FINDING · DETECTION
WireGuard connections are blackholed by Iranian infrastructure immediately after the initial WireGuard handshake completes — clients stop receiving server packets — indicating the Iranian DPI identifies WireGuard by its distinct UDP handshake pattern and applies IP-level blocking at that point.
From 2026-pooribitwise-iran-advanced-dpi — [Iran] Advanced DPI is reassembling TCP fragments to extract SNI on VLESS/WS + CDN · Issue body — Other Observations §3 · 2026 · net4people/bbs
Implications
- Plain WireGuard is not viable in Iran; tool designers must use AmneziaWG or equivalent obfuscated WireGuard that alters the handshake byte pattern before deployment
- The immediate-post-handshake blocking window is the critical detection moment; obfuscation must cover at minimum the first two handshake messages
Tags
Extracted by claude-sonnet-4-6 — review before relying.