We saw that (at least as of 8 PM UTC) outbound connections to HTTP servers wasn't really a problem. A fresh ec2 box with a basic web server wasn't effected.
So, early yesterday I set up an OpenVPN server on ec2 (eu-west-1) to try to get some slow but functional internet access. What we saw was that about 15-30 seconds after the TLS handshake the connection would stall and drop out. To me this says they're doing some deep packet inspection to find TLS and dropping those firewall states. I also noticed while running `tcpdump` that almost every tcp segment from a BY address had incorrect CRC's after the IDS kicked in.
Tonight we're going to try using an xor tcp proxy to obfuscate the VPN traffic. The system we're using has a name, but I'm not going to say it to risk KGB (yes it's still called that there) creating IDS signatures and killing our VPN. I'm sure that after a few hours it will start dropping these connections as well, but if we can buy some time that's worth while.
This, really, is the real problem with the internet. In many small countries there's only one IX, often under government ownership or supervision. You might think that they know better than to do stuff like this, but push comes to shove they'll all lock it down as soon as there's a threat to their authority.