Tell HN: Russia has started blocking OpenVPN/WireGuard connections

Russia is increasingly blocking OpenVPN, WireGuard and other VPN protocols, likely using deep packet inspection and IP blacklists, in a move that resembles China’s Great Firewall. Commenters report patchy, ISP-dependent enforcement inside Russia and occupied territories, plus collateral effects such as throttling or blocking of entire ASNs that limit access to foreign research and services. Much of the conversation centers on technical workarounds—obfuscated VPNs, proxy protocols like Shadowsocks, V2Ray/XRay, Snowflake, and domain-fronted HTTPS—as well as the broader implications for censorship, propaganda, and citizens’ ability to access information from abroad.

Reports of Blocking & Variability

  • Some users in Russia and Russia-controlled areas report WireGuard totally blocked and OpenVPN heavily or selectively blocked (often depending on ISP, region, server, and time).
  • Others say self‑hosted WireGuard/OpenVPN still work, especially when servers also run non‑VPN services and don’t look like “obvious VPN nodes.”
  • Several note OpenVPN or IKEv2 stopped working months ago, often with connections reset, suggesting a rolling, ISP‑by‑ISP or region‑by‑region rollout.
  • Access to specific foreign services and entire ASNs is also being blocked from both sides (Russian censors and Western services/sanctions).

Technical Mechanisms Discussed

  • Many assume deep packet inspection (DPI) plus IP / ASN blacklisting, with inspiration or help from China’s Great Firewall.
  • WireGuard is said to be fingerprintable because of its packet structure, despite PSK mode; OpenVPN is “TLS‑like” but still easy to detect unless further wrapped.
  • Some speculate on simple whitelisting (allow mostly HTTPS/TCP) and traffic‑pattern analysis (packet entropy, statistics, high‑volume overseas flows).

Workarounds and Tools

  • Suggested tools/protocols: obfsproxy, stunnel‑wrapped OpenVPN, Shadowsocks, v2ray/XRay (XTLS‑Reality), Hysteria, Outline, AmneziaWG (obfuscated WireGuard), wstunnel, Snowflake, Psiphon, and remote browser isolation (e.g., SquareX).
  • Strategies include: custom/obfuscated protocols over HTTPS/WebSocket, domain fronting (where still possible), using CDNs, running other services on the same VPS, and rotating foreign VPSs (sometimes paid via crypto or foreign bank accounts).

Legal and Practical Risks

  • In Russia, using a VPN itself is reported as not clearly illegal, but using it for certain content is risky; enforcement is seen as selective and politically driven.
  • In China, VPN use is common, but selling VPN services is heavily punished; enforcement is similarly discretionary.

Broader Political and Social Context

  • Blocking is framed as part of tightening censorship, especially ahead of Russian “elections” and amid protests and war.
  • Some fear a switch to a largely isolated “Russian internet,” though others argue full cutoff would be too costly and instead expect a slow, annoying, majority‑control model.