Do not choose a name. Choose the right operating model.

A WAF, a firewall and a blocking tool solve different problems. The useful comparison starts from the level of protection, responsibility, data and work needed after installation.

Comparison by categoriesLimits declaredNo universal solution
Technology

What level does it protect?

Application, host access, network and volumetric capacity are not equivalent.

Management

Who configures and maintains?

An installed license and a managed service produce different operating loads.

Control

Where do data and traffic pass?

Local, self-hosted, appliance or cloud change responsibilities and dependencies.

Comparison matrix

Five approaches, different features.

Columns describe typical configurations. Specific products and suppliers can offer additional functions.

Indicative comparison between managed Sentinel and other security categories
FeatureSentinel managedWAF standaloneLog-based bansWAF cloud / CDNTraditional firewall
Main levelApplication L7 + hostApplication L7Logs and host accessEdge and L7 applicationNetwork and transport
Typical locationOn the server + self-hosted coreOn reverse proxy/serverOn the single hostProvider networkHost, appliance or network
WAF OWASP CRSIncludedDepends on the engineNo.Supplier's rulesNo.
SSH and log watchersIncludedNormally notCentral functionNormally notDepends
Blocking on the host firewallYesWith integrationYesNo, blocking occurs at the edge.Yes
Fleet consoleIntegratedMust be built or purchasedNot typicalCloud consoleDepends on the product
FIM and ClamAVAvailable if compatibleNo.No.No on the serverNo.
Data and controlSelf-hosted coreLocalLocalProcessed by the edge providerOn premises or in an appliance
TuningManaged by G Tech GroupManaged by your teamManaged by your teamSelf-service or premium serviceManaged by your team/provider
Agent updatesSignature, checksum, canary and rollbackProcess to be definedSystem packageManaged by the supplierDepends on the product
Application DDoS L7Rate-limit and challengeDependsNo.Often availableLimited
Volumetric DDoS L3/L4Requires upstream networkNo.No.Often availableLimited by connectivity
Available or central functionVariable or addictive to integrationNot the intended function

Honest Choice

When an alternative can suffice.

Log-based bans

One server, one problem.

If you only want to stop brute force SSH on a machine and have internal skills, a specialized tool can be sufficient and simpler.

WAF standalone

You already have a team that manages it.

If installation, tuning, updates, logging and incident response are already mature internal processes, an autonomous WAF engine can offer more freedom.

WAF cloud / CDN

The priority is the global edge network.

When geographical presence, caching and upstream volumetric capacity are needed, a cloud service can be the most suitable starting point.

Traditional firewall

You need network segmentation.

For ports, protocols, VPNs and segmentation you need a network firewall. Sentinel supports it at the application and host layers, it does not replace it.

When to choose Sentinel

You want to combine technology and management.

Sentinel is designed for those who want web and server protection in a single process, keeping the core under control and entrusting the management of the platform to an Italian team.

  • Multiple layers: WAF, logs, SSH, firewall, FIM, antivirus and alert.
  • Multiple servers: status and updates coordinated by the console.
  • Data control: Self-hosted core in defined deployment.
  • Managed service: verification, installation and Sentinel management according to the plan.

Sentinel in a sentence

It's not just a filter in front of the site and it's not just an automatic ban: it's a managed platform that connects application defence, host protection and fleet visibility.

Explore the platform →

Real cost

The price of the licence does not coincide with the operating cost.

DIY solution

Free software or a licence, more time for installation, tuning, updates, integrations, monitoring and incident management.

Cloud Service

The model may depend on domains, requests, bandwidth, functions or level of support. Conditions and limits change between suppliers.

Sentinel managed

Per-server subscription based on sites and traffic, with software and Sentinel technical work included according to the plan.

€49, €69 or €99 per month per server, with an annual commitment. With annual prepayment, you pay for ten monthly payments. Server, VPS and hosting purchased by G Tech Group include Sentinel within the selected service thresholds.

FAQ

Questions before choice.

Does Sentinel replace Fail2Ban?

It covers part of the scenario, but adds WAF, consoles, fleet, reports and management. If the only requirement is stopping brute-force attacks on one machine, a dedicated tool can suffice.

Does it replace a WAF cloud?

Not always. Sentinel prioritises self-hosted control and coordination with the host; the cloud is often more suitable for global edge and volumetric capacity.

Does it replace the firewall?

No. The network firewall remains necessary for segmentation, ports and protocols; Sentinel adds application context and host blocks.

Can I use more solutions together?

Yes. CDNs, firewalls, Sentinel and application controls can live together if headers, real IP addresses, TLS and responsibilities are configured correctly.

Is Sentinel always the best choice?

No. It depends on scope, skills, data, network and operating model. The evaluation is to avoid an inappropriate purchase.

How do I compare costs?

Consider fee, traffic, number of servers and especially hours needed to configure, maintain and respond to events.

Let's compare your scenario, not a brochure.

Describe infrastructure and priorities: we also tell you when Sentinel is not the right tool.