# Russia VPN Bypass State — April 2026

**Time-bound note.** This is a snapshot from late April 2026, synthesized from ntc.party community discussions and public statements by circumvention tool maintainers (Amnezia, Xray). The blocking landscape changes on a weekly basis — if you're reading this and the dates in `created` / `updated` are more than two or three months old, verify against a current source ([ntc.party](https://ntc.party/)) before acting on it.

The headline finding: **protocol choice matters less than where your exit IP lives.** The dominant filter in 2026 is TSPU's CIDR whitelist applied to mobile carriers, with SNI filtering and VLESS-Reality statistical fingerprinting layered on top. A poorly-configured VLESS+Reality on a Hetzner IP dies faster than a well-configured AmneziaWG 2.0 on a whitelisted Russian CIDR.

## The three filters to beat

1. **CIDR whitelist** — applied at IP-routing layer, mostly on mobile carriers (Megafon, Beeline, MTS, T2, Yota). Connections to non-whitelisted subnets (Hetzner, DigitalOcean, OVH, Cloudflare ranges) get dropped or throttled. Bypass: endpoint IP inside a whitelisted Russian-hoster subnet. See [[whitelist-internet-blocking]].
2. **SNI whitelist** — DPI inspects the TLS ClientHello's SNI and drops unknown hostnames. Bypass: outer SNI is a whitelisted domain (`max.ru`, `sun6-21.userapi.com`, etc.) — Reality, ShadowTLS, and domain-fronting-style tricks all attack this layer.
3. **Statistical fingerprinting** — traffic-pattern analysis of TLS handshakes, first-packet entropy, flow timing. Catches plain VLESS-Reality-over-TCP, old Shadowsocks, plain WireGuard. Bypass: transport layers that look like ordinary web traffic (XHTTP, HTTP/2, HTTP/3) and padding/mux on raw streams.

## VLESS-based methods

**Working:**

- **VLESS + Reality + XHTTP** — the new default since late 2025. XHTTP looks like ordinary HTTP/2 or HTTP/3 traffic, so it survives the statistical fingerprinting that now catches plain Reality-over-TCP in some regions.
- **VLESS + Reality + XHTTP + "steal oneself"** — serve your own real domain with its own cert at 443, fall back to nginx for non-proxy traffic. Survives active probing because the server *is* the claimed site.
- **VLESS on whitelisted SNI + whitelisted CIDR** — the [[vpn-configs-for-russia]] subscription files ship exactly this combination. The hard part is the CIDR: personal VPSes on OVH/Hetzner/DO get dropped even with a perfect SNI.
- **Cascade through RU VPS → foreign VPS** — first hop on a whitelisted Russian subnet, second hop is the real foreign exit. Throughput hit is large (~80% reported, 500→90 Mbps), but it sidesteps the CIDR filter.

**Degraded / dropping:**

- VLESS + Reality + Vision over plain TCP on non-whitelisted CIDRs — intermittent drops across mobile operators in Povolzhye, St. Petersburg, Yekaterinburg.
- VLESS + gRPC + nginx — reported full collapse on some connections April 10-11 2026, requiring server reboots for brief recovery.
- WebSocket without Reality — detectable via statistical analysis; only useful behind a CDN.

## Non-VLESS methods

### Tier 1 — Actively working

- **AmneziaWG 2.0** — dominant in the WireGuard-family slot. TSPU's February 13 2026 crackdown blocked WireGuard, OpenVPN, and old AmneziaWG; AmneziaWG 2.0 and Xray survived. The v2.0 rewrite added packet-shaping and handshake obfuscation beyond the original junk-packet design. Amnezia founder Mazay Banzaev has said RKN periodically pokes at it but hasn't broken it.
- **Trojan + TLS** — works with a real cert on a non-suspicious CIDR. TLS-over-TLS fingerprint is the weakness; needs the same CIDR/SNI discipline as VLESS-Reality.
- **NaiveProxy** — HTTP/2-over-TLS disguised as Chrome traffic, using real Chromium for the handshake so the fingerprint genuinely matches. Niche on ntc.party but consistently recommended for users who don't want Xray.
- **Hysteria2 / TUIC** — QUIC-based, look like HTTP/3. Work on home fiber, flaky on mobile because TSPU's summer 2025 crackdown on unidentified UDP hit QUIC hard. Port 443/UDP mandatory, obfs padding essential.

### Tier 2 — Situational

- **Shadowsocks (SS-2022)** — old Shadowsocks is dead from RF since summer 2025 (personal SS servers and paid SS VPNs failing simultaneously, with reachable HTTP/SSH on the same host). SS-2022 slightly better but first-packet entropy is still recognizable. Usable only when tunneled inside something else (SS-over-WebSocket-over-TLS, SS-over-v2ray-plugin with a real cert).
- **Outline** — same situation, since Outline *is* Shadowsocks.
- **Cloak / ShadowTLS v3 / ShadowQUIC** — use a legitimate website's TLS cert during the initial handshake. Work on the right CIDR with a whitelisted SNI, subject to the same CIDR-whitelist ceiling.

### Tier 3 — Dead or dying

- **Plain WireGuard** — February 16 2026, vdsina hosting saw a WG block rollout based on the initial handshake. The punishment escalated: previously only the UDP port receiving the handshake got blocked, now all UDP ports above 1000 on the endpoint get blocked. UDP/53 and low ports still work on some operators as a janky workaround.
- **OpenVPN** — fully blocked everywhere that matters; handshake fingerprint is textbook DPI material.
- **VMess** — technically "still works" but community has abandoned it; known statistical fingerprints, nothing it offers over VLESS+Reality.
- **MTProto / FakeTLS (Telegram)** — multiple ntc.party reports of midday Moscow time failures on April 1 2026. Inconsistent since, heavily operator-dependent.
- **L2TP / IKEv2 / PPTP** — trivially DPI-detectable. Some Russian hosting docs still recommend them as fallback; ignore that advice.

## Orthogonal tools (not tunnels, but complementary)

- **zapret / GoodbyeDPI / ByeDPI / [[gecit]]** — client-side fragmentation and TTL manipulation (the [[tls-desync-fake-clienthello|fake-ClientHello desync]] family). Don't give you a foreign exit; just help you reach blocked resources directly by splitting or desyncing the TLS ClientHello so TSPU's SNI matcher loses the pattern. zapret/GoodbyeDPI/ByeDPI use NFQUEUE/WinDivert; gecit uses [[ebpf-sock-ops|eBPF sock_ops]] on Linux for an in-kernel implementation. Active development, effective for YouTube and similar on many operators. Standard companion to any real tunnel.
- **Cascade / multihop through RU VPS** — pattern-agnostic. Russian VPS on a whitelisted network as first hop, real foreign exit as second hop. Works with any tunnel protocol.

## Hosting selection

In 2023-2024, you picked a hoster on price and latency. In 2026 the two questions that dominate everything else are: **does this hoster's CIDR survive the TSPU whitelist**, and **does the hoster cooperate with RKN takedown notices**. Everything else is secondary.

### Tier 1 — Community-recommended

- **PQ.Hosting** (Moldova-based) — explicitly circumvention-friendly, 25+ country menu, doesn't respond to RKN requests. The default pick on ntc.party; because it's popular among RU users, its subnets do get poked at, but support rotates quickly when a block lands.
- **4vps.su** — small, RU-speaking support, VPN-specific reputation. Referenced in AntiZapret-VPN's deployment docs as a tested option.
- **justhost.asia** — cheap, good for test servers and second exits. Shared IPs on low-tier plans are often pre-burned; dedicated-IP upgrades are clean.
- **ishosting** — 40+ country footprint, VPN-tolerant ToS, not the cheapest but stable. Good for unusual geographies (SE Asia, LatAm).
- **VDSina** — usable with protocol caveat. On February 16 2026 a WireGuard block rolled out on VDSina's Netherlands hosting based on the initial handshake, meaning the CIDR is known-targeted. Xray-stack still works there; WireGuard family doesn't.
- **waicore, senko.digital, hshp.host** — smaller, less-scrutinized. The unpopularity is the advantage: lower chance of their CIDRs being on TSPU's "suspicious" list, traded against lower SLA expectations.
- **u1host** — publishes current block-status docs (their February 2026 VPN troubleshooting page is one of the better real-world references). Worth choosing just for the support quality.

### Tier 2 — Use with caution

- **Aeza** (aeza.net / aeza.ru) — on December 3 2025, Aeza began sending clients notifications about possible service termination for VPN use, reportedly tied to an RKN-provided list covering the `138.124/16` subnet. Still used on recent ntc.party setups (e.g. "aeza + Xray/Reality + masquerade as max.ru"), but with the understanding that Aeza will terminate or swap your IP under pressure. Acceptable for personal use on non-RU-resident IPs; don't rely on their Russian-address plans.
- **Timeweb Cloud, Selectel, REG.RU, Beget** — Russian companies that comply with RKN as a matter of corporate survival. Useful only as the **RU-side first hop** in a cascade, never as your foreign exit.
- **VK Cloud** — increasingly referenced specifically because it's *inside the mobile operator whitelists* — you wouldn't use it alone, but as the RU endpoint in a cascade it punches through the CIDR filter where nothing else does. See the GitHub "russia-whitelist" discussion for the VK-Cloud-as-first-hop pattern.

### Tier 3 — Avoid for new deployments

- **Hetzner, OVH, DigitalOcean, Vultr, Contabo** — their entire CIDR ranges are now TSPU-flagged. Not because the hosters are bad (they're the best on price/performance), but because reaching them from Russian mobile networks requires an intermediate node with a whitelisted IP. Home-fiber users still sometimes get through; mobile users increasingly don't.
- **Cloudflare (as origin)** — widely reported as throttled or dropped on Russian networks. Useful as an intermediate CDN in a tunnel, not as your direct endpoint.

### Selection matrix

- **Personal exit**: PQ.Hosting or 4vps.su in a less-mainstream country — Moldova, Serbia, Finland all currently beat DE/NL.
- **Cascaded setup**: RU-side on VK Cloud, Selectel, or Timeweb (small plan, cheap — it just relays); foreign exit on PQ.Hosting, ishosting, or similar.
- **Budget floor**: justhost.asia or waicore; expect to rotate IPs often.
- **Maximum stability**: ishosting or u1host with a dedicated IP in a less-targeted country (Kazakhstan, Armenia, Serbia, Turkey).
- **IPv6-only**: underused but effective. IPv6 CIDRs are filtered far less aggressively than IPv4; Hetzner/OVH IPv6-only plans can still work where their IPv4 doesn't.

### Operational posture

The community rule: **treat VPS IPs as disposable.** Budget for IP rotation (most hosters charge €1-3 for a swap, or you destroy/recreate the VM). Keep Xray/Amnezia configs in version control so respinning takes 5 minutes. Run a health check from an RU mobile connection that pings your exit every few minutes and rotates before users notice.

One thing specifically not to do: **don't bring up WireGuard/OpenVPN/Shadowsocks first on a brand-new IP.** Those handshakes get caught immediately and burn the new address. Start any fresh IP with VLESS+Reality+XHTTP or AmneziaWG 2.0, which have much lower first-impression detection.

## Practical recommendations

**If setting up fresh in April 2026:**

Primary: **Xray latest + VLESS + Reality + XHTTP + steal-oneself** on your own domain, IPv6-first, VPS on a CIDR that isn't in [[tspu|TSPU]]'s tar pit (smaller EU/Asian providers, IPv6-only endpoints hold up better than Hetzner/OVH/DO). Client apps: v2RayTun, Hiddify, or [[karing]] for cross-platform.

Non-VLESS primary: **AmneziaWG 2.0** for general use + **Hysteria2** for home connections where UDP still flows. **Trojan-TLS** or **NaiveProxy** as fallback when mobile UDP gets squeezed. Layer **zapret/ByeDPI** on top for direct access to blocked sites without routing everything through a tunnel.

**Endpoint reliability > protocol choice.** If your exit IP is on a Russian-whitelisted CIDR and your SNI is on the state-approved list, a mediocre protocol works. If your IP is on OVH's most notorious subnet, even the best protocol dies. [[vpn-configs-for-russia]] is the public data source tracking which CIDR/SNI combinations currently survive.

## Related

- [[whitelist-internet-blocking]] — the concept page explaining the default-deny regime this analysis responds to
- [[vpn-configs-for-russia]] — the live tracker of working CIDR/SNI combinations
- [[russia-v2ray-rules-dat]] — companion geoip/geosite rule files for client-side routing
- [[tspu]] — the Russian DPI/filtering system enforcing these blocks
- [[vless-subscription-format]] — wire format for the VLESS subscriptions referenced throughout
- [[karing]] — recommended client for the XHTTP-era VLESS stack
- [[amneziawg-architect]] — generator for the AWG 1.0/1.5/2.0 obfuscation parameter sets, for the AmneziaWG half of the Tier 1 list
- [[domain-fronting]] — the cousin technique used elsewhere (Iran); note the Russian context is different enough that classic domain fronting plays a smaller role
