4 ms·
We have. We are an egress firewall company and have been testing our product on Graviton2, privately, for some time now. The ARM builds will be GA in a couple o
by new23d 6y ago
We have. We are an egress firewall company and have been testing our product on Graviton2, privately, for some time now. The ARM builds will be GA in a couple of months but so far we've concluded that:
1. These offer an excellent price to performance ratio for an egress firewall like purpose because of low instance pricing and high network throughput.
2. For our stack written in C and Rust, any performance penalty isn't noticeable. It's basically a NAT gateway filtering by hostnames for TLS & SSH outbound.
- jcims 6y agoInteresting point solution. Do you just license through the AWS Marketplace? Any issues with encrypted SNI?
- new23d 6y agoYes, just through AWS and GCP marketplaces. ESNI (now Encrypted Client Hello: https://tools.ietf.org/html/draft-ietf-tls-esni-08 https://tools.ietf.org/html/draft-ietf-tls-esni-08) is still in draft. v1 of the firewall that is currently published ignores the extension but will deny in case SNI is absent. v2, due in a couple of weeks, will actively seek presence of any of ECH extensions and deny them. This is to prevent domain-fronting style of exfiltration attempts. We expect HTTP Clients in the enterprise to not have moved over to ECH any time soon. However, the firewall has a lot of checks and balances built-in to mitigate this in the future when it arrives.
- jcims 6y agoVery cool! Thanks for the details. Totally agree on lag time for rolling out ECH.
- new23d 6y agoThank you! Should you be interested in the v2 preview, drop us an email (from your work email) or follow our LinkedIn page.
- oars 6y agoHad a look at your website and it seems like a fantastic product. Regarding V1 of your product that ignores the encrypted SNI (ESNI) extension, do you mean it just allows all traffic using ESNI? If so, have you considered blocking malicious domains via DNS instead?
- deleted 6y ago[deleted]
- new23d 6y agoSeveral defence-in-depth checks including DNS and protocol legitimacy are carried out in v1, so no it wouldn't just allow ESNI through. Happy to invite you to the v2 preview if you drop us an email (from your work email) or follow our LinkedIn page.