GFW Update Report – November 2025
In the last GFW update (past ~2 weeks) we have some very interesting and bad changes:
- GFW gesture has completely changed since the last two weeks
- The main change is how DPI now reacts to TCP connections
- As we know, a TCP connection has a handshake and a keep-alive part
- Now the firewall does these gestures against every TCP connection:
→ When the connection is going to be established, it checks the SNI, matches it with the real certificate, and even reverses the IP to map it back to the domain
→ If the SNI does not match the IP in the firewall cache and whitelist → immediately timed out (RST)
→ If the SNI matches the IP, but the IP is in the gray list and the SNI is blocked → connection is dropped after a few packets
→ If the SNI is in the gray list or any trick on TLS handshake is recognized (fake SNI, weird extensions, forbidden fragments size,etc.) → active reset from firewall
The firewall also resets the whole gray IP list after a while.
This behavior is very clear on CDN V2Ray configs, Telegram calls, and any long connection that stays on the same IP range – they all die together when the gray list is wiped.(mostly happens from 6.pm to midnight)
- DoH is closed for all popular providers (Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9, etc.)
- Fragmentation above certain packet numbers is ineffective now – old fragment tricks are mostly dead and need much more time and effort
- For the UDP side the firewall also blocks the connection after a few seconds if it can find a handshake.
QUIC protocol and WireGuard took most hits from this.
If the handshake is going to be established it mostly tries not to let you do it.
In second hand it makes a profile of your connection and if it sees normal Warp checking, it immediately blocks the connection to the endpoint – so no data passes through then.
On QUIC there is the same situation: the firewall is too cautious about handshake requests to Warp ranges no matter IPv4 or IPv6. The Warp connection to these IPs is immediately interrupted.
Overall we assess the internet situation in Iran as very frustrating for users right now.
One thing we noticed: CDN IP ranges are still less restricted than normal clean IPs.
But don’t count on them and don’t put all emergency configs behind CDNs only – this is exactly their trick!
Blocking the whole Cloudflare is much easier than finding unknown ASN/VPS provider IPs, so they keep CDN half-alive on purpose and poison clean IPs much faster.
Keep your non-CDN emergency configs ready at all times.
That’s the situation today.
©Atomic
#report #iran #gfw
Post #18
3.22K
- ❤ 7
- 👍 2