<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>PARC Network — Managed Hosting Architecture for your Magento / Mage-OS shop! on Managed Magento Hosting — by shop owners, for shop owners</title><link>https://www.parc-network.com/</link><description>Recent content in PARC Network — Managed Hosting Architecture for your Magento / Mage-OS shop! on Managed Magento Hosting — by shop owners, for shop owners</description><generator>Hugo</generator><language>en-GB</language><atom:link href="https://www.parc-network.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Firewall for Magento — network hardening with OPNsense</title><link>https://www.parc-network.com/magento-firewall/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.com/magento-firewall/</guid><description>&lt;p class="lead"&gt;While the &lt;a href="https://www.parc-network.com/magento-waf/"&gt;WAF&lt;/a&gt; inspects HTTP traffic at the application layer, the firewall works one level deeper: it decides at the network level which traffic is allowed to flow at all. At PARC, OPNsense handles this.&lt;/p&gt;
&lt;h2 id="network-firewall-vs-waf"&gt;Network firewall vs. WAF&lt;/h2&gt;
&lt;p&gt;The two layers complement each other but don’t replace each other:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;WAF (SafeLine)&lt;/strong&gt; — Layer 7, understands HTTP, blocks injection, XSS, bots.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Firewall (OPNsense)&lt;/strong&gt; — Layer 3/4, filters packets by source, destination, port and protocol. What isn&amp;rsquo;t let through here never reaches the higher layers in the first place.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="why-opnsense"&gt;Why OPNsense&lt;/h2&gt;
&lt;p&gt;OPNsense is an open-source firewall built on FreeBSD — fitting seamlessly into our line:&lt;/p&gt;</description></item><item><title>Legal Notice</title><link>https://www.parc-network.com/legal-notice/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.com/legal-notice/</guid><description>&lt;p&gt;
&lt;strong&gt;PARC Network GmbH &amp;amp; Co. KG&lt;/strong&gt;&lt;br&gt;
Am Weidengraben 27&lt;br&gt;
97297 Waldbüttelbrunn, Germany
&lt;/p&gt;
&lt;p&gt;
Phone: &lt;a href="tel:+4993197091331"&gt;+49 (0) 931 / 970 913 31&lt;/a&gt;&lt;br&gt;
Email: &lt;a href="mailto:hallo@parc-network.com"&gt;hallo@parc-network.com&lt;/a&gt;
&lt;/p&gt;
&lt;p&gt;
Register court: Würzburg Local Court (AG Würzburg)&lt;br&gt;
Registration number: HRA 7122
&lt;/p&gt;
&lt;p&gt;
VAT identification number according to § 27a German VAT Act (UStG): DE292075424
&lt;/p&gt;
&lt;p&gt;
&lt;strong&gt;Notice according to § 36 VSBG (Consumer Dispute Resolution Act):&lt;/strong&gt; We are neither willing nor obliged to participate in dispute resolution proceedings before a consumer arbitration board.
&lt;/p&gt;</description></item><item><title>PARC Security — open-source module for Magento protection</title><link>https://www.parc-network.com/parc-security/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.com/parc-security/</guid><description>&lt;p class="lead"&gt;PARC Security is our own open-source module. It complements the &lt;a href="https://www.parc-network.com/magento-waf/"&gt;WAF&lt;/a&gt; and the &lt;a href="https://www.parc-network.com/magento-firewall/"&gt;firewall&lt;/a&gt; with a Magento-aware layer: curated blacklists, IP groups and rules that keep known attackers, bots and scrapers out — right in the context of the shop.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://github.com/ParcNetwork" target="_blank" rel="noopener noreferrer" class="btn btn-secondary"&gt;View the module on GitHub&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="what-the-module-does"&gt;What the module does&lt;/h2&gt;
&lt;p&gt;PARC Security sits between the pure network/WAF layer and the Magento application. While WAF and firewall work generically, PARC Security knows the Magento context — which routes are sensitive, which bots are legitimate (e.g. Google) and which aren’t.&lt;/p&gt;</description></item><item><title>Privacy Policy</title><link>https://www.parc-network.com/privacy-policy/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.com/privacy-policy/</guid><description>&lt;p&gt;As the data controller under the GDPR, we inform you below about the processing of personal data when visiting this website.&lt;/p&gt;
&lt;nav class="toc" aria-label="Table of contents"&gt;
&lt;strong&gt;Contents&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#controller"&gt;1. Data Controller&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#purposes"&gt;2. Purposes of Processing and Legal Bases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#processing"&gt;3. Processing in Detail&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#recipients"&gt;4. Recipients and Third-Country Transfer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#storage"&gt;5. Storage Period&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rights"&gt;6. Your Rights&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#objection"&gt;7. Right to Object (Art. 21 GDPR)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#security"&gt;8. Data Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/nav&gt;
&lt;h2 id="controller" style="margin-top: 32px;"&gt;1. Data Controller&lt;/h2&gt;
&lt;p&gt;The controller responsible for the processing of personal data is &lt;strong&gt;PARC Network GmbH &amp;amp; Co. KG&lt;/strong&gt;. You can find the name and contact details of the controller in our &lt;a href="https://www.parc-network.com/legal-notice/"&gt;Legal Notice&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>WAF for Magento — SafeLine as the Web Application Firewall</title><link>https://www.parc-network.com/magento-waf/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://www.parc-network.com/magento-waf/</guid><description>&lt;p class="lead"&gt;A Web Application Firewall (WAF) filters HTTP traffic before it ever reaches Magento. At PARC, SafeLine handles this — the first active line of defence in front of every shop, even before Varnish and Nginx.&lt;/p&gt;
&lt;h2 id="what-a-waf-does--and-what-it-doesnt"&gt;What a WAF does — and what it doesn’t&lt;/h2&gt;
&lt;p&gt;A WAF operates at the application layer (Layer 7). It understands HTTP requests and detects attack patterns a classic network firewall can’t see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;SQL injection&lt;/strong&gt; and &lt;strong&gt;cross-site scripting (XSS)&lt;/strong&gt; in forms, URL parameters and headers&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Known Magento exploits&lt;/strong&gt; — many attacks target specific, patched CVEs. The WAF blocks the attack patterns even if a patch is occasionally applied with delay&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Credential stuffing &amp; brute force&lt;/strong&gt; on login and admin routes&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Bad bots &amp; scrapers&lt;/strong&gt; that harvest catalog data or generate load&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;To be honest: a WAF is &lt;strong&gt;not a replacement for patches&lt;/strong&gt;. It’s an additional layer that buys time and absorbs broad attack waves — the actual vulnerabilities still need patching.&lt;/p&gt;</description></item></channel></rss>