Ethiopia (E21) project completion/acceptance documentation was routed through an intermediary named 长城网际 ('Great Wall Cyber' or similar transliteration), which then delivered it onward to an entity referred to only as '进出口' -- plausibly a state export-import financing bank given the Belt-and-Road financing pattern gfw.report and others have already reported for this customer, but this ticket alone doesn't establish that identification with certainty.
目前需要提供相关资料,给长城网际然后再交给进出口的。执行合同完毕的验收材料。
Related findings
Ethiopia (E21) customer specifically tested Melon VPN and Ultrasurf against TSG; Ultrasurf's frequently-rotating IPs required an updated signature (successfully blocked after update), while Melon VPN's connection succeeded but was non-functional for other reasons (not attributed to TSG blocking).
Confirms the full licensed TSG component roster deployed at Ethiopia (E21): Firewall, Digital Observer, Email Retention, Statistics Policy, Proxy, Session Record, GTP Security, AppSketch, AppSketch Engine, AppSketch DB, WebSketch, WebSketch DB. Several license terms were extended to expire 2091-12-31, indicating a multi-decade commercial commitment.
Side-by-side internal performance comparison across Xinjiang (China Mobile carrier deployment, hostname cmcc-xj-server1-sapp-244), Fujian (domestic), and Ethiopia (E21) explicitly references the same 'app_sketch_maat' diagnostic log format at all three sites, confirming the identical AppSketch app-fingerprinting stack is used for domestic Xinjiang surveillance and for the exported Ethiopia deployment.
Direct dated evidence (July 2023) that the Ethiopia (E21) customer actively toggles application-level blocking as a live policy lever: lifting the block on YouTube plus four other apps caused a documented traffic surge and device alerts at the BOL-IGW site.
TSG's blocking of YouTube/Facebook/Twitter/Tencent at Ethiopia's IGW nodes fails for a large fraction of sessions because those sessions structurally never traverse the inspection point — quantified per-site traffic-completeness rates ranged from 0% to 40% (vs. ~100% completeness at the upstream PE node), with roughly half of sampled YouTube/Facebook sessions missing entirely from IGW-side logs. Root cause was traffic-splitting/mirroring architecture, not a detection failure of the DPI engine itself.
Ethiopia's INSA (Information Network Security Agency, the state cybersecurity/intelligence body) is named as the end-customer/oversight authority for the E21 TSG deployment — Geedge staff prepared formal incident reports specifically for INSA leadership after operators publicly complained about failed YouTube/Twitter blocking.