Internal site codename "E21" is confirmed as the Ethiopia TSG deployment — IGW node names in a traffic report match Ethiopian cities (Bahir Dar, Dire Dawa) alongside other coded node names (BOL, MWV), giving a reusable search key for the rest of the leak corpus.
BOL-IGW:链路1... Bahir Dar-IGW:链路1... MWV_IGW:链路1...链路2... Dire Dawa-IGW:链路1...
Defense implications
- 'E21' is a reusable search key for pulling every Ethiopia-specific record out of the rest of the leak.
Related findings
Ethiopia (E21) customer specifically tested Melon VPN and Ultrasurf against TSG; Ultrasurf's frequently-rotating IPs required an updated signature (successfully blocked after update), while Melon VPN's connection succeeded but was non-functional for other reasons (not attributed to TSG blocking).
Confirms the full licensed TSG component roster deployed at Ethiopia (E21): Firewall, Digital Observer, Email Retention, Statistics Policy, Proxy, Session Record, GTP Security, AppSketch, AppSketch Engine, AppSketch DB, WebSketch, WebSketch DB. Several license terms were extended to expire 2091-12-31, indicating a multi-decade commercial commitment.
Side-by-side internal performance comparison across Xinjiang (China Mobile carrier deployment, hostname cmcc-xj-server1-sapp-244), Fujian (domestic), and Ethiopia (E21) explicitly references the same 'app_sketch_maat' diagnostic log format at all three sites, confirming the identical AppSketch app-fingerprinting stack is used for domestic Xinjiang surveillance and for the exported Ethiopia deployment.
Direct dated evidence (July 2023) that the Ethiopia (E21) customer actively toggles application-level blocking as a live policy lever: lifting the block on YouTube plus four other apps caused a documented traffic surge and device alerts at the BOL-IGW site.
TSG's blocking of YouTube/Facebook/Twitter/Tencent at Ethiopia's IGW nodes fails for a large fraction of sessions because those sessions structurally never traverse the inspection point — quantified per-site traffic-completeness rates ranged from 0% to 40% (vs. ~100% completeness at the upstream PE node), with roughly half of sampled YouTube/Facebook sessions missing entirely from IGW-side logs. Root cause was traffic-splitting/mirroring architecture, not a detection failure of the DPI engine itself.
Ethiopia's INSA (Information Network Security Agency, the state cybersecurity/intelligence body) is named as the end-customer/oversight authority for the E21 TSG deployment — Geedge staff prepared formal incident reports specifically for INSA leadership after operators publicly complained about failed YouTube/Twitter blocking.