new IR-GFW behaviour - Target : XRAY #3407
Replies: 8 comments 4 replies
-
I have this problem too! screen-20240531-002821.2.mp4 |
Beta Was this translation helpful? Give feedback.
-
it's not surprising that vless without tls is being blocked, more surprising however that there is a difference between clients. the pcap for both sing-box-client and xray-client with regard to vless+ws+notls is completely identical. i checked it on a config yesterday that was allegedly blocked. if you have a config where one client is blocked and another one isn't, i suggest to capture the connection attempt/urltest with wireshark and upload the pcap here. also i suggest to try replacing ws with httpupgrade, and vless with vmess, to see if it makes a difference. |
Beta Was this translation helpful? Give feedback.
-
I have the same experience. Only affected xray-core clients. (freshly installed both clients without any custom settings) |
Beta Was this translation helpful? Give feedback.
-
i agree with you mehrad and this is most be fix |
Beta Was this translation helpful? Give feedback.
-
Same issue with tls+ws and fragment in Android. |
Beta Was this translation helpful? Give feedback.
-
I captured packets and attached the file here |
Beta Was this translation helpful? Give feedback.
-
XRAY clients where WebSocket connections are being throttled or blocked due to |
Beta Was this translation helpful? Give feedback.
-
Today the restriction removed temporarily, so i repeated the packet capture at the time when Xray was working fine. |
Beta Was this translation helpful? Give feedback.
-
Recently, the IR-GFW has implemented a new type of censorship using DP. They are specifically targeting WebSocket (no-tls) connections established by XRAY clients. Yes, you read that correctly—XRAY clients. While standard WebSocket (no-tls) connections remain unaffected, those made through XRAY are being throttled and limited, resulting in a poor network experience. In contrast, the same connections made using Sing-box clients do not encounter any issues.
This DPI strategy was introduced in response to the growing use of Cloudflare CDN to circumvent censorship measures. The selective throttling of XRAY client connections indicates a new scary level of DPI in GFW
Currently the only ISP implementing this type of DPI is IR-MCI which is also a leading ISP in inspecting and filtering REALITY connections.
Beta Was this translation helpful? Give feedback.
All reactions