2026-gohoski-russia-possible-tun
findings extracted from this paper
-
The detection event on Beeline (AS16345) exhibits a 5–15 minute delay between TUN activation and connection degradation onset, followed by a further delay before full blocking, consistent with a behavioral or statistical classifier rather than a signature-based real-time inspector. The graduated timeline (partial degradation → near-total block) suggests a threshold-based scoring system rather than an immediate signature match.
-
After the detection event triggers on Beeline (AS16345), the connection is restricted to exactly one destination: the government-approved MAX messenger (max.ru), while all other Russian domestic whitelist domains (ok.ru, vk.ru, ya.ru, mail.ru) are also blocked. This response is enforced at the ISP/TSPU level and persists until the LTE router is restarted, indicating a stateful per-subscriber penalty state rather than simple packet-level blocking.
-
On Beeline mobile internet (AS16345, Russia), enabling TUN mode with a VLESS+REALITY proxy consistently triggers ISP-level connection degradation after 5–15 minutes, while using the same proxy in HTTP/SOCKS5 proxy mode produces no such effect. The detection is reproducible across two independent GUI clients (v2rayN and Throne) with stock settings, suggesting the DPI trigger is the TUN traffic pattern rather than a client-specific artifact.
-
The reporter notes the phenomenon began several months prior to the September 2026 report and has only one corroborating data point (a Telegram message describing similar Beeline behavior), suggesting the TSPU capability is narrowly deployed — possibly in a single region or in a trial phase — rather than nationally rolled out. The reporter explicitly flags uncertainty about whether this is a TSPU experiment or a misconfiguration in their VPN client.
-
The TUN-mode detection occurs exclusively on Windows 10 and does not manifest on Android using the same VLESS+REALITY server and Beeline SIM, nor when running as a system proxy on Windows. The effect is also observed to impact all devices sharing the Windows hotspot simultaneously, ruling out endpoint-local causes and confirming the classification occurs upstream at the ISP/TSPU layer.