MC
Matt C.
Group Head of Engineering
Mid-Market (51-1000 emp.)
"Straightforward AWS NAT Gateway for egress filtering that doesn't have an SNI spoofing vulnerability"
5/5
What do you like best about DiscrimiNAT Firewall?

DiscrimiNAT mitigates the SNI spoofing vulnerabilities present in solutions like Squid and AWS Network Firewall by enforcing strict FQDN checks. Its transparent operation requires no client-side configuration. The allow list rules are easy to configure. The “see-thru” operating mode helps with deployment to production networks by identifying overlooked egress traffic requirements before they get blocked. Additionally, because DiscrimiNAT functions as an inline appliance rather than a NAT gateway server, security assessors and pen testers with authenticated access cannot raise an “unrestricted outbound access” finding for that host during security audits. Review collected by and hosted on G2.com.

What do you dislike about DiscrimiNAT Firewall?

We have not encountered any drawbacks that prevented deployment. It functions as expected without adding overhead to our infrastructure. Egress traffic must be HTTPS. FQDN wildcard support is available within the inherent limits of the solution. Review collected by and hosted on G2.com.

Verified User in Manufacturing
AM
Verified User in Manufacturing
Enterprise (> 1000 emp.)
"Good forward proxy for our egress security on Google Cloud"
4.5/5
What do you like best about DiscrimiNAT Firewall?

We like the fact that DiscrimiNAT is doing FQDN filtering on SNI while being a transparent proxy, that it integrates with native firewall rules on GCP and that it's really fast and performant. We deploy it with the Terraform module and it's maintenance-free for us. In addition, we always had really fast feedback and help from the Team anytime we reached out for advice / feedback. Price is also good. Review collected by and hosted on G2.com.

What do you dislike about DiscrimiNAT Firewall?

We don't have any issues as of now. In the past, the lack of wildcards was a downside, but it's now fully supported. Review collected by and hosted on G2.com.

Paul S.
PS
Paul S.
Cloud Security Engineer
Enterprise (> 1000 emp.)
"Secure egress solution with very straightforward rule configuration"
5/5
What do you like best about DiscrimiNAT Firewall?

We really like the speed and simplicity of deployment using Terraform with the vendor-supplied modules, no need for console access, and authorization determined by security group rule descriptions. We initially used the "see-thru" mode to determine existing outbound traffic without enforcement.

We simply replaced our existing NAT Gateways with DiscrimiNAT, added the rules to our security groups, then checked traffic details in CloudWatch logs (AWS) or Cloud Logging (GCP).

It's particularly well suited to our organization with a large number of autonomous teams who want a simple, secure egress solution that's easy to configure, no change to application code, and no need for explicit proxy settings.

DiscrimiNAT is available via AWS and GCP Marketplaces, so it's easy to procure - as the cost is simply included in the monthly cloud provider bill.

There's a high standard of documentation with example Terraform code, and we received a prompt response to a minor technical query. Review collected by and hosted on G2.com.

What do you dislike about DiscrimiNAT Firewall?

One downside of DiscrimiNAT is that it can't filter on URL path - for example, you can't block all of github.com except for github.com/mycompany. However, implementing that level of control would require an SSL interception solution which isn't suitable for us, due to the need to install the proxy certificate chain as trusted in our server operating systems and applications. Review collected by and hosted on G2.com.

There are not enough reviews of DiscrimiNAT Firewall for G2 to provide buying insight. Below are some alternatives with more reviews:

1
Check Point Next Generation Firewalls (NGFWs) Logo
Check Point Next Generation Firewalls (NGFWs)
4.5
(593)
Check Point Firewall. The Check Point Firewall Software Blade incorporates all of the power and capability of the revolutionary FireWall-1 solution while adding user identity awareness to provide granular event awareness and policy enforcement.
2
Sophos Firewall Logo
Sophos Firewall
4.7
(869)
Ultimate enterprise firewall performance, security, and control.
3
SolarWinds Observability Logo
SolarWinds Observability
4.3
(863)
SolarWinds® Observability is a comprehensive full-stack observability solution designed to meet the diverse needs of modern organizations, regardless of their size. This solution provides deep visibility into hybrid ecosystems, enabling users to monitor and manage both on-premises and cloud environments effectively. By optimizing performance and ensuring availability across distributed hybrid IT infrastructures, SolarWinds Observability supports organizations in navigating the complexities of their IT environments. Targeted at IT professionals and organizations that require robust monitoring capabilities, SolarWinds Observability caters to a wide range of use cases. It is particularly beneficial for businesses operating in hybrid environments, where the integration of on-premises and cloud resources is essential. The solution allows users to gain a holistic view of their networks, applications, databases, and user experiences, thereby facilitating better decision-making and operational efficiency. This is especially crucial in today’s fast-paced digital landscape, where downtime can significantly impact service reliability and customer satisfaction. One of the standout features of SolarWinds Observability is its built-in intelligence powered by AIOps capabilities. This functionality accelerates issue remediation by enabling users to detect, troubleshoot, and resolve problems more efficiently. The advanced predictive analysis and anomaly-based alerts help organizations proactively address potential issues before they escalate, ultimately reducing downtime and enhancing service reliability. Additionally, the solution's log pattern analysis further streamlines the troubleshooting process, allowing IT teams to focus on strategic initiatives rather than being bogged down by operational challenges. SolarWinds Observability offers flexibility in deployment, providing users with the option to choose between self-hosted and SaaS models. The self-hosted option integrates seamlessly with other SolarWinds services, such as security and storage monitoring, while the SaaS option is tailored for deeper monitoring of custom and cloud-based applications. This adaptability ensures that organizations can select the deployment method that best aligns with their operational needs and infrastructure. Moreover, SolarWinds Observability stands out by consolidating multiple monitoring tools into a single, integrated solution. This not only simplifies the monitoring process but also helps organizations reduce costs associated with managing disparate systems. By offering comprehensive visibility across hybrid IT environments, SolarWinds Observability empowers organizations to optimize their operations and enhance overall performance.
4
Datadog Logo
Datadog
4.4
(726)
Datadog is a monitoring service for IT, Dev and Ops teams who write and run applications at scale, and want to turn the massive amounts of data produced by their apps, tools and services into actionable insight.
5
ThreatLocker Zero Trust Platform Logo
ThreatLocker Zero Trust Platform
4.8
(514)
Get unprecedented visibility and control of your cybersecurity, quickly, easily, and cost-effectively. Schedule a free product demonstration and ThreatLocker will show you how.
6
Progress WhatsUp Gold Logo
Progress WhatsUp Gold
4.4
(391)
WhatsUp Gold is unified infrastructure and application monitoring software that gives modern IT teams the ability to monitor their increasingly complex IT environment with a single product.
7
Coralogix Logo
Coralogix
4.6
(343)
Coralogix is a stateful streaming data platform that provides real-time insights and long-term trend analysis with no reliance on storage or indexing, solving the monitoring challenges of data growth in large scale systems.
8
IBM QRadar SIEM Logo
IBM QRadar SIEM
4.4
(338)
IBM QRadar is designed to collect logs, events, network flows and user behavior across your entire enterprise, correlates that against threat intelligence and vulnerability data to detect known threats, and applies advanced analytics to identify anomalies that may signal unknown threats. The solution then uniquely connects the end-to-end chain of activity associated with a single potential incident, and provides prioritized alerts based on severity, helping quickly uncover critical threats while reducing false positives.
9
Netgate pfSense Logo
Netgate pfSense
4.7
(326)
The Netgate pfSense project is a powerful open source firewall and routing platform based on @FreeBSD.
10
Check Point Cloud Firewall (formerly CloudGuard Network Security) Logo
Check Point Cloud Firewall (formerly CloudGuard Network Security)
4.4
(294)
Check Point CloudGuard Network Security for private and public cloud platforms is designed to protect assets in the cloud against the most sophisticated threats.
Show More