FINDING · DETECTION

After a GFW ESNI block is triggered, residual censorship persists for 120–180 seconds (varying by vantage point), blocking all traffic on the same (srcIP, dstIP, dstPort) 3-tuple. Additional ESNI handshakes sent during the residual window do not reset the timer, and it takes at least 1 second for the GFW to enable blocking rules after the triggering packet.

From 2020-gfw-esni-blockingExposing and Circumventing China's Censorship of ESNI · Residual Censorship · 2020 · gfw.report

Implications

Tags

censors
cn
techniques
esni-eh-blocking

Extracted by claude-sonnet-4-6 — review before relying.