FINDING · DEFENSE
Community members propose a two-hop architecture as a potential mitigation for Iran's current DPI upgrade: a first-hop server inside Iran's whitelisted datacenter ranges (where outbound traffic faces lighter inspection) proxying to a foreign exit node, with Reality masquerading as a legitimate Iranian organization's domain. The architecture's effectiveness under active TCP reassembly and handshake probing is explicitly unverified.
From 2026-pooribitwise-iran-advanced-dpi — [Iran] Advanced DPI is reassembling TCP fragments to extract SNI on VLESS/WS + CDN · Issue body — Description · 2026 · net4people/bbs
Implications
- Evaluate Iran's whitelisted datacenter IP ranges as a first-hop option — traffic originating from these ranges toward foreign servers may receive reduced DPI scrutiny compared to direct client-to-foreign-server flows.
- A two-hop design isolates the user's IP from the foreign exit, but the inter-server link still requires obfuscation; Reality masquerading as a whitelisted Iranian domain does not guarantee safety given active handshake probing capabilities now deployed.
Tags
Extracted by claude-sonnet-4-6 — review before relying.