As it so happens, I've spent the last day trying to break in through the
technical restrictions of a regime from the outside. There is a country
with a very oppressive government that prevents outsiders from observing
them. It's a tiny island monarchy that doesn't matter much in the grand
scheme of things, but you may have heard of them; it's called the
"United Kingdom" or "Great Britain" or whatever.
If you don't live within their control, they don't want you to see the
propaganda they put out on their "British Broadcasting Corporation"
(BBC) television stations and web site. Needless to say, there are ways
around their entirely pointless technical restrictions.
(Note_To_Self: As somewhat dyslectic person, I'll never forgive patio11
for nick-naming his product "BCC").
I would like to say that by-passing government sanctioned Internet
restrictions is simple and easy, but it's not true. Doing it safely can
be impossible at times, and considering the rather severe punishments
for getting caught (i.e. death), it may not be the smartest choice you
could make. If you want to take your chances, there are often
technically possible ways to by-pass the restrictions. It's not easy,
and it may not be entirely safe, but usually, it is technically
possible.
There are free solutions out there like Tor ("The Onion Router"
https://www.torproject.org/), but they mostly suck. If you don't believe
me, then just try using them. The other problem with the free solutions
is a lot of government filtering knows about them and adjusts
accordingly (when possible). There is also a lot of monitoring an
profiling done on the traffic on the free solutions like Tor since the
traffic is interesting.
If you need a solution that sucks less, you'll need to pay for it. As
much as many would like to believe otherwise, bandwidth and servers are
not free, so when a service is unable to support itself through
advertising, then you'll need to pay for it. The commercial VPN vendors
are more reliable and have far better security, privacy and performance
than the free alternatives.
I've been a paying customer of https://www.tunnelr.com for over a year,
and really enjoy their service. I'm on friendly terms through email with
the two founders, Daniel and Jared, so I'm probably guilty of some sock
puppetry or fanboyism. They also run the "devio.us" free shell provider
service which is very impressive.
The thing to realize is the people responsible for controlling the
network you are on and enforcing the restrictions probably have a way
out of their own. It could be that their "day job" gives them access to
the "other" side of their censorship filters, or possibly they've left a
few holes here and there that they can use to by-pass their own
filtering system. If the latter, it's probably done with a VPN of some
sort.
In the case of a good commercial service like tunnelr.com, you don't
need to worry too much about figuring out where things were left open.
Typically, if UDP traffic is found going to port 53, most people expect
it to be DNS lookups from client systems. Again typically, if TCP
traffic is going to port 53, most people expect it to be DNS lookups
done by DNS servers. Of course, if you see TCP traffic going to port 80,
you'd expect it to be going to a web server...
The common expectations are not "wrong" in most situations, but these
expectations can be wrong if things are configured differently.
In the case of good VPN services, things are configured differently!
For example, I can use TCP and connect to port 80 but establish a SSH
connection, or use UDP and connect to port 53 but establish an OpenVPN
connection.
This kind of trickery will not fool filters with the capacity to do
"Deep Packet Inspection" ("DPI" e.g. protocol profiling), but the vast
majority of filtering tech out there can't do deep packet inspection all
of the time. It requires too much computation to be effective on fully
saturated links, so it slows things down terribly. There are a few
products out there that can do DPI at "wire-line" speeds, but they are
hellishly expensive and fairly difficult to manage properly.
BTW, if you go the SSH route, check out dsocks by Dug Song. It runs on
most UNIX systems, on MacOS, and on MS-Windows through cygwin.
EDIT: I totally forgot about countless the payment options you have
available in Iran (i.e. none). If that's an issue for you, contact me
privately (email address is in my HN profile).