Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'll stick to using a Linux firewall.


PaloAlto devices ARE “Linux Firewalls”

https://live.paloaltonetworks.com/t5/general-topics/how-to-a...


They aren't exactly linux firewalls, even if they run linux as management OS.

AFAIK the forwarding engine is custom(ized), and on physical devices some of them offload to FPGA - or at least they used to when I administrated some 2014~2016.

The management UI was in PHP :P


They probably mean some Linux distro with no crapware on top. Seeing how this exploit seems to be PaltoAlto-specific stuff built on top of the basic OS, GP's approach sounds sensible enough.


Yes. This is what I meant. A GNU/Linux iptables2 firewall.


iptables2 == nftables I suppose




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: