DiscrimiNAT Firewall - Deprecated
Chaser Systems
Price: Typical Total Price$0.291/hrTotal pricing per instance for services hosted on t3.small in US East (N. Virginia). View Details
Free TrialProduct Overview
NOTICE: This listing is now deprecated in favour of the new listing at https://aws.amazon.com/marketplace/pp/prodview-7ulmdnoq5jnwuCONSOLE INTEGRATIONThere are no new UIs to learn the config is stored in Security Groups directly, and the flow & audit logs go to CloudWatch. Because only AWS APIs are used for interfacing, you will never have to leave the AWS console or introduce new tooling.TRANSPARENT OPERATIONNo need to set http_proxy like environment variables or change any code. Everything in the VPC, from VMs to EKS, Fargate, Lambda and even zero-trust WorkSpaces, will have its egress traffic routed via DiscrimiNAT. Swapping to (and from) AWS NAT Gateway is just updating the route tables.REFINED OPERABILITYWe are an AWS Gateway Load Balancing Partner for Security Appliances and the DiscrimiNAT runs with high-availability, load-balancing & auto-scaling within your VPC. It's also completely maintenance-free!ENTERPRISE READYWhether you seek compliance with PCI DSS v4.0 or NIST SP 800-53 AC-4, SC-7 and SC-8, we've got it covered. DiscrimiNAT is hardened to CIS benchmarks, receives quarterly updates (critical OS updates in 10 days) and rolling updates apply with zero downtime.https://chasersystems.com/blog/log4shell-and-its-traces-in-a-network-egress-filter/https://chasersystems.com/solutions/daas-ztna/3.https://aws.amazon.com/elasticloadbalancing/partners/
Version: 2.7.1
By: Chaser Systems
Categories: Security
Network Infrastructure
Operating System
Linux/Unix, Ubuntu 20.04
Delivery Methods
Amazon Machine ImageCloudFormation Template
Related ProductsLibreNMS preconfigured to be ready to usevSRX Next Generation Virtual FirewallOracle Linux 9 with Support by Supported ImagesUbuntu Pro FIPS 20.04 LTS
Highlights: SPOOFING PREVENTION: Unlike AWS Network Firewall, DiscrimiNAT does conduct out-of-band DNS lookups, so TLS SNI spoofing by supply-chain malware will be logged & stopped. It even supports allowing SSH by FQDNs. The next Log4J won't slip through! LEAST PRIVILEGE EGRESS: You no longer need to apply the entire allowlist to large CIDR ranges hosting multiple applications. The policies are as granular as AWS Security Groups, so each application gets access to only what it needs. FQDN DISCOVERY: Do not know what needs allowing? With the see-thru monitor mode, egress traffic can be logged without blocking; then a CloudWatch query extracts FQDNs accessed. Watch this 3.5 min video on how easy it is: https://youtu.be/63EfQQiirZQ
Category: Infrastructure Software
Delivery Method: Amazon Machine ImageCloudFormation Template
Company Information
Company Name: Chaser Systems
About Company: The trinity of 'developer experience + security standards + operational excellence' is greater than the sum of its parts. We call it 'ergonomic cybersecurity'.