China — Great Firewall of China (GFW)#
Overview#
The Chinese GFW, also known as the Great Firewall of China, is the most sophisticated firewall in the world. It employs techniques such as injecting TCP RST packets, DNS poisoning, SNI blocking, and DPI to detect and block circumvention traffic.
What Doesn’t Work#
- Google, NYT, Twitter, etc., obviously don’t work.
- OpenVPN and WireGuard are readily detected and blocked.
- SSH tunneling is short-lived and unreliable.
- Shadowsocks is easily detected without obfuscation.
What Works#
- CDN + VMESS + WS — does work but can be technically detected.
- Hysteria 2 — effective but may be unstable.
- Any VLESS with TLS or XTLS — strong option.
- NaiveProxy — functional for basic use.
- Trojan — works but fingerprint may be identified.
Notes#
- Cloudflare CDN is sometimes slow.
- Hysteria 2 can be unstable but works.
- Some provinces have extra firewall blocking and employ a whitelist.