4 ms·
My parents live in Dubai and had a VPN for VoIPing, but recently the VPN stopped working. I'm terrible at networking and don't really know how all of this works
by globuous 8y ago
My parents live in Dubai and had a VPN for VoIPing, but recently the VPN stopped working. I'm terrible at networking and don't really know how all of this works, but is it possible for ISPs to block particular VPNs ?
- aaomidi 8y agoYes it is. Either just blocking the IP or using DPI.
- gnode 8y agoYes, as long as they can recognise them. It's possible to selectively reveal IPs to customers, so an attacking ISP would need the perspective of multiple users to find all VPN hosts. At an extreme, ISPs could run a whitelist instead of a blacklist (allowing connections only to approved hosts; denying by default). It's possible for services to be run on the same IPs / ports as legitimate services, forcing an ISP to choose between blocking both or none. An example of this is Telegram's use of AWS IPs, which when blocked by Russian ISPs caused disruption to other services. ( https://www.theregister.co.uk/2018/04/17/russia_blocks_google_aws_ip_addresses_to_get_telegram/ https://www.theregister.co.uk/2018/04/17/russia_blocks_googl... )
- rocgf 8y agoPerfectly possible. If it's possible for China to ban Google and for Turkey to ban Wikipedia, you can be sure that an ISP can block a VPN. :) All they have to do is bad a certain range of IP addresses that correspond to that VPN provider.
- Chardok 8y agoYes, but most paid VPNs have several different servers and ports to choose from for this very reason. Its been a while but Private Internet Access' chat support was very helpful in troubleshooting my ISP throttling my VPN connections.
- gruez 8y ago>but is it possible for ISPs to block particular VPNs ? yes, at both the network level (by blocking IP ranges belonging to VPN services) and protocol level (ie. known handshake sequences for VPN software). but both can be easily bypassed with a few google searches.
- xrisk 8y agoAccording to the OpenVPN docs, running it in static key mode makes the traffic indistinguishable from ordinary HTTPS. Regardless, my university network still manages to block it even though I use TCP mode + port 443. What gives?
- chipperyman573 8y agoDoes it block it right away? If it works for a minute or two (or ten) then cuts off they might be doing more deep heuristics, but that's usually something only governments do (ex, great firewall). They also might have just blocked the IP range of your VPN because you connected to it in a different mode before and the network just remembers that.
- gruez 8y agoAFAIK even in static key mode + TCP, it doesn't perfectly resemble a "normal" TLS connection. I think openvpn adds some custom headers to each packet or something. Something like stunnel + openvpn in TCP mode should look more similar to https.
- rblion 8y agoYup. Send them over to Pornhub.com right now and sign them up. They will love you for this notion of goodwill.