What level does it protect?
Application, host access, network and volumetric capacity are not equivalent.
A WAF, a firewall and a blocking tool solve different problems. The useful comparison starts from the level of protection, responsibility, data and work needed after installation.
Application, host access, network and volumetric capacity are not equivalent.
An installed license and a managed service produce different operating loads.
Local, self-hosted, appliance or cloud change responsibilities and dependencies.
Comparison matrix
Columns describe typical configurations. Specific products and suppliers can offer additional functions.
| Feature | Sentinel managed | WAF standalone | Log-based bans | WAF cloud / CDN | Traditional firewall |
|---|---|---|---|---|---|
| Main level | Application L7 + host | Application L7 | Logs and host access | Edge and L7 application | Network and transport |
| Typical location | On the server + self-hosted core | On reverse proxy/server | On the single host | Provider network | Host, appliance or network |
| WAF OWASP CRS | Included | Depends on the engine | No. | Supplier's rules | No. |
| SSH and log watchers | Included | Normally not | Central function | Normally not | Depends |
| Blocking on the host firewall | Yes | With integration | Yes | No, blocking occurs at the edge. | Yes |
| Fleet console | Integrated | Must be built or purchased | Not typical | Cloud console | Depends on the product |
| FIM and ClamAV | Available if compatible | No. | No. | No on the server | No. |
| Data and control | Self-hosted core | Local | Local | Processed by the edge provider | On premises or in an appliance |
| Tuning | Managed by G Tech Group | Managed by your team | Managed by your team | Self-service or premium service | Managed by your team/provider |
| Agent updates | Signature, checksum, canary and rollback | Process to be defined | System package | Managed by the supplier | Depends on the product |
| Application DDoS L7 | Rate-limit and challenge | Depends | No. | Often available | Limited |
| Volumetric DDoS L3/L4 | Requires upstream network | No. | No. | Often available | Limited by connectivity |
Honest Choice
If you only want to stop brute force SSH on a machine and have internal skills, a specialized tool can be sufficient and simpler.
If installation, tuning, updates, logging and incident response are already mature internal processes, an autonomous WAF engine can offer more freedom.
When geographical presence, caching and upstream volumetric capacity are needed, a cloud service can be the most suitable starting point.
For ports, protocols, VPNs and segmentation you need a network firewall. Sentinel supports it at the application and host layers, it does not replace it.
When to choose Sentinel
Sentinel is designed for those who want web and server protection in a single process, keeping the core under control and entrusting the management of the platform to an Italian team.
It's not just a filter in front of the site and it's not just an automatic ban: it's a managed platform that connects application defence, host protection and fleet visibility.
Explore the platform →Real cost
Free software or a licence, more time for installation, tuning, updates, integrations, monitoring and incident management.
The model may depend on domains, requests, bandwidth, functions or level of support. Conditions and limits change between suppliers.
Per-server subscription based on sites and traffic, with software and Sentinel technical work included according to the plan.
€49, €69 or €99 per month per server, with an annual commitment. With annual prepayment, you pay for ten monthly payments. Server, VPS and hosting purchased by G Tech Group include Sentinel within the selected service thresholds.
FAQ
It covers part of the scenario, but adds WAF, consoles, fleet, reports and management. If the only requirement is stopping brute-force attacks on one machine, a dedicated tool can suffice.
Not always. Sentinel prioritises self-hosted control and coordination with the host; the cloud is often more suitable for global edge and volumetric capacity.
No. The network firewall remains necessary for segmentation, ports and protocols; Sentinel adds application context and host blocks.
Yes. CDNs, firewalls, Sentinel and application controls can live together if headers, real IP addresses, TLS and responsibilities are configured correctly.
No. It depends on scope, skills, data, network and operating model. The evaluation is to avoid an inappropriate purchase.
Consider fee, traffic, number of servers and especially hours needed to configure, maintain and respond to events.
Describe infrastructure and priorities: we also tell you when Sentinel is not the right tool.