Listing Thumbnail

    DiscrimiNAT OTF

     Info
    Deployed on AWS
    Free Trial
    DiscrimiNAT OTF (Outbound Traffic Filtering) is a transparent, proxy-less NAT Gateway alternative to discover & filter egress traffic by domains, without breaking existing applications.
    4.8

    Overview

    Play video

    CONSOLE INTEGRATION

    There are no new UIs to learn - the config is stored in Security Groups and the Parameter Store directly, and the flow & audit logs go to CloudWatch. Use existing GitOps workflows since only AWS APIs are used for interfacing, and you will never have to leave the AWS console.

    TIP: Drop us an email at devsecops@chasersystems.com  to receive version-update release notes one week prior to GA. Also for a demo, best practices and architecture review.

    TRANSPARENT OPERATION

    No need to set http_proxy like environment variables or change any code. Everything in the VPC, from VMs to EKS, Fargate, Lambda and even zero-trust WorkSpaces [2], will have its egress traffic routed via DiscrimiNAT. We can plan a zero-downtime migration from AWS NAT Gateway for you, and you can roll back in under 1 minute if needed.

    SAFE WILDCARDS

    Public Suffix List [4] safeguard in place, by default, to reject wildcard patterns matching all tenants on a CSP or a CDN (aka Effective TLDs); precise patterns can also be configured with use of glob characters (*, ?).

    DEVELOPER GUARD RAILS

    With bidirectional enforcement of TLS 1.2+ and SSH v2, automated expiry of exemptions, dropping unencrypted Internet-bound traffic, etc., each feature has been carefully designed to avoid footguns.

    REFINED OPERABILITY

    We are an AWS Gateway Load Balancing Partner for Security Appliances [3] and the DiscrimiNAT runs with high-availability, load-balancing & auto-scaling within your VPC. It's also completely maintenance-free!

    ENTERPRISE READY

    Whether you seek compliance with PCI DSS v4.0, SOC 2 or NIST SP 800-53 AC-4, SC-7 and SC-8, we've got it covered. DiscrimiNAT is hardened to CIS Ubuntu Linux 24.04 LTS Benchmark Level 2 - Server, receives regular updates (critical OS updates in 10 days) and rolling updates apply with zero downtime.

    AGENT RESOURCES

    Using an AI assistant to manage or troubleshoot DiscrimiNAT OTF? Point it to our machine-readable documentation: https://chasersystems.com/llms.txt  . The resource covers configuration changes, operations, log analysis, and troubleshooting.

    [2] https://chasersystems.com/solutions/daas-ztna/  .

    [3] https://aws.amazon.com/elasticloadbalancing/partners/  .

    [4] https://publicsuffix.org/  .

    Highlights

    • SPOOFING PREVENTION: Unlike AWS Network Firewall, DiscrimiNAT performs out-of-band DNS verification, so DNS rewrites, /etc/hosts pinning, in-process resolver monkey-patching, TLS Encrypted ClientHello (ECH), and TLS SNI spoofing by rogue agents will be logged & stopped. It even supports allowing SSH by FQDNs. The next Log4Shell [1] won't slip through! [1] https://chasersystems.com/blog/log4shell-and-its-traces-in-a-network-egress-filter/ .
    • LEAST PRIVILEGE INTERNET: Avoid applying one broad allowlist to large CIDR ranges that host multiple applications. DiscrimiNAT OTF policies can be defined at the granularity of AWS Security Groups, allowing each application or workload group to access only the destinations it requires.
    • FQDN DISCOVERY: Not sure which destinations an application needs to access? Use see-thru monitoring mode to observe outbound traffic without blocking it, then use a CloudWatch query to identify the FQDNs accessed. Watch the three-minute demonstration: https://youtu.be/63EfQQiirZQ .

    Details

    Delivery method

    Delivery option
    64-bit (x86) Amazon Machine Image (AMI)

    Latest version

    Operating system
    Ubuntu 24.04

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Free trial

    Try this product free for 31 days according to the free trial terms set by the vendor. Usage-based pricing is in effect for usage beyond the free trial terms. Your free trial gets automatically converted to a paid subscription when the trial ends, but may be canceled any time before that.

    DiscrimiNAT OTF

     Info
    Pricing is based on actual usage, with charges varying according to how much you consume. Subscriptions have no end date and may be canceled any time. Alternatively, you can pay upfront for a contract, which typically covers your anticipated usage for the contract duration. Any usage beyond contract will incur additional usage-based costs.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Usage costs (5)

     Info
    Dimension
    Cost/hour
    t3.small
    Recommended
    $0.27
    c6a.large
    $0.27
    c6a.xlarge
    $0.27
    c6i.xlarge
    $0.27
    c6i.large
    $0.27

    AI Insights

     Info

    Dimensions summary

    You pay by the hour for each running DiscrimiNAT instance, billed to the nearest whole hour. The five options are AWS instance types, not feature tiers, so pricing reflects the compute size you choose. The t3.small suits light to medium usage and small allowlists. The c6a.large, c6i.large, c6a.xlarge, and c6i.xlarge give dedicated CPU cores for steady throughput or accounts with many protected instances. Each instance needs at least 2 vCPU and 2 GiB RAM. You pay for as many instances as you run. AWS infrastructure and data transfer costs are separate.

    Top-of-mind questions for buyers

    Each running DiscrimiNAT gateway instance counts as one billable unit. The software fee applies per instance per hour, rounded up to the nearest whole hour. If you run instances across multiple Availability Zones for high availability, you pay the hourly rate for each one.
    The software fee meters running time only. Usage is rounded up to the nearest whole hour per active instance. A stopped instance does not accrue the DiscrimiNAT hourly charge, though separate AWS infrastructure costs may still apply while resources exist.
    No. The hourly rate covers the DiscrimiNAT software only. There are no per-GB data processing charges. AWS infrastructure costs, such as the EC2 instance itself and EC2-to-Internet data transfer, are separate. DiscrimiNAT replaces your NAT Gateways, so you avoid running both.
    chasersystems.com+2
    Helpful?

    Vendor refund policy

    You may terminate the EC2 instance(s) at any time to stop incurring charges. Email devsecops@chasersystems.com  for questions on billing.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    64-bit (x86) Amazon Machine Image (AMI)

    Amazon Machine Image (AMI)

    An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.

    Support

    Vendor support

    INCLUDED: Enterprise support is included in the AWS Marketplace price.

    SCREEN SHARE: Contact us for hands-on help at devsecops@chasersystems.com  at any stage of your deployment journey: we'll jump on a screen-sharing call right away. Use a work email address so we can provide support in the right context.

    WALK-THROUGH: Why not book our 60-minute demo ? It's a 40-minute walk-through of configuring and operating DiscrimiNAT OTF, including tasks such as creating allowlists swiftly, followed by time for questions and answers. Engineers from the development, operations (SRE, DevOps, etc.) and security domains would find it useful to participate.

    TIP: Drop us an email anyway to receive version-update release notes one week prior to GA. Also for a demo, best practices and architecture review.

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Product comparison

     Info
    Updated weekly

    Accolades

     Info
    Top
    10
    In Security Observability
    Top
    10
    In Network Infrastructure

    Customer reviews

     Info
    Sentiment is AI generated from actual customer reviews on AWS and G2
    Reviews
    Functionality
    Ease of use
    Customer service
    Cost effectiveness
    3 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    0 reviews
    Insufficient data
    Insufficient data
    Insufficient data
    Insufficient data
    Positive reviews
    Mixed reviews
    Negative reviews

    Overview

     Info
    AI generated from product descriptions
    DNS Spoofing Prevention
    Out-of-band DNS lookups to detect and block TLS SNI spoofing attempts and prevent supply-chain malware from establishing unauthorized connections
    FQDN-Based Traffic Filtering
    Egress traffic filtering by Fully Qualified Domain Names with support for glob character patterns and Public Suffix List safeguards to prevent overly broad wildcard rules
    Encryption Enforcement
    Bidirectional enforcement of TLS 1.2+ and SSH v2 protocols with automatic dropping of unencrypted Internet-bound traffic
    High Availability and Auto-Scaling
    Gateway Load Balancing integration for security appliances with built-in high-availability, load-balancing, and auto-scaling capabilities within VPC
    Native AWS Integration
    Configuration stored in Security Groups and Parameter Store with flow and audit logs sent to CloudWatch, using only AWS APIs for interface operations
    Application Layer Visibility and Control
    Complete application layer-7 visibility and control of traffic with next-generation firewall capabilities in AWS environments
    AI/ML-Powered Threat Detection
    AI/ML-powered inspection engine with researcher-grade signatures for detection of zero-day threats, exploits, malware, spyware, and command and control attacks
    Dynamic Policy Management
    Policy definitions that dynamically apply to cloud assets based on AWS tags, Application IDs, User IDs, geographies, or zones without manual intervention
    Cloud Infrastructure Integration
    Seamless integration with Gateway Load Balancer, AWS Auto Scaling, and Transit VPC with AWS Transit Gateway for protection across dynamic and large-scale deployments
    Advanced Threat Prevention Service
    Cloud-delivered Advanced Threat Prevention security service with market-leading threat coverage against known and zero-day threats while maintaining performance
    Static IP Proxy Service
    Route inbound and outbound traffic through load-balanced pairs of static IP addresses via proxied connections for third-party IP whitelisting and secure access to protected resources.
    Protocol Support
    HTTP and SOCKS5 proxy protocols available with SSL support and custom domain configuration.
    High Availability Infrastructure
    Health monitoring, load-balancing, and automated failover mechanisms across proxy cluster to ensure continuous service availability.
    Multi-Region Deployment
    Proxy infrastructure deployed across 8 AWS regions with ability to select specific regional endpoints for optimized latency.
    Real-Time Monitoring and Analytics
    Dashboard-based tracking of requests and usage metrics with real-time visibility into traffic patterns and account activity.

    Contract

     Info
    Standard contract
    No

    Customer reviews

    Ratings and reviews

     Info
    4.8
    3 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    100%
    0%
    0%
    0%
    0%
    0 AWS reviews
    |
    3 external reviews
    External reviews are from G2 .
    Matt C.

    Straightforward AWS NAT Gateway for egress filtering that doesn't have an SNI spoofing vulnerability

    Reviewed on Mar 05, 2026
    Review provided by G2
    What do you like best about the product?
    DiscrimiNAT mitigates the SNI spoofing vulnerabilities present in solutions like Squid and AWS Network Firewall by enforcing strict FQDN checks. Its transparent operation requires no client-side configuration. The allow list rules are easy to configure. The “see-thru” operating mode helps with deployment to production networks by identifying overlooked egress traffic requirements before they get blocked. Additionally, because DiscrimiNAT functions as an inline appliance rather than a NAT gateway server, security assessors and pen testers with authenticated access cannot raise an “unrestricted outbound access” finding for that host during security audits.
    What do you dislike about the product?
    We have not encountered any drawbacks that prevented deployment. It functions as expected without adding overhead to our infrastructure. Egress traffic must be HTTPS. FQDN wildcard support is available within the inherent limits of the solution.
    What problems is the product solving and how is that benefiting you?
    We needed to restrict outbound AWS cloud traffic to prevent data exfiltration. Previously we used a Squid web proxy and Linux firewall as the NAT gateway to do this. We replaced it with DiscrimiNAT to prevent our egress rules from being bypassed via SNI spoofing, to address a potential security vulnerability. This provides verifiable egress control, which satisfies our security and compliance requirements.
    Manufacturing

    Good forward proxy for our egress security on Google Cloud

    Reviewed on Feb 20, 2025
    Review provided by G2
    What do you like best about the product?
    We like the fact that DiscrimiNAT is doing FQDN filtering on SNI while being a transparent proxy, that it integrates with native firewall rules on GCP and that it's really fast and performant. We deploy it with the Terraform module and it's maintenance-free for us. In addition, we always had really fast feedback and help from the Team anytime we reached out for advice / feedback. Price is also good.
    What do you dislike about the product?
    We don't have any issues as of now. In the past, the lack of wildcards was a downside, but it's now fully supported.
    What problems is the product solving and how is that benefiting you?
    We have a security requirement to filter egress traffic from our Cloud infrastructure. DiscrimiNAT makes that easy and integrates well.
    Paul S.

    Secure egress solution with very straightforward rule configuration

    Reviewed on Nov 18, 2021
    Review provided by G2
    What do you like best about the product?
    We really like the speed and simplicity of deployment using Terraform with the vendor-supplied modules, no need for console access, and authorization determined by security group rule descriptions. We initially used the "see-thru" mode to determine existing outbound traffic without enforcement.

    We simply replaced our existing NAT Gateways with DiscrimiNAT, added the rules to our security groups, then checked traffic details in CloudWatch logs (AWS) or Cloud Logging (GCP).

    It's particularly well suited to our organization with a large number of autonomous teams who want a simple, secure egress solution that's easy to configure, no change to application code, and no need for explicit proxy settings.

    DiscrimiNAT is available via AWS and GCP Marketplaces, so it's easy to procure - as the cost is simply included in the monthly cloud provider bill.

    There's a high standard of documentation with example Terraform code, and we received a prompt response to a minor technical query.
    What do you dislike about the product?
    One downside of DiscrimiNAT is that it can't filter on URL path - for example, you can't block all of github.com except for github.com/mycompany. However, implementing that level of control would require an SSL interception solution which isn't suitable for us, due to the need to install the proxy certificate chain as trusted in our server operating systems and applications.
    What problems is the product solving and how is that benefiting you?
    DiscrimiNAT provides controlled egress to authorized domains from cloud computing environments in AWS and GCP, using TLS and SSH. It significantly reduces the risk of data exfiltration, malware, and command and control using reverse shell attacks.
    View all reviews