Overview

No Internet for Rogue Agents
Unlike AWS Network Firewall, DiscrimiNAT performs DNS verification, so DNS rewrites, /etc/hosts pinning, in-process resolver monkey-patching, and TLS SNI spoofing by rogue agents will be stopped.
CONSOLE INTEGRATION
There are no new UIs to learn - the config is stored in Security Groups and the Parameter Store directly, and the flow & audit logs go to CloudWatch. Use existing GitOps workflows since only AWS APIs are used for interfacing, and you will never have to leave the AWS console.
TIP: Drop us an email at devsecops@chasersystems.com to receive version-update release notes one week prior to GA. Also for a demo, best practices and architecture review.
TRANSPARENT OPERATION
No need to set http_proxy like environment variables or change any code. Everything in the VPC, from VMs to EKS, Fargate, Lambda and even zero-trust WorkSpaces [2], will have its egress traffic routed via DiscrimiNAT. We can plan a zero-downtime migration from AWS NAT Gateway for you, and you can roll back in under 1 minute if needed.
SAFE WILDCARDS
Public Suffix List [4] safeguard in place, by default, to reject wildcard patterns matching all tenants on a CSP or a CDN (aka Effective TLDs); precise patterns can also be configured with use of glob characters (*, ?).
DEVELOPER GUARD RAILS
With bidirectional enforcement of TLS 1.2+ and SSH v2, automated expiry of exemptions, dropping unencrypted Internet-bound traffic, etc., each feature has been carefully designed to avoid footguns.
REFINED OPERABILITY
We are an AWS Gateway Load Balancing Partner for Security Appliances [3] and the DiscrimiNAT runs with high-availability, load-balancing & auto-scaling within your VPC. It's also completely maintenance-free!
ENTERPRISE READY
Whether you seek compliance with PCI DSS v4.0, SOC 2 or NIST SP 800-53 AC-4, SC-7 and SC-8, we've got it covered. DiscrimiNAT is hardened to CIS Ubuntu Linux 24.04 LTS Benchmark Level 2 - Server, receives regular updates (critical OS updates in 10 days) and rolling updates apply with zero downtime.
AGENT RESOURCES
Using an AI assistant to manage or troubleshoot DiscrimiNAT OTF? Point it to our machine-readable documentation: https://chasersystems.com/llms.txt . The resource covers configuration changes, operations, log analysis, and troubleshooting.
[2] https://chasersystems.com/solutions/daas-ztna/ .
[3] https://aws.amazon.com/elasticloadbalancing/partners/ .
Highlights
- SPOOFING PREVENTION: Unlike AWS Network Firewall, DiscrimiNAT performs out-of-band DNS verification, so DNS rewrites, /etc/hosts pinning, in-process resolver monkey-patching, TLS Encrypted ClientHello (ECH), and TLS SNI spoofing by rogue agents will be logged & stopped. It even supports allowing SSH by FQDNs. The next Log4Shell [1] won't slip through! [1] https://chasersystems.com/blog/log4shell-and-its-traces-in-a-network-egress-filter/ .
- LEAST PRIVILEGE INTERNET: Avoid applying one broad allowlist to large CIDR ranges that host multiple applications. DiscrimiNAT OTF policies can be defined at the granularity of AWS Security Groups, allowing each application or workload group to access only the destinations it requires.
- FQDN DISCOVERY: Not sure which destinations an application needs to access? Use see-thru monitoring mode to observe outbound traffic without blocking it, then use a CloudWatch query to identify the FQDNs accessed. Watch the three-minute demonstration: https://youtu.be/63EfQQiirZQ .
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Vendor refund policy
There are no refunds for BYOL licensing.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
64-bit (x86) Amazon Machine Image (AMI)
Amazon Machine Image (AMI)
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
Additional details
Usage instructions
Resources
Vendor resources
Support
Vendor support
INCLUDED: Enterprise support is included in the AWS Marketplace price.
SCREEN SHARE: Contact us for hands-on help at devsecops@chasersystems.com at any stage of your deployment journey: we'll jump on a screen-sharing call right away. Use a work email address so we can provide support in the right context.
WALK-THROUGH: Why not book our 60-minute demo ? It's a 40-minute walk-through of configuring and operating DiscrimiNAT OTF, including tasks such as creating allowlists swiftly, followed by time for questions and answers. Engineers from the development, operations (SRE, DevOps, etc.) and security domains would find it useful to participate.
TIP: Drop us an email anyway to receive version-update release notes one week prior to GA. Also for a demo, best practices and architecture review.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Similar products

Customer reviews
Straightforward AWS NAT Gateway for egress filtering that doesn't have an SNI spoofing vulnerability
Good forward proxy for our egress security on Google Cloud
Secure egress solution with very straightforward rule configuration
We simply replaced our existing NAT Gateways with DiscrimiNAT, added the rules to our security groups, then checked traffic details in CloudWatch logs (AWS) or Cloud Logging (GCP).
It's particularly well suited to our organization with a large number of autonomous teams who want a simple, secure egress solution that's easy to configure, no change to application code, and no need for explicit proxy settings.
DiscrimiNAT is available via AWS and GCP Marketplaces, so it's easy to procure - as the cost is simply included in the monthly cloud provider bill.
There's a high standard of documentation with example Terraform code, and we received a prompt response to a minor technical query.