ycliper

Популярное

Музыка Кино и Анимация Автомобили Животные Спорт Путешествия Игры Юмор

Интересные видео

2025 Сериалы Трейлеры Новости Как сделать Видеоуроки Diy своими руками

Топ запросов

смотреть а4 schoolboy runaway турецкий сериал смотреть мультфильмы эдисон
Скачать

DiscrimiNAT Firewall: Short Demo on AWS

egress

firewall

egress firewall

discriminat

palo alto

cloud security

egress filter

discriminat tutorial

discriminat logging

monitor outbound traffic

egress rules

aviatrix

egress filtering

squid

smokescreen

outbound filtering

outbound firewall

aws network firewall

Автор: Chaser Systems

Загружено: 2023-06-20

Просмотров: 181

Описание: Egress controls can protect against a range of Exfiltration and Command & Control TTPs. The DiscrimiNAT Firewall is a transparent, proxy-less solution to discover & filter egress traffic by FQDNs in a VPC.

It's built upon our cutting-edge technology, Wormhole DNS, that handles highly variable and load-balanced domain name resolution results perfectly well to give your applications uninterrupted access to allowed destinations.

To test your firewall for SNI spoofing detection, use the `curl` command at https://chasersystems.com/discriminat...

See the comparison with AWS Network Firewall: https://chasersystems.com/discriminat...

SPOOFING PREVENTION: Unlike AWS Network Firewall, DiscrimiNAT does conduct out-of-band DNS lookups, so TLS SNI spoofing by supply-chain malware will be logged & stopped. It even supports allowing SSH by FQDNs. The next Log4J¹ won't slip through!

LEAST PRIVILEGE EGRESS: You no longer need to apply the entire allowlist to large CIDR ranges hosting multiple applications. The policies are as granular as AWS Security Groups, so each application gets access to only what it needs.

FQDN DISCOVERY: Don't know what needs allowing? With the ‘see-thru’ monitor mode, egress traffic can be logged without blocking; then a CloudWatch query extracts FQDNs accessed. Watch this 3½ min video on how easy it is:    • Creating a whitelist on AWS for DiscrimiNA...  

CONSOLE INTEGRATION: There are no new UIs to learn – the configuration is stored in AWS Security Groups directly, and the flow & audit logs go to CloudWatch. Because only AWS APIs are used for interfacing, you will never have to leave the AWS console or introduce new tooling.

TRANSPARENT OPERATION: No need to set http_proxy like environment variables or change any code. Everything in the VPC, from VMs to EKS, Fargate, Lambda and even zero-trust WorkSpaces², will have its egress traffic routed through DiscrimiNAT. Swapping to (and from) AWS NAT Gateway is just changing the Targets in route tables.

DEVELOPER GUARD RAILS: With bidirectional enforcement of TLS 1.2+ and SSH v2, automated expiry of monitor mode exemptions, dropping unencrypted Internet-bound traffic, etc., each feature has been carefully designed so as not to inadvertently create footguns.

REFINED OPERABILITY: We are an AWS Gateway Load Balancing Partner for Security Appliances³ and the DiscrimiNAT runs with high-availability, load-balancing & auto-scaling within your VPC. It's also completely maintenance-free!

ENTERPRISE READY: Whether you seek compliance with PCI DSS v4.0 or NIST SP 800-53 AC-4, SC-7 and SC-8, we've got it covered. Also, DiscrimiNAT is hardened to CIS Ubuntu Linux 20.04 LTS Benchmark v1.1.0 Level 2 - Server. Besides the quarterly updates, critical OS updates are released in less than 10 days and rolling updates apply seamlessly.

¹ https://chasersystems.com/blog/log4sh...
² https://chasersystems.com/solutions/d...
³ https://aws.amazon.com/elasticloadbal...

Не удается загрузить Youtube-плеер. Проверьте блокировку Youtube в вашей сети.
Повторяем попытку...
DiscrimiNAT Firewall: Short Demo on AWS

Поделиться в:

Доступные форматы для скачивания:

Скачать видео

  • Информация по загрузке:

Скачать аудио

Похожие видео

© 2025 ycliper. Все права защищены.



  • Контакты
  • О нас
  • Политика конфиденциальности



Контакты для правообладателей: [email protected]