Hacker News new | ask | show | jobs
by kccqzy 73 days ago
That’s usually done not on the network side but through the device itself. Think MDM and endpoint management.
1 comments

A good solution is tackling it on both. At work we have network level firewalls with separate policies for internal and guest networks, and our managed PCs sync a filter policy as well (through primarily for when those devices are not on our network). The network level is more efficient, easier to manage and troubleshoot, and works on appliances, rogue hardware, and other things that happen not to have client management.
Well, if you have MDM you should be able to just disable ECH.
This is also indeed done on both. Browser policies.