
Traffic Flows in the Cloud
The four traffic flows that matter in cloud networks — east-west, ingress, egress, and traffic to service endpoints — and how to control each one.
Read article → - NAT gateways
How NAT Gateways Work
How NAT gateways translate private addresses to public ones, why RFC 1918 ranges need translation, port-mapping limits, and what the gateway costs you.
Read article → - Firewalls
The Problem with Cloud-Native Firewalls and NAT Gateways
Cloud-native firewalls and NAT gateways meter you per gigabyte and lock you into one provider. Here's the cost wedge and the flat-priced alternative.
Read article → - Firewalls
Understanding AWS Network Firewall
How AWS Network Firewall works, its Suricata-based rule engine, the per-endpoint and per-GB pricing model, and where a flat-priced alternative fits.
Read article → - Cost
Reducing Cloud NAT Costs
Practical ways to cut cloud NAT gateway spend, compare the alternatives, and improve outbound security without the per-GB data-processing tax.
Read article →
Ditch the data-processing charges.
Flat, per-firewall pricing — and no per-GB data-processing charges, ever. The same egress filtering, identity-aware L7 and NAT, in any cloud or on-prem. Start free, no card.