geedge.lantern.io
detection confidence: high public

A known Psiphon3 relay IP, already in the signature set, wasn't blocked because it used destination port 179 (BGP): TSG's switch/distribution board bypassed port-179 traffic without forwarding it to the compute board for inspection at all (confirmed at the E21/Ethiopia site). A separate domain-whitelist mechanism can also override deny actions. Fixed by routing port-179 to compute.

5.157.60.60的链接目的port=179,所以未产生效果...端口179(BGP)的流量在交换版bypass,未回流到计算版

Defense implications

censorset
productstsg
capabilitydpi-signature

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-ompub704-psiphon3-port179-bgp-bypass

Related findings

evaluation

Ethiopia (E21) customer specifically tested Melon VPN and Ultrasurf against TSG; Ultrasurf's frequently-rotating IPs required an updated signature (successfully blocked after update), while Melon VPN's connection succeeded but was non-functional for other reasons (not attributed to TSG blocking).

deployment

A customer technical Q&A document specifies capacity requirements for a front-end traffic-shunting device sitting ahead of TSG: rule capacity above 10,000 masked/wildcard rules and above 1,000,000 exact-match rules, distributed across multiple X86 boards by rule-category (>16 categories), a rule-load speed above 100,000 rules/second, and sub-1ms rule-effective time, supporting IP/port-based drop, forward, mirror, and loopback actions on innermost addresses under nested MPLS/VLAN/IPv4-v6 encapsulation.

export/sales

Ethiopia customer (E21/E-site) explicitly requested TSG blocking be extended beyond the baseline (Psiphon 3) to a named list of commercial VPNs: Freegate, CyberGhost, Torguard, NordVPN, IPVanish, VPN Unlimited, ExpressVPN, Surfshark, Windscribe, Hotspot Shield, Ivacy, Atlas VPN, PureVPN, ProtonVPN, Norton Secure VPN. Engineering confirmed delivery of NordVPN and Hotspot Shield signatures with successful field tests.

defense

Multi-week TSG engineering investigation of iTOP VPN (requested by an Ethiopia deployment, cross-tested in a Myanmar environment) found blocking only takes effect for VPN sessions established AFTER a detection policy is pushed; a VPN already connected before the policy loads is never blocked or logged, regardless of signature type (SNI or server-IP).

detection

Geedge extracted and analyzed Betternet VPN's underlying protocols (WireGuard, a proprietary "Hydra" protocol using spoofed-domain TLS 1.2, and IKEv2), and found the Hydra protocol could be "completely blocked" via JA3 TLS fingerprinting; IKEv2 was blocked via UDP port 500/4500 policy, and thousands of VPN server IPs were extracted as a supplementary IP blocklist.

evaluation

On the E21 (Ethiopia/Safaricom) deployment, TSG blocked Psiphon3 via ~1.69M known server IPs; in one ~3.5hr window, 76,496 unique client IPs still attempted Psiphon3, which accounted for 14% of total bandwidth, 5.96% of sessions, and 1.32% of unique client IPs despite the active Deny policy.