00x11
June 28, 2025, 11:08am
1
МТС, билайн, дом ру, Ростелеком, СПБ и область, ни 1 vpn протокол, даже с самымой лучшей маскировкой timeout. Работают только РФ isp с серверами за границей. Устройства тестирования самые разные… WTF? Тула, Москва, СПБ, Альтай, рыбинск, Ростов.. все молчат, всем норм?
Hentay
June 28, 2025, 11:14am
2
Уже столько тем было создано , начиная с 9 мая, что это стало буднично
И просто каждый получает доступ к тем или иным сайтам самостоятельно.
w1ryyx
June 28, 2025, 10:12pm
5
У тебя ситуация не из этого поста случаем?
открытые 07:37PM - 27 Jun 25 UTC
Russia
### Problem
A few weeks ago, a new method of blocking (especially on mobile netw… orks) was introduced in Russia by the censor.
It works as follows. So, if:
1. The client connects to the server via TCP using HTTPS and TLS 1.3 (for example, VLESS/Reality actually mimics HTTPS with TLS 1.3);
2. The IP address of the server is “suspicious” (it is located **outside** (i.e. not in Russia), is part of the subnet AS which is owned by foreign data centers like Hetzner, Digital Ocean, etc.);
3. Within one TCP connection (not within one HTTP request/response - this is important) the data size received from the server to the client is more than ≈15-20KB (the value varies depending on the provider) — the MAIN thing.
This connection is "frozen" (i.e. TCP packets from the server within this connection stop arriving after the specified limit on the size of transmitted data has been reached). It is curious to note that, as a rule, the censor (under the pretence of a response from the server) does not send, for example, an RST packet - instead, it simply “freezes” the TCP connection (from the client's point of view), and thus the client simply waits for an error on the timeout of waiting for a response from the server and everything stops working.
**IMPORTANT**: It doesn't matter whether it's "legitimate" HTTPS traffic or whether someone is mimicking it. They don't pay attention to that now.
### Notes
The good news is that if you fragment the responses from the server into several ≈15-20KB data bundles (if it is large enough) in different TCP connections, everything will work fine. It is important not to confuse this with fragmentation of TCP packets within one connection or splitting of transmitted data into several HTTP requests/responses (in **one** connection) - this is different and it won't help.
Yes, it will work noticeably slower than a single connection (especially if we're going to upload/download a large file). For example, it would take ~2560 TCP connections to download a 50MB file - that's a lot and quite suspicious.
### Related links
- https://blog.cloudflare.com/russian-internet-users-are-unable-to-access-the-open-internet/
- https://github.com/XTLS/Xray-core/pull/4835#issuecomment-2988824955
- https://github.com/XTLS/Xray-core/issues/4846
- https://ntc.party/t/09062025-%D0%B8%D0%BD%D1%84%D0%BE%D1%80%D0%BC%D0%B0%D1%86%D0%B8%D1%8F-%D0%BF%D0%BE-%D0%B1%D0%BB%D0%BE%D0%BA%D0%B8%D1%80%D0%BE%D0%B2%D0%BA%D0%B5-cloudflare-ovh-hetzner-digitalocean/17013
---
Any ideas (which would not require additional intermediate nodes)?
00x11
June 29, 2025, 5:04am
7
Завтра буду настраивать фрагментацию, чтобы узнать, но фрагметироваь на 10-15 кб, это будет адище как медленно…
00x11
June 29, 2025, 5:49am
8
У меня сейчас больше вопрос стоит, если куплю Starlink и оплачу зарубежной картой, соединится ли?
Только на границе , и то не везде, есть же карта с покрытием его, ну там вроде ещё продавали к нему машинку спуфинг , как купите - ждём обзор.
00x11
June 29, 2025, 5:54am
10
Попытка не пытка, Финляндия в 300 км, глядишь!
w1ryyx
June 29, 2025, 1:07pm
11
можешь ещё xhttp на packet-up попробовать настроить если влесску юзаешь.