<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Neil Briscoe</title>
    <description>The latest articles on DEV Community by Neil Briscoe (@neilbriscoe).</description>
    <link>https://dev.to/neilbriscoe</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4056672%2Fd178d804-2d6c-47f8-8461-5918b4a57f08.png</url>
      <title>DEV Community: Neil Briscoe</title>
      <link>https://dev.to/neilbriscoe</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/neilbriscoe"/>
    <language>en</language>
    <item>
      <title>How to reduce Azure Firewall costs: 7 ways, ranked by savings</title>
      <dc:creator>Neil Briscoe</dc:creator>
      <pubDate>Mon, 03 Aug 2026 15:00:10 +0000</pubDate>
      <link>https://dev.to/enforza/how-to-reduce-azure-firewall-costs-7-ways-ranked-by-savings-24of</link>
      <guid>https://dev.to/enforza/how-to-reduce-azure-firewall-costs-7-ways-ranked-by-savings-24of</guid>
      <description>&lt;p&gt;Azure Firewall's bill has a floor and a meter. The floor is the&lt;br&gt;
per-deployment-hour fee: $1.25/hr on Standard, which is about &lt;strong&gt;$912 a month&lt;br&gt;
before a single byte moves&lt;/strong&gt;. That is a strong interpretation of&lt;br&gt;
"pay as you go". The meter is $0.016 per GB processed, uncapped, on&lt;br&gt;
everything you route through it. And the floor multiplies: the same rates&lt;br&gt;
re-apply per secured virtual hub, so a tidy multi-region hub-and-spoke&lt;br&gt;
diagram is also a multiplication exercise. (Rates Central US, dated&lt;br&gt;
2026-07-04, directional.)&lt;/p&gt;

&lt;p&gt;Disclosure before we start: I work on &lt;a href="https://enforza.io/" rel="noopener noreferrer"&gt;Enforza&lt;/a&gt;, which is option 7 below.&lt;br&gt;
It gets one section, at the end, after six things you should try first. Most&lt;br&gt;
of them are configuration, not products.&lt;/p&gt;

&lt;p&gt;Same rules as the &lt;a href="https://enforza.io/articles/reduce-aws-nat-gateway-costs/" rel="noopener noreferrer"&gt;AWS version of this guide&lt;/a&gt;:&lt;br&gt;
ranked by how much of the bill each move typically removes, boring ones first,&lt;br&gt;
because that's where the money is.&lt;/p&gt;

&lt;h2&gt;
  
  
  The ranking at a glance
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Right-size the SKU.&lt;/strong&gt; Premium without TLS inspection in use is $365/month
of nothing. Basic below ~12 TB/month beats Standard's floor.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Deallocate what sleeps.&lt;/strong&gt; Azure Firewall has an off switch. Dev and test
firewalls off nights and weekends drop ~70% of their hourly line.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Count your deployments.&lt;/strong&gt; Every extra firewall or secured hub is another
$912/month floor. Consolidate where the architecture allows.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keep Azure-bound traffic off the meter.&lt;/strong&gt; Service endpoints are free;
stop paying $0.016/GB to inspect your own backups.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunt your top talkers.&lt;/strong&gt; Firewall logs, aggregate, rank, be mildly
annoyed, fix with caching and routing granularity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Prune the forgotten floors.&lt;/strong&gt; Idle POC and staging firewalls bill $912 a
month for existing. Delete or deallocate them.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A flat-priced NVA.&lt;/strong&gt; Same egress-firewall job, flat licence, no per-GB
meter, one floor instead of several.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Now each one, with the arithmetic.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Right-size the SKU
&lt;/h2&gt;

&lt;p&gt;Three rate cards, frequently mixed up, occasionally all paid at once.&lt;br&gt;
Standard is $1.25/hr plus $0.016/GB. Premium is $1.75/hr plus the same&lt;br&gt;
$0.016/GB: the extra $0.50/hr, about &lt;strong&gt;$365 a month per deployment&lt;/strong&gt;, buys&lt;br&gt;
TLS inspection and IDPS. Premium is excellent value right up until you check&lt;br&gt;
whether anyone actually enabled those features. If they didn't, that's a&lt;br&gt;
one-line change worth $4,380 a year.&lt;/p&gt;

&lt;p&gt;Basic runs the other direction: a $0.395/hr floor, about $288 a month, but a&lt;br&gt;
&lt;strong&gt;$0.065/GB&lt;/strong&gt; meter, four times Standard's rate. The break-even sits around&lt;br&gt;
&lt;strong&gt;12 to 13 TB of processed data a month&lt;/strong&gt;. Below it, Basic's lower floor&lt;br&gt;
wins. Above it, Basic is the expensive option wearing a budget name badge.&lt;br&gt;
Basic also caps throughput and trims features, so read the limits first. The&lt;br&gt;
one unforgivable move is quoting Standard's floor with Basic's meter, or vice&lt;br&gt;
versa; the two rate cards never mix.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Deallocate what sleeps
&lt;/h2&gt;

&lt;p&gt;Here is the rarest thing in cloud billing: an off switch. Azure Firewall can&lt;br&gt;
be &lt;strong&gt;deallocated&lt;/strong&gt;. Stopped, the per-hour fee stops with it; allocated again,&lt;br&gt;
it comes back in a few minutes. AWS offers nothing like this for a NAT&lt;br&gt;
Gateway, which makes it strange that so few Azure teams use it.&lt;/p&gt;

&lt;p&gt;A dev firewall runs 730 hours a month. The team that uses it works maybe 200&lt;br&gt;
of those. Deallocating outside working hours removes roughly &lt;strong&gt;70% of that&lt;br&gt;
firewall's hourly line&lt;/strong&gt;, which on Standard is around $640 a month per dev&lt;br&gt;
firewall, for the cost of a small automation script and a few minutes of&lt;br&gt;
patience on Monday morning. A firewall guarding an empty dev environment at&lt;br&gt;
3am is protecting sleep nobody is having.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Count your deployments
&lt;/h2&gt;

&lt;p&gt;The rates re-apply per deployment and per secured virtual hub. This is where&lt;br&gt;
tidy architecture gets expensive: firewalls multiply the way meeting invites&lt;br&gt;
do, one per region, one per environment, one per team that didn't want to&lt;br&gt;
share, and each one brings its own $912 floor before traffic.&lt;/p&gt;

&lt;p&gt;The consolidation play is standard hub-and-spoke: one firewall in the hub,&lt;br&gt;
spokes peered to it, instead of a firewall per VNet. The honest caveats: VNet&lt;br&gt;
peering carries its own per-GB charge, consolidation concentrates blast&lt;br&gt;
radius, and cross-region traffic should stay regional. But the arithmetic is&lt;br&gt;
blunt. Two Standard deployments doing the work of one is $912 a month of&lt;br&gt;
duplicated floor; count yours, then justify each one out loud.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Keep Azure-bound traffic off the meter
&lt;/h2&gt;

&lt;p&gt;With a blanket 0.0.0.0/0 route through the firewall, everything pays the&lt;br&gt;
meter, including traffic to your own Azure services. Backups to your own&lt;br&gt;
storage account, container image pulls from ACR, log shipping to your&lt;br&gt;
workspace: $0.016/GB each, for the privilege of being inspected on the way&lt;br&gt;
to your own resources.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Service endpoints are free&lt;/strong&gt; and keep Azure-service traffic on the Microsoft&lt;br&gt;
backbone without the firewall hairpin. Private endpoints cost roughly&lt;br&gt;
$0.01/hr plus $0.01/GB (checked 2026-08-03, directional) and buy the same&lt;br&gt;
bypass with a private IP where you need it. Route with some granularity&lt;br&gt;
instead of one blanket default, and the meter only sees the traffic that&lt;br&gt;
actually warrants inspection. Your security team keeps control of what&lt;br&gt;
matters; your backups stop paying tolls.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Hunt your top talkers
&lt;/h2&gt;

&lt;p&gt;Same discipline as on AWS, different console. Azure Firewall's logs (or the&lt;br&gt;
built-in workbook) aggregated by destination will produce a top-ten list, and&lt;br&gt;
the list will annoy you. The usual suspects: image pulls that a cache would&lt;br&gt;
kill, telemetry sending the same heartbeat uncompressed every ten seconds,&lt;br&gt;
CI downloading identical packages hundreds of times a day in case they&lt;br&gt;
changed, and one chatty third-party API nobody remembers integrating.&lt;/p&gt;

&lt;p&gt;Fix with caching, batching and compression, then re-check quarterly. New&lt;br&gt;
workloads invent new talkers. They always do.&lt;/p&gt;

&lt;h2&gt;
  
  
  6. Prune the forgotten floors
&lt;/h2&gt;

&lt;p&gt;Somewhere in your subscriptions there is a firewall from a proof of concept&lt;br&gt;
that ended in March. It bills $912 a month for existing. The floor charges&lt;br&gt;
whether bytes flow or not, which makes idle firewalls the purest waste on&lt;br&gt;
this list: nothing is being protected, inspected or even routed. Sweep for&lt;br&gt;
firewalls with near-zero processed data, then delete them, or deallocate the&lt;br&gt;
ones somebody swears they'll need again. The POC will not miss it.&lt;/p&gt;

&lt;h2&gt;
  
  
  7. Replace the floor and the meter with one flat price (this is us)
&lt;/h2&gt;

&lt;p&gt;The last option is the one I have a stake in, so weigh my enthusiasm&lt;br&gt;
accordingly. &lt;a href="https://enforza.io/secure-nat-gateway/" rel="noopener noreferrer"&gt;Enforza&lt;/a&gt; is a network virtual appliance,&lt;br&gt;
one Linux VM in your own VNet, that does the egress-firewall job: stateful&lt;br&gt;
L3/L4, FQDN/SNI-based allow and deny on what leaves, and its own source NAT,&lt;br&gt;
so it covers the outbound role too. Flat per-firewall licence, about $239 a&lt;br&gt;
month, less at fleet volume, &lt;strong&gt;$0/GB processed&lt;/strong&gt;, and the VM stays on your&lt;br&gt;
Azure bill because physics and Microsoft both insist.&lt;/p&gt;

&lt;p&gt;Against Standard's floor-plus-meter that typically lands &lt;strong&gt;up to 60–80%&lt;br&gt;
lower&lt;/strong&gt;, and the gap widens with traffic and with every consolidated hub&lt;br&gt;
deployment, because a flat line doesn't multiply. Directional and dated, so&lt;br&gt;
check it against your own bill: the &lt;a href="https://enforza.io/savings-calculator/" rel="noopener noreferrer"&gt;savings calculator&lt;/a&gt;&lt;br&gt;
takes two minutes, and the &lt;a href="https://enforza.io/worked-examples/azure-firewall-cost-example/" rel="noopener noreferrer"&gt;20 TB worked example&lt;/a&gt;&lt;br&gt;
prices the comparison line by line if you'd rather see the working.&lt;/p&gt;

&lt;p&gt;The honest boundaries. At low volume on Basic the gap narrows, and if you're&lt;br&gt;
deep into Premium's TLS inspection or Sentinel-native tooling, the native&lt;br&gt;
integration is a real reason to stay. And a deadline worth knowing either&lt;br&gt;
way: Microsoft is retiring default outbound access on &lt;strong&gt;March 31, 2026&lt;/strong&gt;,&lt;br&gt;
after which every workload needs an explicit egress path: Azure Firewall,&lt;br&gt;
NAT Gateway, Load Balancer outbound rules, or an NVA. You'll be making this&lt;br&gt;
decision anyway; the only question is whether you cost it first.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;p&gt;Audit first, then take the configuration savings, then decide what the&lt;br&gt;
remainder is worth:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Right-size the SKU. Premium unused features off; Basic only below
~12 TB/month.&lt;/li&gt;
&lt;li&gt;Deallocate dev and test outside working hours. The off switch exists.&lt;/li&gt;
&lt;li&gt;Count deployments; consolidate the duplicate floors.&lt;/li&gt;
&lt;li&gt;Service endpoints and granular routes; stop metering your own backups.&lt;/li&gt;
&lt;li&gt;Logs, top talkers, caching. Repeat quarterly.&lt;/li&gt;
&lt;li&gt;Delete the POC firewall from March.&lt;/li&gt;
&lt;li&gt;Flat-priced NVA if the floors and meters still add up to real money.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For the line-by-line anatomy, see &lt;a href="https://enforza.io/azure-firewall-cost/" rel="noopener noreferrer"&gt;Azure Firewall pricing&lt;/a&gt;&lt;br&gt;
and the &lt;a href="https://enforza.io/azure-nat-gateway-cost/" rel="noopener noreferrer"&gt;Azure NAT Gateway breakdown&lt;/a&gt;; for the same&lt;br&gt;
exercise on AWS, &lt;a href="https://enforza.io/articles/reduce-aws-nat-gateway-costs/" rel="noopener noreferrer"&gt;how to reduce AWS NAT Gateway costs&lt;/a&gt;;&lt;br&gt;
for the multi-cloud view, &lt;a href="https://enforza.io/articles/cloud-nat-costs/" rel="noopener noreferrer"&gt;reducing cloud NAT costs&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How much does Azure Firewall cost?
&lt;/h3&gt;

&lt;p&gt;Two charges at once. A per-deployment-hour fee of $1.25/hr on Standard (about $912/month) or $1.75/hr on Premium (about $1,278/month), before any traffic, plus $0.016 per GB processed, uncapped. The cheaper Basic SKU is $0.395/hr (about $288/month) but pays a higher $0.065/GB. The same rates re-apply per secured virtual hub, so multi-region hub-and-spoke estates multiply the hourly line. Rates Central US, dated 2026-07-04, directional.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I turn Azure Firewall off when I'm not using it?
&lt;/h3&gt;

&lt;p&gt;Yes, and almost nobody does. Azure Firewall supports deallocation: stop it and the per-hour billing stops with it; allocate it again when you need it, which takes a few minutes. For a dev or test firewall that nobody touches outside working hours, deallocating nights and weekends removes roughly 70% of that firewall's hourly line. It needs a small automation script and the willingness to wait a few minutes on Monday morning.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is Azure Firewall Basic cheaper than Standard?
&lt;/h3&gt;

&lt;p&gt;On the floor, yes: about $288/month versus about $912/month. On the meter, no: Basic processes data at $0.065/GB against Standard's $0.016/GB, four times the rate. The break-even is around 12 to 13 TB of processed data a month; below it Basic wins, above it Basic quietly becomes the expensive option. Basic also caps throughput and drops features, so check the limits before celebrating. Never mix the two rate cards in one estimate.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need Azure Firewall and a NAT Gateway?
&lt;/h3&gt;

&lt;p&gt;Usually not both for egress. Azure Firewall performs its own source NAT, so there is no AWS-style NAT-gateway-behind-firewall stacking. The question is becoming unavoidable anyway: Microsoft is retiring default outbound access (March 31, 2026), after which every workload needs an explicit egress path: Azure Firewall, a NAT Gateway, Load Balancer outbound rules, or an NVA. Which one you pick is now a costed decision rather than a default.&lt;/p&gt;

&lt;h3&gt;
  
  
  What Azure Firewall traffic costs the most?
&lt;/h3&gt;

&lt;p&gt;Whatever you hairpin through it that never needed inspection. With a blanket 0.0.0.0/0 route through the firewall, backups to your own storage accounts, container image pulls and log shipping all pay $0.016/GB for the privilege of being waved through. Firewall logs (or the workbook) aggregated by destination will show your top ten. The fixes are routing granularity, service endpoints and caching, in that order.&lt;/p&gt;

&lt;h3&gt;
  
  
  How much can I save replacing Azure Firewall?
&lt;/h3&gt;

&lt;p&gt;It depends on volume and how many deployments you run, and anyone quoting one number without asking is selling something. A flat-priced NVA such as Enforza does the same egress-firewall job (stateful L3/L4, FQDN/SNI filtering, its own source NAT) at a flat per-firewall licence, about $239/month, less at fleet volume, plus the VM on your Azure bill. Against Standard's $912/month floor plus metering, that typically lands up to 60–80% lower, and the gap widens with traffic and with every extra hub deployment. At low volume on Basic, the honest answer is the gap narrows. Run your own numbers in the savings calculator, or read the 20 TB worked example priced line by line.&lt;/p&gt;

</description>
      <category>azure</category>
      <category>devops</category>
      <category>cloud</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>How to reduce AWS NAT Gateway costs: 7 ways, ranked by savings</title>
      <dc:creator>Neil Briscoe</dc:creator>
      <pubDate>Mon, 03 Aug 2026 14:49:39 +0000</pubDate>
      <link>https://dev.to/enforza/how-to-reduce-aws-nat-gateway-costs-7-ways-ranked-by-savings-ll4</link>
      <guid>https://dev.to/enforza/how-to-reduce-aws-nat-gateway-costs-7-ways-ranked-by-savings-ll4</guid>
      <description>&lt;p&gt;The AWS NAT Gateway bill has two lines. The hourly fee is $0.045 per&lt;br&gt;
gateway-hour, about $33 a month, and it is the least interesting number on your&lt;br&gt;
invoice. The other line is the &lt;strong&gt;data-processing charge&lt;/strong&gt;: $0.045 for every&lt;br&gt;
gigabyte the gateway touches, in either direction. That one compounds. It grows&lt;br&gt;
with traffic you didn't know was internet-bound, it multiplies across&lt;br&gt;
Availability Zones, and it surfaces in a bill review three months later as a&lt;br&gt;
number nobody can explain and everybody has approved. Nobody has ever been&lt;br&gt;
paged for a NAT Gateway, which is precisely why nobody looks at it. (Rates&lt;br&gt;
us-east-1, dated 2026-07-31, directional.)&lt;/p&gt;

&lt;p&gt;Disclosure before we start: I work on &lt;a href="https://enforza.io/" rel="noopener noreferrer"&gt;Enforza&lt;/a&gt;, which is option 7 below. It&lt;br&gt;
gets one section, at the end, after six things you should try first. Several of&lt;br&gt;
them are free, which is a difficult price to argue with.&lt;/p&gt;

&lt;p&gt;The list is ranked by how much of the bill each move typically removes, not by&lt;br&gt;
how interesting it is to implement. The boring ones are at the top. That's&lt;br&gt;
where the money is.&lt;/p&gt;

&lt;h2&gt;
  
  
  The ranking at a glance
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Free gateway endpoints for S3 and DynamoDB.&lt;/strong&gt; Often removes 30–60% of the
per-GB line. Costs nothing. Do it today.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Interface endpoints for busy AWS services.&lt;/strong&gt; The next 10–30%, wherever a
service clears the break-even.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Hunt your top talkers with VPC Flow Logs.&lt;/strong&gt; 10–40% once you can actually
see the traffic. The fixes are mostly caching and hygiene.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Route zonally, or consolidate deliberately.&lt;/strong&gt; Stops the cross-AZ surcharge
stacking on top of NAT processing.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Consolidate non-production.&lt;/strong&gt; Pure hourly-line savings. Sprawling dev
estates leak $33 a month per forgotten gateway.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Swap in a NAT instance (fck-nat).&lt;/strong&gt; Kills the per-GB line entirely, in
exchange for owning the operations.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A flat-priced NVA with egress filtering built in.&lt;/strong&gt; Kills the per-GB line
and the separate firewall meter, for a flat licence plus a VM you run.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Now each one, with the arithmetic.&lt;/p&gt;

&lt;h2&gt;
  
  
  1. Add the free S3 and DynamoDB gateway endpoints
&lt;/h2&gt;

&lt;p&gt;Gateway endpoints for S3 and DynamoDB are free in the way AWS things rarely&lt;br&gt;
are: actually free. No hourly fee, no per-GB fee. A route-table entry sends&lt;br&gt;
that traffic over the endpoint instead of through NAT, and the charge simply&lt;br&gt;
stops.&lt;/p&gt;

&lt;p&gt;This is usually the single largest cut available, and it is bigger than people&lt;br&gt;
expect for one sneaky reason: &lt;strong&gt;container image pulls ride on S3&lt;/strong&gt;. ECR stores&lt;br&gt;
image layers in S3, so a busy EKS cluster pulling through a NAT Gateway has&lt;br&gt;
been paying NAT rates to re-download the same Ubuntu layers it downloaded&lt;br&gt;
yesterday. And the day before.&lt;/p&gt;

&lt;p&gt;There is no threshold, no break-even and no trade-off here beyond a route-table&lt;br&gt;
change per VPC. If you read no further, do this one.&lt;/p&gt;

&lt;h2&gt;
  
  
  2. Add interface endpoints for the busy AWS services
&lt;/h2&gt;

&lt;p&gt;Interface endpoints (PrivateLink) extend the same idea to the rest of AWS:&lt;br&gt;
ECR's API, CloudWatch Logs, STS, SSM, Secrets Manager. Unlike gateway&lt;br&gt;
endpoints they are not free. Roughly $0.01 per hour per endpoint per AZ plus&lt;br&gt;
about $0.01/GB (us-east-1, checked 2026-07-31, directional).&lt;/p&gt;

&lt;p&gt;The arithmetic that matters: you save about $0.035/GB versus NAT processing,&lt;br&gt;
and the endpoint's standing cost is about $7.30 a month per AZ. So an&lt;br&gt;
interface endpoint pays for itself at roughly &lt;strong&gt;200 GB a month per service&lt;/strong&gt;.&lt;br&gt;
ECR and log shipping clear that on any real cluster without noticing. The&lt;br&gt;
service you call twice a day does not, and endpointing it anyway is how people&lt;br&gt;
end up reducing their NAT bill by increasing their total bill.&lt;/p&gt;

&lt;p&gt;Which services are busy enough? That's step 3.&lt;/p&gt;

&lt;h2&gt;
  
  
  3. Find your top talkers with VPC Flow Logs
&lt;/h2&gt;

&lt;p&gt;You can't cut traffic you can't see. Turn on VPC Flow Logs for the NAT&lt;br&gt;
Gateway's network interfaces, aggregate by destination, rank, and prepare to be&lt;br&gt;
mildly annoyed by what you find. Every big NAT-savings write-up on the&lt;br&gt;
internet, all the "how we cut 40%" and "how we cut 52%" posts, is secretly this&lt;br&gt;
step wearing a headline.&lt;/p&gt;

&lt;p&gt;The usual suspects, and the usual fixes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Image pulls.&lt;/strong&gt; Slim the images, add a pull-through cache, and check the S3
endpoint from step 1 is actually carrying the layers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Log and telemetry shipping.&lt;/strong&gt; Batch and compress, and send CloudWatch-bound
traffic over an interface endpoint rather than out the front door.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Package registries in CI.&lt;/strong&gt; Your build farm is downloading the same
packages four hundred times a day, apparently in case they change. A proxy
cache (or CodeArtifact) turns that into once.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Chatty third-party APIs.&lt;/strong&gt; Batch where the API allows it. You are paying
NAT processing on every iteration of somebody's polling loop.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Expect to repeat this quarterly. New workloads invent new talkers, reliably.&lt;/p&gt;

&lt;h2&gt;
  
  
  4. Stop paying the cross-AZ surcharge
&lt;/h2&gt;

&lt;p&gt;Traffic from a subnet in one Availability Zone through a NAT Gateway in&lt;br&gt;
another pays cross-AZ data transfer &lt;strong&gt;on top of&lt;/strong&gt; NAT processing. You are&lt;br&gt;
paying a surcharge for your bytes to commute between buildings before they&lt;br&gt;
leave. If you consolidated to one gateway "to save money" and now push serious&lt;br&gt;
traffic to it from three AZs, part of that saving is being quietly clawed&lt;br&gt;
back, and you gained a cross-AZ failure dependency as a bonus.&lt;/p&gt;

&lt;p&gt;High-traffic estates want a gateway per AZ with zonal route tables so traffic&lt;br&gt;
stays local. Small quiet estates want the opposite: one gateway, accept the&lt;br&gt;
cross-AZ pennies, bank the duplicate hourly fees. There is no universal&lt;br&gt;
answer, just a break-even, and it takes ten minutes with your traffic numbers&lt;br&gt;
to find out which side of it you live on.&lt;/p&gt;

&lt;h2&gt;
  
  
  5. Consolidate non-production
&lt;/h2&gt;

&lt;p&gt;Production topology gets designed. Dev topology gets copied from the&lt;br&gt;
production template, faithfully, including the parts that cost money at 2am.&lt;br&gt;
Every sandbox VPC with three NAT gateways (one per AZ, because that's what&lt;br&gt;
prod does) is paying the hourly line for connectivity nobody is using.&lt;/p&gt;

&lt;p&gt;Ten forgotten gateways is $330 a month, which is a decent team dinner nobody&lt;br&gt;
got to eat. Centralise non-prod egress where isolation requirements allow, and&lt;br&gt;
for truly ephemeral environments let the IaC tear the gateway down with the&lt;br&gt;
rest of the stack. It will not miss you. (If you're consolidating egress&lt;br&gt;
across VPCs properly, the &lt;a href="https://enforza.io/landing-zones/aws/" rel="noopener noreferrer"&gt;AWS landing-zone pattern&lt;/a&gt;&lt;br&gt;
shows the route-table shape; it's the same pattern whoever's appliance sits in&lt;br&gt;
the middle.)&lt;/p&gt;

&lt;h2&gt;
  
  
  6. Swap in a NAT instance you operate
&lt;/h2&gt;

&lt;p&gt;A NAT instance is a VM doing source NAT, which is what the managed gateway is&lt;br&gt;
underneath anyway. It pays &lt;strong&gt;no per-GB processing fee at all&lt;/strong&gt;. Just the&lt;br&gt;
instance and normal data-transfer-out. &lt;a href="https://enforza.io/compare/fck-nat/" rel="noopener noreferrer"&gt;fck-nat&lt;/a&gt; is the&lt;br&gt;
well-maintained open-source version (the name tells you the founding mood):&lt;br&gt;
current ARM images, a clean Terraform module, and instances that cost a few&lt;br&gt;
dollars a month per AZ. On the metered line it is unbeatable, and our own&lt;br&gt;
comparison page says so.&lt;/p&gt;

&lt;p&gt;What you take on in exchange: high availability (its documented failover is&lt;br&gt;
active-passive with route reconvergence), patching, monitoring, and the box's&lt;br&gt;
own attack surface. And it is exactly NAT. It is excellent at what it does;&lt;br&gt;
what it does is NAT. If you need to control or even see what is leaving your&lt;br&gt;
network, that is not on the menu.&lt;/p&gt;

&lt;h2&gt;
  
  
  7. Replace the meter with a flat price (this is us)
&lt;/h2&gt;

&lt;p&gt;The last option is the one I have a stake in, so weigh my enthusiasm&lt;br&gt;
accordingly. &lt;a href="https://enforza.io/secure-nat-gateway/" rel="noopener noreferrer"&gt;Enforza&lt;/a&gt; is a network virtual appliance,&lt;br&gt;
one Linux VM in your own VPC, that does the NAT Gateway's job with &lt;strong&gt;no per-GB&lt;br&gt;
charge&lt;/strong&gt; at a flat per-firewall licence: about $239 a month, less at fleet&lt;br&gt;
volume, and the VM itself stays on your AWS bill because we are not magicians.&lt;br&gt;
The difference from option 6 is that it's managed (HA, patching and fleet&lt;br&gt;
policy handled) and it's also an egress firewall: FQDN/SNI-based allow and&lt;br&gt;
deny on what leaves, with logs your auditor will accept. So it can replace a&lt;br&gt;
separate firewall meter as well as the NAT one.&lt;/p&gt;

&lt;p&gt;The honest boundaries. At low volumes a plain NAT Gateway with free endpoints&lt;br&gt;
is hard to beat, and I'd rather tell you that here than have you discover it&lt;br&gt;
in a renewal meeting. The "up to 60–80%" saving we quote is against a metered&lt;br&gt;
NAT-plus-firewall stack at meaningful volume: dated, directional, and worth&lt;br&gt;
checking against your own bill in the&lt;br&gt;
&lt;a href="https://enforza.io/savings-calculator/" rel="noopener noreferrer"&gt;savings calculator&lt;/a&gt; rather than taking on faith. One&lt;br&gt;
wrinkle worth knowing: since 2026-02-06 AWS waives the NAT Gateway fee when&lt;br&gt;
the gateway sits behind AWS Network Firewall. If you're already paying Network&lt;br&gt;
Firewall's $0.065/GB, filtered egress is one meter, not two, and that one&lt;br&gt;
meter is the comparison to run.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;p&gt;Measure first, take the free money, then decide how much of the remainder is&lt;br&gt;
worth engineering away:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Gateway endpoints for S3 and DynamoDB. Free, immediate, often the biggest
single cut.&lt;/li&gt;
&lt;li&gt;Interface endpoints where a service clears ~200 GB a month.&lt;/li&gt;
&lt;li&gt;Flow Logs, then fix the top talkers. Mostly caching and hygiene.&lt;/li&gt;
&lt;li&gt;Zonal routing (or deliberate consolidation). Stop stacking cross-AZ on NAT.&lt;/li&gt;
&lt;li&gt;Non-prod cleanup. The hourly line there is pure waste.&lt;/li&gt;
&lt;li&gt;NAT instance / fck-nat, if you can own the ops.&lt;/li&gt;
&lt;li&gt;Flat-priced NVA with egress filtering, if you want it managed or you were
about to pay for a firewall anyway.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For the line-by-line anatomy of the bill itself, see&lt;br&gt;
&lt;a href="https://enforza.io/articles/aws-nat-gateway-cost-and-alternatives/" rel="noopener noreferrer"&gt;what an AWS NAT Gateway actually costs&lt;/a&gt;&lt;br&gt;
and the &lt;a href="https://enforza.io/aws-nat-gateway-cost/" rel="noopener noreferrer"&gt;rates-at-a-glance page&lt;/a&gt;; for the mechanics of&lt;br&gt;
NAT, &lt;a href="https://enforza.io/articles/how-nat-gateways-work/" rel="noopener noreferrer"&gt;how NAT gateways work&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I reduce AWS NAT Gateway costs?
&lt;/h3&gt;

&lt;p&gt;In order of typical impact: add the free S3 and DynamoDB gateway endpoints so that traffic never touches the NAT Gateway at all; add interface endpoints (PrivateLink) for busy AWS services like ECR and CloudWatch; use VPC Flow Logs to find and fix your top talkers; route zonally so you aren't paying cross-AZ transfer on top of NAT processing; consolidate non-production gateways; and for the remaining internet egress, replace the gateway with a NAT instance you operate or a flat-priced NVA. The per-GB data-processing charge is almost always the line to attack. The hourly fee is a rounding error next to it.&lt;/p&gt;

&lt;h3&gt;
  
  
  What uses the most NAT Gateway data?
&lt;/h3&gt;

&lt;p&gt;On most estates the biggest single slice is traffic to AWS's own services: container image pulls (ECR layers are stored in S3), log shipping, and S3 access from private subnets. None of it needed to go through NAT in the first place. After that come package registries during builds, telemetry agents, and chatty third-party APIs. VPC Flow Logs aggregated by destination will show your actual top ten in an afternoon.&lt;/p&gt;

&lt;h3&gt;
  
  
  Are VPC endpoints free?
&lt;/h3&gt;

&lt;p&gt;Gateway endpoints for Amazon S3 and DynamoDB are free. No hourly fee, no per-GB fee, which is why they are always step one. Interface endpoints (PrivateLink) are not free: roughly $0.01 per hour per endpoint per Availability Zone plus about $0.01/GB (us-east-1, checked 2026-07-31, directional). That beats the NAT Gateway's $0.045/GB from roughly 200 GB a month per service. Below that volume the endpoint costs more than it saves.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does one NAT Gateway per Availability Zone save money?
&lt;/h3&gt;

&lt;p&gt;It removes the cross-AZ data-transfer charge you pay when a subnet in one AZ routes through a gateway in another, and it removes a cross-AZ failure dependency. But each gateway also adds its own hourly fee, about $33 a month. High-traffic production estates usually save with per-AZ gateways; small quiet VPCs often save by consolidating to one gateway and accepting the cross-AZ pennies. Which side of the line you are on is arithmetic, not doctrine.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is a NAT instance cheaper than a NAT Gateway?
&lt;/h3&gt;

&lt;p&gt;On the metered line, dramatically. A NAT instance pays no $0.045/GB processing fee, just the VM and normal data-transfer-out. fck-nat, the well-maintained open-source option, runs on instances costing a few dollars a month per AZ. The trade is operational: high availability, patching and monitoring are yours, and it is plain source NAT with no egress filtering. It is the right answer when you can own the ops and only need connectivity.&lt;/p&gt;

&lt;h3&gt;
  
  
  How much can I save replacing the NAT Gateway entirely?
&lt;/h3&gt;

&lt;p&gt;It depends on volume, and anyone who gives you one number without asking about your traffic is selling something. A NAT instance removes the per-GB line for the cost of your own operations. A flat-priced NVA such as Enforza removes it for a flat per-firewall licence (about $239/month, less at fleet volume, plus the VM on your AWS bill) and adds FQDN egress filtering. Against a metered NAT-plus-firewall stack that typically lands up to 60–80% lower from meaningful egress volumes, and the gap widens as traffic grows. At low volumes the honest answer is that a plain NAT Gateway with free gateway endpoints is hard to beat. Run your own numbers.&lt;/p&gt;

</description>
      <category>aws</category>
      <category>devops</category>
      <category>cloud</category>
      <category>tutorial</category>
    </item>
    <item>
      <title>enforza-cockpit: a free web GUI for nftables</title>
      <dc:creator>Neil Briscoe</dc:creator>
      <pubDate>Fri, 31 Jul 2026 14:07:37 +0000</pubDate>
      <link>https://dev.to/enforza/enforza-cockpit-a-free-web-gui-for-nftables-o1c</link>
      <guid>https://dev.to/enforza/enforza-cockpit-a-free-web-gui-for-nftables-o1c</guid>
      <description>&lt;p&gt;nftables is the right tool for a Linux firewall and a genuinely nice piece of&lt;br&gt;
engineering, but writing rulesets by hand is a niche pleasure. If you run a homelab&lt;br&gt;
or a small cloud box and you want a firewall you can see and click, without pulling&lt;br&gt;
in a whole appliance distribution or standing up something in the cloud, there is a&lt;br&gt;
free, open-source option worth knowing about:&lt;br&gt;
&lt;a href="https://github.com/enforza/enforza-cockpit" rel="noopener noreferrer"&gt;enforza-cockpit&lt;/a&gt;. It is a &lt;a href="https://cockpit-project.org/" rel="noopener noreferrer"&gt;Cockpit&lt;/a&gt; plugin that gives you a browser GUI over&lt;br&gt;
nftables. Install it, build a policy, and watch per-rule logs land in your syslog.&lt;/p&gt;

&lt;p&gt;This article walks through what it is and how to use it. It asks nothing of you and&lt;br&gt;
there is nothing to buy, so read it as a how-to. The one-line disclosure of who&lt;br&gt;
makes it is at the bottom where it belongs.&lt;/p&gt;
&lt;h2&gt;
  
  
  What it actually is
&lt;/h2&gt;

&lt;p&gt;enforza-cockpit turns a single Linux box into three things that usually come&lt;br&gt;
separately, all on the one host and with nothing external to depend on:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdnd7h0ye69sqo5wptr0w.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fdnd7h0ye69sqo5wptr0w.png" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;A firewall.&lt;/strong&gt; Three rule sections compile to a live nftables ruleset that
filters traffic to, through, and from the host.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A router and NAT gateway.&lt;/strong&gt; Turn on IP forwarding and the box routes between
its interfaces; mark a rule SNAT and it masquerades outbound traffic, so it works
as an edge gateway for whatever sits behind it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A management console.&lt;/strong&gt; Cockpit's web UI is the console. You build, preview,
apply and log every rule from the browser. There is no separate controller, no
agent phoning home, and no cloud account.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Because it runs entirely on the one host and inside Cockpit's own authentication&lt;br&gt;
and TLS, the result is a stand-alone appliance you happen to manage from a web&lt;br&gt;
page. That is the whole idea: a clean GUI wrapper for a local nftables firewall,&lt;br&gt;
nothing more clever than that.&lt;/p&gt;
&lt;h2&gt;
  
  
  Installing it
&lt;/h2&gt;

&lt;p&gt;You need a Linux server with root or sudo, inbound access to TCP 9090 (Cockpit's&lt;br&gt;
web port) from wherever you browse, and a browser. On a cloud instance, open 9090&lt;br&gt;
in the security group to your own IP only, not the world.&lt;/p&gt;

&lt;p&gt;There are two scripts. The first clones the repo and installs the prerequisites,&lt;br&gt;
detecting your package manager along the way:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/enforza/enforza-cockpit.git
&lt;span class="nb"&gt;cd &lt;/span&gt;enforza-cockpit
&lt;span class="nb"&gt;sudo&lt;/span&gt; ./bootstrap.sh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That pulls in nftables, its JSON/Python bindings (so the GUI can read and write the&lt;br&gt;
ruleset programmatically), ulogd2 for userspace netfilter logging, and Cockpit&lt;br&gt;
itself. It enables Cockpit's socket immediately, and enables the nftables service&lt;br&gt;
but deliberately does not start it with an empty ruleset, so it cannot lock you out&lt;br&gt;
before you have written a policy.&lt;/p&gt;

&lt;p&gt;The second script installs the plugin into Cockpit:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo&lt;/span&gt; ./deploy.sh
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;That copies the built files into Cockpit's system package directory&lt;br&gt;
(&lt;code&gt;/usr/share/cockpit/enforza&lt;/code&gt;). Browse to &lt;code&gt;https://&amp;lt;your-host&amp;gt;:9090&lt;/code&gt;, accept the&lt;br&gt;
self-signed certificate warning on a fresh install, and log in with a local system&lt;br&gt;
account that can use sudo. The firewall plugin needs administrative privilege, so&lt;br&gt;
if Cockpit shows a "Limited access" banner, click it and re-authenticate. The&lt;br&gt;
plugin then appears as &lt;strong&gt;Firewall (enforza)&lt;/strong&gt; in the left-hand menu.&lt;/p&gt;
&lt;h2&gt;
  
  
  The three chains, in plain terms
&lt;/h2&gt;

&lt;p&gt;The reason a GUI over nftables is useful is that the mental model is simple once&lt;br&gt;
someone lays it out. enforza-cockpit gives you three rule sections, and each maps&lt;br&gt;
directly to one of nftables' filter hooks:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Tab&lt;/th&gt;
&lt;th&gt;nftables hook&lt;/th&gt;
&lt;th&gt;What it controls&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Management&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;input&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic &lt;strong&gt;to&lt;/strong&gt; the box itself: SSH, the Cockpit port, health checks.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Network&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;forward&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic passing &lt;strong&gt;through&lt;/strong&gt; the box between other hosts and the internet.&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;strong&gt;Local&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;&lt;code&gt;output&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Traffic originating &lt;strong&gt;from&lt;/strong&gt; the box: updates, DNS, outbound calls.&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Each section has a default action (accept or drop). First match wins; anything a&lt;br&gt;
rule does not catch falls through to the default. There is also an &lt;strong&gt;Objects&lt;/strong&gt; tab&lt;br&gt;
for reusable named network (CIDR) and port sets: define &lt;code&gt;home-lan&lt;/code&gt;, &lt;code&gt;mgmt&lt;/code&gt;, &lt;code&gt;web&lt;/code&gt;&lt;br&gt;
once and reference them as &lt;code&gt;@home-lan&lt;/code&gt;, &lt;code&gt;@web&lt;/code&gt; and so on across any rule. Edit the&lt;br&gt;
object and every rule using it updates, which is the same reason you use named sets&lt;br&gt;
in a hand-written ruleset, minus the typing.&lt;/p&gt;

&lt;p&gt;If you have ever stared at &lt;code&gt;input&lt;/code&gt;, &lt;code&gt;forward&lt;/code&gt; and &lt;code&gt;output&lt;/code&gt; in the docs and not&lt;br&gt;
been quite sure which one your rule belonged in, seeing them as three labelled&lt;br&gt;
tabs is most of the value on its own.&lt;/p&gt;
&lt;h2&gt;
  
  
  Building a first policy
&lt;/h2&gt;

&lt;p&gt;The safe first policy is a locked-down Management section: allow SSH and the&lt;br&gt;
Cockpit port from your own address, drop everything else. In the Management tab,&lt;br&gt;
set the default action to &lt;strong&gt;drop&lt;/strong&gt;, then add a rule:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Action&lt;/strong&gt; &lt;code&gt;accept&lt;/code&gt;, &lt;strong&gt;Protocol&lt;/strong&gt; &lt;code&gt;tcp&lt;/code&gt;, &lt;strong&gt;Destination port&lt;/strong&gt; &lt;code&gt;22&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Source&lt;/strong&gt; your admin IP or CIDR (or &lt;code&gt;any&lt;/code&gt; to start with)&lt;/li&gt;
&lt;li&gt;Tick &lt;strong&gt;Log matches&lt;/strong&gt;, which is what puts the rule in your syslog&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Comment&lt;/strong&gt; &lt;code&gt;SSH from admin&lt;/code&gt;, which is included in the log line, so make it mean
something&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Add a second rule the same way for TCP 9090 so you keep the Cockpit UI. And heed&lt;br&gt;
the obvious warning: allow SSH &lt;strong&gt;and&lt;/strong&gt; Cockpit from your own IP before you apply a&lt;br&gt;
default-drop policy, or you will be relying on the auto-revert to get back in.&lt;/p&gt;

&lt;p&gt;Then the apply flow, which is the part that makes this safe to do on a box you care&lt;br&gt;
about:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Preview&lt;/strong&gt; renders the policy to nftables JSON and dry-runs it against the
kernel. A green "Valid" means the kernel accepts it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Apply&lt;/strong&gt; puts it live and starts a &lt;strong&gt;confirm-or-revert&lt;/strong&gt; banner with a 60-second
countdown.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Verify you still have access.&lt;/strong&gt; Open a fresh SSH session, or just check the
Cockpit page still responds.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Confirm&lt;/strong&gt; to keep the ruleset. Do nothing and it auto-reverts to the previous
one; there is also a Revert now button.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Save&lt;/strong&gt; persists the policy document to &lt;code&gt;/etc/enforza/policy.json&lt;/code&gt; so it reloads
next time.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Your rules are now live in the &lt;code&gt;inet enforza&lt;/code&gt; nftables table, and you can always&lt;br&gt;
check what actually landed from a shell with &lt;code&gt;sudo nft list table inet enforza&lt;/code&gt;.&lt;br&gt;
The GUI is a front end; the kernel state is the truth, and nothing stops you&lt;br&gt;
reading it directly.&lt;/p&gt;
&lt;h2&gt;
  
  
  Turning it into a router and NAT gateway
&lt;/h2&gt;

&lt;p&gt;The Network tab (the &lt;code&gt;forward&lt;/code&gt; path) is where the box stops being just a host&lt;br&gt;
firewall and becomes a gateway. Turn on &lt;strong&gt;Enable routing&lt;/strong&gt; to switch on IP&lt;br&gt;
forwarding, then add a Network rule and mark it &lt;strong&gt;SNAT&lt;/strong&gt;. That masquerades outbound&lt;br&gt;
traffic from the hosts behind the box out through its public interface, so a single&lt;br&gt;
Linux instance becomes the edge gateway for a whole segment: a lab network, a set&lt;br&gt;
of VMs, or the machines on a home LAN. Network rules can carry both a &lt;strong&gt;LOG&lt;/strong&gt; flag&lt;br&gt;
and the &lt;strong&gt;SNAT&lt;/strong&gt; flag, so you can log and source-NAT the same traffic, and&lt;br&gt;
reference &lt;code&gt;@objects&lt;/code&gt; for source, destination and ports to keep the rules readable.&lt;/p&gt;

&lt;p&gt;That is the same job a small cloud NAT instance does, on hardware you already have.&lt;/p&gt;
&lt;h2&gt;
  
  
  Watching the logs
&lt;/h2&gt;

&lt;p&gt;Any rule with &lt;strong&gt;Log matches&lt;/strong&gt; ticked emits a kernel log line each time it matches,&lt;br&gt;
and enforza-cockpit tags every line with three useful things: the section&lt;br&gt;
(&lt;code&gt;to-firewall&lt;/code&gt;, &lt;code&gt;through-firewall&lt;/code&gt; or &lt;code&gt;from-firewall&lt;/code&gt;), a plain verdict word&lt;br&gt;
(&lt;code&gt;ALLOW&lt;/code&gt;, &lt;code&gt;DENY&lt;/code&gt; or &lt;code&gt;REJECT&lt;/code&gt;), and your rule's comment. So a matched SSH accept&lt;br&gt;
reads like:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight console"&gt;&lt;code&gt;&lt;span class="go"&gt;kernel: enforza to-firewall ALLOW: SSH from admin IN=eth0 ... SRC=203.0.113.10 DPT=22 ...
&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Because the verdict is a plain word, grep does the rest:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;&lt;span class="nb"&gt;sudo tail&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; /var/log/syslog | &lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="s1"&gt;'enforza.*DENY'&lt;/span&gt;   &lt;span class="c"&gt;# only denials&lt;/span&gt;
&lt;span class="nb"&gt;sudo tail&lt;/span&gt; &lt;span class="nt"&gt;-f&lt;/span&gt; /var/log/syslog | &lt;span class="nb"&gt;grep&lt;/span&gt; &lt;span class="s1"&gt;'SSH from admin'&lt;/span&gt;  &lt;span class="c"&gt;# one rule, by its comment&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;On distributions without &lt;code&gt;/var/log/syslog&lt;/code&gt; (many dnf-based ones), read the kernel&lt;br&gt;
log through the journal instead with &lt;code&gt;sudo journalctl -kf | grep enforza&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;One gotcha worth internalising, because it catches everyone once: a section's&lt;br&gt;
&lt;strong&gt;default&lt;/strong&gt; drop is not logged. If you want to see what is being denied, add an&lt;br&gt;
explicit last rule with &lt;strong&gt;Action&lt;/strong&gt; &lt;code&gt;drop&lt;/code&gt; (or &lt;code&gt;reject&lt;/code&gt;), &lt;strong&gt;Source&lt;/strong&gt; &lt;code&gt;any&lt;/code&gt; and&lt;br&gt;
&lt;strong&gt;Log matches&lt;/strong&gt; ticked, and make sure it sits at the bottom of the list. First&lt;br&gt;
match wins, so a logging catch-all only works as the final rule.&lt;/p&gt;

&lt;h2&gt;
  
  
  What it isn't
&lt;/h2&gt;

&lt;p&gt;Since being honest about limits is more useful than a feature list, here is what&lt;br&gt;
enforza-cockpit does not do:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;No application-layer filtering.&lt;/strong&gt; It is plain nftables: L3/L4 rules plus SNAT.
There is no FQDN or hostname filtering, no SNI inspection, no L7 anything. If you
need to allow &lt;code&gt;github.com&lt;/code&gt; but not the rest of the internet, this is not the tool.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;One host, not a fleet.&lt;/strong&gt; It manages the box it runs on. There is no central
console, no pushing one policy to many machines, and no policy-as-code pipeline.
For a homelab that is exactly right; for fifty boxes it is fifty logins.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A static ruleset.&lt;/strong&gt; The kernel enforces the rules you compiled. It does not
learn, score, or adapt, and it does not pretend to.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of that is a criticism. It is a small, sharp tool that does one job well, and&lt;br&gt;
knowing the edges is what lets you use it confidently.&lt;/p&gt;

&lt;h2&gt;
  
  
  Who makes it
&lt;/h2&gt;

&lt;p&gt;enforza-cockpit is a free, MIT-licensed community tool from the people behind&lt;br&gt;
&lt;a href="https://enforza.io" rel="noopener noreferrer"&gt;enforza&lt;/a&gt;, a managed cloud-firewall platform. It needs no&lt;br&gt;
account and no cloud connection, the code is open so you can read exactly what it&lt;br&gt;
does to your box, and contributions and bug reports are welcome. That is the whole&lt;br&gt;
disclosure. Go build a firewall.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is enforza-cockpit really free?
&lt;/h3&gt;

&lt;p&gt;Yes. It is MIT-licensed and open source, needs no account, no cloud connection and no subscription, and all firewall state stays on your machine. The repo is github.com/enforza/enforza-cockpit.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is it built on?
&lt;/h3&gt;

&lt;p&gt;It is a plugin for Cockpit, the web console that ships with most Linux distributions. The GUI renders your policy to a live nftables ruleset (in a table called inet enforza) and lets the kernel do the enforcing. A bootstrap script installs nftables, its JSON/Python bindings, ulogd2 for logging, and Cockpit itself.&lt;/p&gt;

&lt;h3&gt;
  
  
  Which Linux distributions does it support?
&lt;/h3&gt;

&lt;p&gt;Debian and Ubuntu, Fedora, RHEL/Rocky/Alma, and openSUSE. The bootstrap script detects your package manager (apt, dnf, yum or zypper) so the same steps work across the common homelab and small-cloud distributions.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can a bad rule lock me out of the box?
&lt;/h3&gt;

&lt;p&gt;It is designed so it cannot, permanently. Every apply uses a confirm-or-revert model: after you click Apply you have 60 seconds to click Confirm, and if you do not, the previous ruleset is automatically restored. Keep a second way onto the box handy the first few times anyway. If you ever do get stuck, get on out-of-band and run nft flush ruleset or nft delete table inet enforza.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does it do FQDN or application-layer filtering?
&lt;/h3&gt;

&lt;p&gt;No, and it is worth being clear about that. It is a GUI over plain nftables: L3/L4 rules on the three chains (traffic to, through and from the host) plus SNAT. There is no FQDN, SNI or other L7 filtering, and it manages one host, not a fleet. If that is what you need, this is not the tool.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can it act as a router and NAT gateway?
&lt;/h3&gt;

&lt;p&gt;Yes. Turn on Enable routing (IP forwarding) and the box routes between its interfaces; mark a Network rule SNAT and it masquerades outbound traffic, so it works as an edge gateway for the machines behind it. That is the homelab use case it is happiest in.&lt;/p&gt;

</description>
      <category>linux</category>
      <category>nftables</category>
      <category>gui</category>
      <category>firewall</category>
    </item>
  </channel>
</rss>
