2026-lunarcanvas-swift-look-into
findings extracted from this paper
-
Iran's source-IP allowlist severely restricted outbound access before the May 26, 2026 partial restoration: only ~0.017% (~2,000 of 11,766,454 spoofed Iranian IPs) could reach destinations outside Iran. After restoration, reachable IPs increased nearly fourfold to ~0.07% (~8,000), with most newly reachable addresses originating from Noyan Abr Arvan Co. (ASN 202468), indicating expansion rather than removal of the allowlist.
-
Before the May 26 restoration, Iran's inbound allowlist granted near-full access (100%) to university ASes (e.g., Shahid Beheshti University AS56765, Iran University of Medical Sciences AS47981) while major residential ISPs had <2% pass rates, demonstrating that the Iranian allowlist enforces differentiated access by institution type rather than a uniform policy. Additionally, roughly half of allowlisted IPs experienced no SNI filtering at all, while the other half faced domain-specific RSTs, suggesting non-uniform application-layer policies even among privileged addresses.
-
Inbound access to Iran remains heavily restricted even after the May 26 restoration: only ~2.8% of tested global /24 blocks (~400,000 of 14,461,944 representative IPs) could reach the Iran vantage point, compared to over 70% for comparable hosts outside Iran — more than 25× lower reachability — demonstrating that Iran enforces allowlist-based destination-IP filtering on inbound traffic as well as outbound.
-
Unlike the Great Firewall of China, Iran's SNI-triggered blocking produces no residual interference: after a TCP RST caused by a sensitive SNI, subsequent connections from the same source IP using benign or randomly generated SNIs proceed normally without additional disruption. This behavior was observed consistently before and after the May 26, 2026 partial restoration.
-
Iran layers SNI-based domain blocking on top of its IP allowlist: even source IPs permitted by the allowlist trigger TCP RSTs when a TLS ClientHello contains a sensitive SNI value. Randomly generated, non-existent domain names pass through without triggering resets, confirming the blocking operates as a domain-name blocklist rather than a generic TLS fingerprinting rule. Blocking behavior was highly consistent, with 97.4% of (source IP, SNI) pairs producing identical outcomes across three test repetitions.
-
Iran's SNI filtering is applied inconsistently across allowlisted users: among 737 tested allowlisted IP addresses, approximately half experienced no SNI filtering at all and could reach destinations even using previously-reported blocked domains. For IPs subject to filtering, 49.9% of requests containing hrw.org and 50.2% containing tiktok.com triggered RSTs, while only 0.5% of requests with youtube.com were blocked — suggesting differential access policies tied to specific domains and user classes even within the allowlisted population.