TGViewer
Void Verge Void Verge @voidverge · 14K subscribers
Post #18 3.22K
GFW Update Report – November 2025


In the last GFW update (past ~2 weeks) we have some very interesting and bad changes:

- GFW gesture has completely changed since the last two weeks
- The main change is how DPI now reacts to TCP connections
- As we know, a TCP connection has a handshake and a keep-alive part
- Now the firewall does these gestures against every TCP connection:

→ When the connection is going to be established, it checks the SNI, matches it with the real certificate, and even reverses the IP to map it back to the domain

→ If the SNI does not match the IP in the firewall cache and whitelist → immediately timed out (RST)
→ If the SNI matches the IP, but the IP is in the gray list and the SNI is blocked → connection is dropped after a few packets
→ If the SNI is in the gray list or any trick on TLS handshake is recognized (fake SNI, weird extensions, forbidden fragments size,etc.) → active reset from firewall

The firewall also resets the whole gray IP list after a while.
This behavior is very clear on CDN V2Ray configs, Telegram calls, and any long connection that stays on the same IP range – they all die together when the gray list is wiped.(mostly happens from 6.pm to midnight)

- DoH is closed for all popular providers (Cloudflare 1.1.1.1, Google 8.8.8.8, Quad9, etc.)
- Fragmentation above certain packet numbers is ineffective now – old fragment tricks are mostly dead and need much more time and effort

- For the UDP side the firewall also blocks the connection after a few seconds if it can find a handshake.
QUIC protocol and WireGuard took most hits from this.
If the handshake is going to be established it mostly tries not to let you do it.
In second hand it makes a profile of your connection and if it sees normal Warp checking, it immediately blocks the connection to the endpoint – so no data passes through then.
On QUIC there is the same situation: the firewall is too cautious about handshake requests to Warp ranges no matter IPv4 or IPv6. The Warp connection to these IPs is immediately interrupted.

Overall we assess the internet situation in Iran as very frustrating for users right now.

One thing we noticed: CDN IP ranges are still less restricted than normal clean IPs.
But don’t count on them and don’t put all emergency configs behind CDNs only – this is exactly their trick!
Blocking the whole Cloudflare is much easier than finding unknown ASN/VPS provider IPs, so they keep CDN half-alive on purpose and poison clean IPs much faster.

Keep your non-CDN emergency configs ready at all times.
That’s the situation today.

©Atomic
#report #iran #gfw
  • ❤ 7
  • 👍 2
More from @voidverge
  1. Jun 1, 2026Since Iran's internet was reopened by the government, extensive changes have been taking p…
  2. Apr 16, 2026document post
  3. Apr 16, 2026As we suspected, the Iranian government has begun rolling out internet whitelisting in a g…
  4. Apr 1, 2026document post
  5. Apr 1, 2026Another draft paper we found suggests that Iran is planning to control third-party applica…
  6. Mar 28, 2026document post
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →