FINDING · DETECTION
Iran's DPI blocks VLESS/WS traffic routed through Cloudflare CDN in full-strict TLS mode with regularly rotated clean Cloudflare IPs, demonstrating that CDN-fronted traffic is not opaque to the censor and that IP-layer evasion (using clean CDN IPs) is insufficient when the SNI is fingerprinted.
From 2026-pooribitwise-iran-advanced-dpi — [Iran] Advanced DPI is reassembling TCP fragments to extract SNI on VLESS/WS + CDN · Description · 2026 · net4people/bbs
Implications
- CDN fronting with a stable domain name is no longer reliable against Iran; pair CDN fronting with domain rotation or ECH so the SNI seen by DPI is not the real destination.
- Do not assume Cloudflare's infrastructure provides blocking resistance by itself — the censor targets the domain name exposed in the ClientHello, not the CDN IP.
Tags
Extracted by claude-sonnet-4-6 — review before relying.