From time to time we get a customer who calls up to order a connection specifically for a VPN. They know exactly what they need. They won't listen. I try to steer them to a less expensive package that is perfectly adequate for a VPN. They'll have none of it. They want a bunch of special add-ons because they have done this all before with other ISPs and they know the ropes. They have no idea how a VPN even works, and they've never even heard of our company before, but they know exactly what they want.
I try to politely point out that I could help them save money and still guarnantee it will work without problems. But I won't argue with the customer. If they want to pay 5x for a bunch of custom stuff they don't need, I can do that.
In the end, they are very happy. They have outsmarted the greedy, conniving ISP, and got themselves a rock-solid service. I make a mental note to try to find a local contact for them with whom we can build a relationship of trust and perhaps persuade down the road that they could actually pay less without compromising their service.
This is not always the case, but it is the most common case.
So when a customer demands a dedicated static IP address, I wonder if they really need that. We charge extra for that because we have a limited pool of public IPv4 addresses. We can do it, but it is usually unnecessary, and better to avoid unless you really need it.
I'd assume they're restricting access further by only allowing certain ips thru a firewall in front of the VPN server, or requiring extra auth factors from unknown ips, or something.
There are other valid reasons for restricting the IP. I ask about those. I'm not arguing with the customer. I'm trying to be helpful.
Unless the customer doesn't want help.
When you have a corporate IT rep who is clueless about the options, they are not in a great position to build the optimal solution.
When you have an ISP rep who is clueless about the requirements, they are not in a great position to build the optimal solution.
When you have an ISP rep who is not willing to explain the options, you have a problem. When you have a corporate IT rep who doesn't know the requirements, is unwilling to explain the requirements, or is unwilling to learn about the options, you are unlikely to achieve the optimal solution.
When you have a helpful and capable ISP rep and a cooperative and capable IT rep, the world is a brighter place. But some levels of trust require either naivety or time and shared experiences. That's difficult when every contact between the customer and the ISP involve different people each time.
So, again, just like everything else, try to work with as small and local of an entity as possible to get the job done. This is true for government, auto dealers, ISPs, or anything else. Only scale up when there is an advantage to doing so.
It's twice the money for half the bandwidth, but I have enough bandwidth and I sleep better at night. Shouldn't be necessary, but . . .
This is a goldmine for ISPs. Over the last five-ish years they decided to think of themselves as "advertising" companies. FCC repealed the internet privacy rule last April, and what are they doing now? They're functioning as data brokers. We should expect this trend to continue and assume that ISPs will take advantage of Pai's NN repeal as soon as possible.
Comcast currently extracts almost $100 a month from me, in addition to the ~$10 I pay for a VPN exit node to hide traffic from their surveillance machine. Why wouldn't they want another $10 or so to "allow" VPNs, given regulators who are loudly, publicly giddy about screwing consumers?
It's a 15 minutes task for good admin to start dropping VPN connections (not to block, but to interrupt every 5 minutes, but blocking is even easier).
One important info: - ISP can't see your VPN traffic. But they can see that you are connecting to specific IP (VPN service's IP) at specific port. Once you're connected to VPN you probably pass ALL the connection through it. So ISP can see only single connection to single point. That is more than enough.
So how can they block VPNs: 1) Most VPNs uses standard VPN ports. Just dropping connections to that port is a good start. 2) Dropping connections to a servers when this is your (almost) only, long standing connection. This is a good moment to store that IP as VPN service IP. 3) Reverse DNS on IPs you're connecting to. A lot of services will reveal that they belongs to VPN services. 4) Public list of VPN IPs. Some provides them. Some are already noted somewhere on the internet.
ISPs can even share their databases with each other to be better at VPN dropping.
This is very easy thing to do.
It would be REALLY hard to hide your connection to a VPN service. One thing that came to my mind, to hide your VPN servers you would have to: - use VPN services at random ports - change VPN IP every few minutes at random factor, so dropped connections will occur anyway - in the background you should keep direct (un-VPNed) connections to random servers at random ports, passing random data around (it will look encrypted just like VPN connection)
This would require huge infrastructure though. Really huge.
But still - if ISP notice behavior like that - it means you're probably trying to do something shady, like walk around their VPN dropping rules - so they could just throttle your connections even more, just in case :)
So in general - you're fu^Hat very bad situation. I'm from Europe. I'm "safe" now, but we are also going to have bad law for net neutrality soon.
I think the most efficient way to hide your service would be to tunnel it over HTTPS given that it's not really realistic to drop that when you're an ISP. Still, a relatively simple traffic analysis tool won't have too much difficulty differentiating between proper web browsing and something fishy over HTTPS even it it just looks at the shape of the traffic.