The GFW is extremely sophisticated in what it blocks and how it blocks it. I have seen it block otherwise random traffic based on packet sizes, packet patterns, stream concurrency, stream duration. It will allow connections, then probe the remote endpoint and disconnect if the probe detects banned services. It will track relationships between endpoints (e.g. blocking one resulting in traffic to another). Traffic that looks off /looks off/ and the GFW will block it -- and looking off may not be the kind of encryption or protocol, but simply how many people are using it from where and for how long.
The toughest part about working around the GFW is its consistency. Its effectiveness can vary by hour, day, political wind, etc. It can vary by what network you are on or the route your traffic takes to leave the country. The GFW isn't perfect, but it is just good enough that you give up trying.
And then every once in a while you get a news report about some VPN user getting arrested, so you get that level of paranoia, too.
There is of course times like when the Two Sessions are in order and nothing worked.
Do you work for / are affiliated with Windscribe?
I made this while in China: https://www.reddit.com/r/shanghai/comments/pp39xi/the_2021_c...
Was based there 4 years so got very familiar with the VPN scene over there so if you have any questions let me know! I found for gaming for example you can't beat local VPNs for latency. No western operation can compete with that.
What does that mean? You installed a proxy/vpn server at someone's house in the US and GFW didn't block it?
~1-2 years ago: yes Currently: I don't know.
I worked for a web company and we were getting reports that our websites looked wrong/bad/messed up from within China.
So we needed an IP within China to confirm.
1st attempt: SOCKS proxy = worked, and confirmed that GFW or something was screwing up our content. (simple SSH tunnel)
2nd attempt: Wireguard = could not establish a connection to wireguard server hosted on same ISP/co-lo in China as the socks proxy.
3rd attempt: Windows RDS = worked
We ended up using RDS as that was easier for our testers to use. (despite the training I offered)
It doesn’t. At least on few tests I did