Current status of Iran #1961
Replies: 5 comments 10 replies
-
What is the software in "OpenVpn TCP stunnel with obfuscated & Cipher 256"? Do you mean OpenVPN + stunnel + obfs4proxy? |
Beta Was this translation helpful? Give feedback.
-
情况确实比较严重, REALITY 的 Web 面板、一键脚本、各种教程、客户端等周边支持已经非常丰富了, Xray-core 的 README/Usage/Tutorial 已添加 https://github.com/SasukeFreestyle/XTLS-Iran-Reality , |
Beta Was this translation helpful? Give feedback.
-
我比较好奇伊朗的最终目标,它是想实现完全的局域网,还是仍允许一些境外的大公司向境内的个人直接提供服务?哪些类型的服务? |
Beta Was this translation helpful? Give feedback.
-
By subdomain, do you mean vpn.example.com ? |
Beta Was this translation helpful? Give feedback.
-
Why do we need a paid ssl certificate with reality, |
Beta Was this translation helpful? Give feedback.
-
Hello there;
I felt an explanation needed to show a more clear picture of Iran restrictions situation.
I would realy like to describe or present this with scientific approach but unfortunately this option is not available, at least not yet !
Let Me describe the current status of restrictions in a compacted frame;
Almost no standard VPN protocol will work in here now despite the method you use.
Only two way in this procedure will have limited success,
OpenVpn / TCP + stunnel with obfuscated & Cipher 256
Using stunnel with Iranian providers to tunnel yourself out that have high risk to you & all people using the service & it is a proven fact !
Beside v2ray, Geph that based on sosistab protocol have shown signs of success but it's not yet competent enough option
In v2ray itself,
Shadowsocks will be blocked by approximately 24 hours
VMess may face problem with time & becomes obsolete
Vless & Trojan is the best choice now & Vless have shown to be even better
For transmission protocol, We have no choice but to use CDN & of course Cloudflare is the best option.
Due to that reason, WS & gRPC are the way to go...
From experiences, WS is more stable & gRPC is faster overall. mode option in gRPC, "gun" mode resulted in better stability in tests.
Vless Vision Reality is what We tested & Could bypass the restrictions successfully with a satisfying result
Currently, Mobile providers have tangibly more tighter restrictions
Different providers have different restrictions
Restrictions may vary in the different regions of the Nation
Overall, Reality is the only solution that most have agreed on & many are desperately waiting for the release.
◇ TLS is a must, best result from experiences is, min 1.0 1.2 in the panel & 1.3 only in the Cloudflare settings.
◇ For the Cloudflare, We also Cname the Subdomain with proxy on because many VPS IP We get are blocked from the start !
& also in general SSL settings We choose, Full or Strict (other options will not work or will result in unstable connection)
◇ Redirecting your proxied Subdomain to a well-known website have shown to be effective for delaying the blockade
◇ Using fully single port 443 have shown better results overall
~ Some users reported that they had achieved better results with a paid SSL Certificate
~ Some users reported that different Nameservers have shown to be a factor, Specially in the last days !
In the past days, one of the daily tasks of life is finding the working Cloudflare IP !
& if you find one that works, You probably still have an issue with uploading speed which is near 0 ...
Beta Was this translation helpful? Give feedback.
All reactions