Ethiopia
TSG export customer, Belt-and-Road framework.
also: ET
Ethiopia (E21) customer specifically tested Melon VPN and Ultrasurf against TSG; Ultrasurf's frequently-rotating IPs required an updated signature (successfully blocked after update), while Melon VPN's connection succeeded but was non-functional for other reasons (not attributed to TSG blocking).
Confirms the full licensed TSG component roster deployed at Ethiopia (E21): Firewall, Digital Observer, Email Retention, Statistics Policy, Proxy, Session Record, GTP Security, AppSketch, AppSketch Engine, AppSketch DB, WebSketch, WebSketch DB. Several license terms were extended to expire 2091-12-31, indicating a multi-decade commercial commitment.
Side-by-side internal performance comparison across Xinjiang (China Mobile carrier deployment, hostname cmcc-xj-server1-sapp-244), Fujian (domestic), and Ethiopia (E21) explicitly references the same 'app_sketch_maat' diagnostic log format at all three sites, confirming the identical AppSketch app-fingerprinting stack is used for domestic Xinjiang surveillance and for the exported Ethiopia deployment.
Direct dated evidence (July 2023) that the Ethiopia (E21) customer actively toggles application-level blocking as a live policy lever: lifting the block on YouTube plus four other apps caused a documented traffic surge and device alerts at the BOL-IGW site.
TSG's blocking of YouTube/Facebook/Twitter/Tencent at Ethiopia's IGW nodes fails for a large fraction of sessions because those sessions structurally never traverse the inspection point — quantified per-site traffic-completeness rates ranged from 0% to 40% (vs. ~100% completeness at the upstream PE node), with roughly half of sampled YouTube/Facebook sessions missing entirely from IGW-side logs. Root cause was traffic-splitting/mirroring architecture, not a detection failure of the DPI engine itself.
Ethiopia's INSA (Information Network Security Agency, the state cybersecurity/intelligence body) is named as the end-customer/oversight authority for the E21 TSG deployment — Geedge staff prepared formal incident reports specifically for INSA leadership after operators publicly complained about failed YouTube/Twitter blocking.
Under peak traffic (~700K logs/sec vs. normal ~450K/sec), Ethiopia's TSG deployment's log-aggregation pipeline (Kafka/Flink) dropped roughly 30% of session logs due to load imbalance across nodes, meaning session visibility during traffic peaks is measurably incomplete, independent of the detection engine's accuracy.
A certificate-issuance repo (luwenpeng/certificate, commit "TSG-8365 为TSG/Nezha界面的服务端签发证书" = "issue server-side certs for the TSG/Nezha interface") contains config, CSR, key, and crt files explicitly named "-for-e21" (ca-root-for-e21.conf, tsg-entity-for-e21.crt, nezha-entity-for-e21.key), confirming an internally-issued PKI hierarchy used for encrypted communication between TSG and its "Nezha" management-web-interface components at a site tagged E21 (Ethiopia).
A TSG "device_group" tag configuration enumerates 30+ Ethiopian deployment sites far beyond the previously-known E21 site list, including many new city/PE (provider-edge) codes (Ambo, Nekemte, Yeka, Arada, Jijiga, Dessie, Mekele, Debre Markos, Gondar, Hawasa, Sodo, Jimma, plus GGSN nodes at Microwave/Kirkos/Nefas Silk) alongside the already-documented sites (Bole, Shashamane, Bahir Dar, Dire Dawa, Legehar, Old Airport, Nefas Silk). Two entries are explicitly labeled "Safaricom Kaliti IGW" (KLT-IGW) and "Safaricom STEP HQ IGW" (STQ-IGW), directly confirming the Safaricom Ethiopia customer identity for the E21 deployment from primary device configuration rather than inference.
A TSG device-group tag list for the Ethiopia deployment enumerates far more IGW/PE sites than previously catalogued, including Bole-IGW, Shashamane-IGW, Microwave-IGW, and Bahir Dar-IGW gateway nodes plus PE sites at Legehar, Old Airport, Nefas Silk, Ambo, Dire Dawa, Nekemte, Kirkos, Yeka, Arada, Jijiga, Dessie, Mekele, Debre Markos, Gondar, Hawasa, and Sodo, and explicitly labels two nodes 'Safaricom Kaliti IGW' and 'Safaricom STEP HQ IGW', directly tying the deployment to carrier Safaricom Ethiopia; a companion site runbook for a link migration at the Bahir Dar-IGW node shows live CLI admin sessions against hardware identified as '9000-SMBIO-P01R01-1'.
The gap_tsg_api QA repo includes commits submitting an Android install package and Android/iOS test scripts for an app labeled "E21VPN" -- E21 being the established internal site codename for the Ethiopia TSG deployment -- indicating Ethiopia-specific VPN-app test targets were built into the same automated policy-validation pipeline used for TSG's general app-blocking QA (which in the same commit already covered ExpressVPN, HotspotShield, NordVPN, Surfshark, ProtonVPN, iTopVPN).
Geedge Networks' 2023 new-hire onboarding deck gives a corporate timeline: TSG's first international market win (with a codename "Nezha" launching the same month) in September 2018, "网络叙事者" (CyberNarrator) launching November 2020, a "South Asia" country project landing August 2021 (overseas market expansion), and Geedge winning a bid as overall solution provider for an "East Africa" country project in May 2022 — timing and regions consistent with this corpus's existing Pakistan (WMS-UTR/P19) and Ethiopia (E21) site attributions, though the deck itself does not name the countries.
Geedge's internal company timeline dates the launch of 网络叙事者 (CyberNarrator) to November 2020, and states the company won a 'South Asian country' project in May 2021 (consistent with Pakistan/WMS-UTR) and, as overall solution provider, an 'East Africa country' project in May 2022 (consistent with Ethiopia/HDM) -- corroborating the export timeline for those two customers from the company's own materials rather than site-side evidence alone.
The SSL plugin's own test corpus includes a pcap explicitly labeled for the E21 (Ethiopia) deployment -- test/pcap/e21/1-E21-target.com-196.188.136.150-151.101.2.187.443.pcap with a matching ssl_e21_target_result.json -- showing the TLS-parsing/JA3/ECH code is validated against real captured traffic from the Ethiopia site, tying this specific detection engine directly to the already-established E21 export deployment.
TSG's QUIC-parsing layer decrypts QUIC ClientHello payloads and parses a user-agent-like parameter from the decrypted content, deployed at the Ethiopia (E21) DIR-IGW site. A missing bounds check on this field caused a watchdog-timeout crash, confirmed via a MESA_Platform/quic GitLab commit (git.mesalab.cn/MESA_Platform/quic).
TSG's Psiphon3 blocking (Ethiopia/E21 site) uses a dynamically-learned "Top SNI" / "Top Server IP" allowlist meant to avoid collaterally blocking shared infrastructure Psiphon3 also rides on (e.g. Google); a bug in the learning pipeline (SNI values under 3 bytes rolled back the whole DB write transaction) let the allowlist silently go stale, causing Google traffic to be misidentified and blocked as Psiphon3.
Internal site codename "E21" is confirmed as the Ethiopia TSG deployment — IGW node names in a traffic report match Ethiopian cities (Bahir Dar, Dire Dawa) alongside other coded node names (BOL, MWV), giving a reusable search key for the rest of the leak corpus.
Ethiopia customer (E21/E-site) explicitly requested TSG blocking be extended beyond the baseline (Psiphon 3) to a named list of commercial VPNs: Freegate, CyberGhost, Torguard, NordVPN, IPVanish, VPN Unlimited, ExpressVPN, Surfshark, Windscribe, Hotspot Shield, Ivacy, Atlas VPN, PureVPN, ProtonVPN, Norton Secure VPN. Engineering confirmed delivery of NordVPN and Hotspot Shield signatures with successful field tests.
TSG deployments include an inline optical-bypass failsafe (光保) that, on link/health failure, can leave the segment in bypass (fail-open passthrough) mode rather than reverting to inline inspection — a 2023 incident at E21 (MSH-TSGX-02, 120Gbps) had a bypass segment stuck open until manually tuned.
TSG integrates a licensed third-party DPI engine (versioned separately from TSG/App Sketch DB releases) that repeatedly segfaulted across many E21 (Ethiopia) NPB nodes over Oct-Dec 2023 when processing specific packet-encapsulation stacks (Ethernet->MPLS->IPv4->UDP, VLAN->IPv4->UDP), requiring an App Sketch DB version bump to resolve.
Confirms the full Ethiopia (E21) deployment site list — Bole, Shashamane, Bahir Dar, Safaricom Kaliti, Safaricom STEP HQ, Dire Dawa, Legehar, Old Airport, Microwave, Nefas Silk, Kirkos — explicitly including Safaricom Ethiopia (the mobile carrier) sites, with aggregate session-log throughput nearly doubling from 728,000/s to 1,383,000/s between March and July 2024.
Ethiopia (E21) project completion/acceptance documentation was routed through an intermediary named 长城网际 ('Great Wall Cyber' or similar transliteration), which then delivered it onward to an entity referred to only as '进出口' -- plausibly a state export-import financing bank given the Belt-and-Road financing pattern gfw.report and others have already reported for this customer, but this ticket alone doesn't establish that identification with certainty.
Project "E21" is conclusively Ethiopia: names IGW sites by city -- MWV-IGW, BOLE-IGW (Bole, the Addis Ababa airport district), Shashamane-IGW, Bahir Dar-IGW, Dire Dawa-IGW, Legehar -- each with a distinct IP block, indicating a national multi-city topology.
Root-caused an Ethiopia SNI-block-failure incident to the detection mechanism itself: APP_SKETCH's FQDN-scanning module -- which exists specifically to identify Psiphon3 and Freegate via top-N SNI matching -- was CPU-expensive enough to saturate cores, triggering sapp's fail-open DDoS bypass and letting some target connections through uninspected. A signature-structure fix roughly doubled throughput (33K/s to 73K/s new connections) and disabling the fail-open bypass restored reliable blocking.
Project "E21" tested SNI-FQDN-wildcard block policies against international news/media/academic domains -- opride.com (Oromo news), ethiotube.net, Reuters, NYT, Bloomberg, GitHub, ResearchGate, NIH.gov -- from an Ethio-Telecom-range office IP. Most blocks silently failed (shared root cause with OMPUB-466); britannica.com needed a separate deny-quic policy since QUIC bypassed SNI blocking.
Multi-week TSG engineering investigation of iTOP VPN (requested by an Ethiopia deployment, cross-tested in a Myanmar environment) found blocking only takes effect for VPN sessions established AFTER a detection policy is pushed; a VPN already connected before the policy loads is never blocked or logged, regardless of signature type (SNI or server-IP).
TSG engineers explicitly acknowledged to an Ethiopia customer that the system's application-identification statistics over-count Psiphon3 and Freegate due to misidentification, inflating their apparent traffic share (e.g. Psiphon3 appearing in the application Top-2 despite the customer reporting no active blocking of it), and that Netflix's ranking also varies drastically by sort metric (bytes vs. sessions vs. unique client IP).
A known Psiphon3 relay IP, already in the signature set, wasn't blocked because it used destination port 179 (BGP): TSG's switch/distribution board bypassed port-179 traffic without forwarding it to the compute board for inspection at all (confirmed at the E21/Ethiopia site). A separate domain-whitelist mechanism can also override deny actions. Fixed by routing port-179 to compute.
At export site "E21" (naming consistent with Ethiopia elsewhere in this batch), Traffic Logs run across 13 servers with 40TB disk each (520TB total); Session Records consume ~7TB/day and Security Events ~1.5TB/day, giving a rough sense of logged traffic volume.
Multi-engineer forensic investigation (pcap, JA3 hashing, TSG session-log correlation) at an Ethiopia site into tv.cctv.com being intermittently unreachable concluded the blocking was NOT done by TSG itself but by a separate, more-client-proximate network censorship system. That system dropped ClientHello-stage TLS1.2 sessions matching cctv.com's SNI, had degraded filtering ability once the client renegotiated to TLS1.3, and at one point misclassified cctv.com traffic as TikTok.
TSG's Psiphon3 signature is a multi-stage stateful match (IP, then protocol/SNI, then a negative/NOT condition) where the NOT condition is only evaluated once, explicitly at the 8th packet of a session. Sessions carrying fewer than 8 packets never reach that evaluation point and are never flagged as Psiphon, regardless of actual protocol. Confirmed in production (E21) as the root cause of a customer-reported partial bypass.
At export site "E21," TSG has a named detection object "Psiphon-Server-Signature"/"Psiphon-Server-APP"; two near-identical sessions to the same Psiphon-associated IP (82.223.55.87) over SSH/port 22 were logged, but only one was correctly tagged — a session-to-session consistency gap in the signature match.
A debugging ticket for sites "Old Airport-PE" and "Bole-IGW" (naming consistent with Addis Ababa, Ethiopia) confirms the customer verified Psiphon3, YouTube, Facebook, and Telegram blocking as working well during independent testing, and reveals the operational session-correlation method used when packet captures and system logs must be cross-referenced across NAT: JA3_HASH + server IP + client public IP + SSL SNI.
The galaxy/deployment/online-config repo — the central field/site configuration store — maintains per-customer git branches named E21 (Ethiopia), P19 and P19-POC (Pakistan), and XJ (Xinjiang), each tracking dated "现场配置" (field configuration) commits pinned to specific TSG software versions (e.g. TSG 22.02, 21.11), directly corroborating the E21/P19/XJ site codenames already established in taxonomy and confirming ongoing, versioned field deployments as recently as 2023-07 (a "P19 23.07 online-config" branch commit).
Internal project codenames decode to specific customers: M22 = Myanmar (operators Mytel, Ooredoo Myanmar, and ATOM; sites YGN=Yangon, MDY=Mandalay), K18 = Kazakhstan (site renamed Nur-Sultan to Astana in OLAP config), E21 = Ethiopia (operator Safaricom Ethiopia; sites ADAMA-PE/SSM-PE to KLT-IGW/SHQ-IGW), WMS-UTR = Pakistan.
On the E21 (Ethiopia/Safaricom) deployment, TSG blocked Psiphon3 via ~1.69M known server IPs; in one ~3.5hr window, 76,496 unique client IPs still attempted Psiphon3, which accounted for 14% of total bandwidth, 5.96% of sessions, and 1.32% of unique client IPs despite the active Deny policy.
MESA Lab's "stellar" SSL/TLS decoder (ssl_decoder, packaged in test fixtures as "stellar-on-sapp") ships a dedicated regression test case captured against an Ethiopia (E21) target host, alongside TLS 1.3 ESNI, encrypted ClientHello (ECH), and TachyonVPN-client test pcaps, showing the decoder is validated both against E21-deployment-style traffic and emerging TLS privacy extensions.