4 ms·
Been doing wireguard over udp 443 for a long time. Works pretty consistently. Probably take a few years for the low-effort network blocks to figure out how to
by netflixandkill 5y ago
Been doing wireguard over udp 443 for a long time. Works pretty consistently.
Probably take a few years for the low-effort network blocks to figure out how to deal with that.
- lxgr 5y agoInteresting, I wonder if this is because of low effort firewall rules (just mirror the TCP settings for UDP) or explicitly to allow QUIC.
- netflixandkill 5y agoQuic has been around long enough that I suspect it's simply a common policy for both tcp and udp on 443. If you just want to charge for access, rate limiting is easier and there is almost never any local person involved in managing it. A lot of VPN blocking isn't a specific, deliberate policy choice by the network owner, it comes in from default policy options on whatever awful vendor they use. The people seriously concerned about outgoing tunnels providing access back into protected networks that hides from normal packet inspection are a different case.
- adamfisk 5y agoWireguard traffic is easy to identify and therefore easy to block.
- bawolff 5y agoBut typically coffee shops aren't really putting much effort into blocking vpns, they're doing some silly block everything not 80 or 443. Its not like they're trying to bypass the great firewall of china.
- midasuni 5y agoIt’s possible that QUiC will mean in some places udp/443 will be blocked but other udp won’t be.