MC
Group Head of Engineering
Mid-Market (51-1000 emp.)
"Straightforward AWS NAT Gateway for egress filtering that doesn't have an SNI spoofing vulnerability"
5/5
What do you like best about DiscrimiNAT Firewall?

DiscrimiNAT mitigates the SNI spoofing vulnerabilities present in solutions like Squid and AWS Network Firewall by enforcing strict FQDN checks. Its transparent operation requires no client-side configuration. The allow list rules are easy to configure. The “see-thru” operating mode helps with deployment to production networks by identifying overlooked egress traffic requirements before they get blocked. Additionally, because DiscrimiNAT functions as an inline appliance rather than a NAT gateway server, security assessors and pen testers with authenticated access cannot raise an “unrestricted outbound access” finding for that host during security audits. Review collected by and hosted on G2.com.

What do you dislike about DiscrimiNAT Firewall?

We have not encountered any drawbacks that prevented deployment. It functions as expected without adding overhead to our infrastructure. Egress traffic must be HTTPS. FQDN wildcard support is available within the inherent limits of the solution. Review collected by and hosted on G2.com.

See what 3 reviewers think of DiscrimiNAT Firewall

4.8 out of 5 · Verified reviews from real users

Read all reviews