A TSG "device_group" tag configuration enumerates 30+ Ethiopian deployment sites far beyond the previously-known E21 site list, including many new city/PE (provider-edge) codes (Ambo, Nekemte, Yeka, Arada, Jijiga, Dessie, Mekele, Debre Markos, Gondar, Hawasa, Sodo, Jimma, plus GGSN nodes at Microwave/Kirkos/Nefas Silk) alongside the already-documented sites (Bole, Shashamane, Bahir Dar, Dire Dawa, Legehar, Old Airport, Nefas Silk). Two entries are explicitly labeled "Safaricom Kaliti IGW" (KLT-IGW) and "Safaricom STEP HQ IGW" (STQ-IGW), directly confirming the Safaricom Ethiopia customer identity for the E21 deployment from primary device configuration rather than inference.
"tagName": "Safaricom Kaliti IGW", "tagValue": "KLT-IGW" ... "tagName": "Safaricom STEP HQ IGW", "tagValue": "STQ-IGW" ... "tagName": "Jimma", "tagValue": "JIM-PE" ... "tagName": "Mekele", "tagValue": "MQX-PE"
Defense implications
- Nationwide-scale, multi-city IGW/PE deployment (30+ sites) implies interception/blocking coverage across essentially all major Ethiopian population centers, not just the capital -- circumvention tooling aimed at Ethiopia should not assume regional variance in censor capability.
Related findings
Ethiopia (E21) customer specifically tested Melon VPN and Ultrasurf against TSG; Ultrasurf's frequently-rotating IPs required an updated signature (successfully blocked after update), while Melon VPN's connection succeeded but was non-functional for other reasons (not attributed to TSG blocking).
Confirms the full licensed TSG component roster deployed at Ethiopia (E21): Firewall, Digital Observer, Email Retention, Statistics Policy, Proxy, Session Record, GTP Security, AppSketch, AppSketch Engine, AppSketch DB, WebSketch, WebSketch DB. Several license terms were extended to expire 2091-12-31, indicating a multi-decade commercial commitment.
Side-by-side internal performance comparison across Xinjiang (China Mobile carrier deployment, hostname cmcc-xj-server1-sapp-244), Fujian (domestic), and Ethiopia (E21) explicitly references the same 'app_sketch_maat' diagnostic log format at all three sites, confirming the identical AppSketch app-fingerprinting stack is used for domestic Xinjiang surveillance and for the exported Ethiopia deployment.
Direct dated evidence (July 2023) that the Ethiopia (E21) customer actively toggles application-level blocking as a live policy lever: lifting the block on YouTube plus four other apps caused a documented traffic surge and device alerts at the BOL-IGW site.
A certificate-issuance repo (luwenpeng/certificate, commit "TSG-8365 为TSG/Nezha界面的服务端签发证书" = "issue server-side certs for the TSG/Nezha interface") contains config, CSR, key, and crt files explicitly named "-for-e21" (ca-root-for-e21.conf, tsg-entity-for-e21.crt, nezha-entity-for-e21.key), confirming an internally-issued PKI hierarchy used for encrypted communication between TSG and its "Nezha" management-web-interface components at a site tagged E21 (Ethiopia).
A TSG device-group tag list for the Ethiopia deployment enumerates far more IGW/PE sites than previously catalogued, including Bole-IGW, Shashamane-IGW, Microwave-IGW, and Bahir Dar-IGW gateway nodes plus PE sites at Legehar, Old Airport, Nefas Silk, Ambo, Dire Dawa, Nekemte, Kirkos, Yeka, Arada, Jijiga, Dessie, Mekele, Debre Markos, Gondar, Hawasa, and Sodo, and explicitly labels two nodes 'Safaricom Kaliti IGW' and 'Safaricom STEP HQ IGW', directly tying the deployment to carrier Safaricom Ethiopia; a companion site runbook for a link migration at the Bahir Dar-IGW node shows live CLI admin sessions against hardware identified as '9000-SMBIO-P01R01-1'.