Skip to content

Iran-accessible endpoint: provider archaeology

VPS Hosting by beto60 4 replies 174 views
4 #1

I need to make a server that my friend in Iran can reach. Not for anything bad, just to talk and share files. The filtering there is very strong now.

I try three providers already:
- Vultr: blocked after 2 days
- GreenCloudVPS: never worked, maybe IP range known
- Leaseweb: worked 1 week, then RST packets

I know some providers have better routes than others. Maybe different upstream? Maybe not in same blacklist? I used https://bgp.he.net to check but hard to say.

I ask the community: which VPS provider you know with working route to Iran in 2025? I can pay with crypto if needed, no problem.

Also I am curious: how to test without being in Iran? I try online proxy checkers but they are not same as real connection.

Nossa, this is harder than I thought kkkk

#2

I am not in iran but I have friend there too. I try the Hetzner and it work for him but that was 3 month ago. Maybe not now?

I use the ping from tehran proxy I found online. Is that good test? Sorry if dumb question.

Also what is RST packet? I see that in my log sometimes too.

4 #3

The hosting at HostHatch, I have one client in Tehran since 2024. Voilà, still working.

The trick is not the provider but the upstream. HostHatch use tier-2 with path through Hong Kong, not direct. The heavy filtering, it look at direct routes first.

For test without being in Iran, I use the looking glass from host in region. Not perfect but better than proxy checker.

Also: change SSH port. The automated scan, they come fast when connection work.

Voilà, good luck.

#4

They don't make them like that anymore—simple Squid on Debian Lenny, no encryption even, and it worked for years because nobody looked.

Now the DPI is everywhere. I had a KnownHost instance in 2022 that worked for Iran access for 8 months. Same datacenter, new IP in 2024, blocked in hours. They fingerprint the traffic now, not just the endpoint.

My advice: don't use standard WireGuard port (https://www.wireguard.com). Don't use standard SSH. Back in 2009 we changed ports and that was enough. Now you need obfuscation too, but the principle holds: don't look like the thing they expect.

They don't make the internet like that anymore either.

SPARCstation 20, still serving HTTP
9 #5

I have the Friend in The Iran too. How to say... the Connection he is «difficult».

I try The Time4VPS and The Route he is good but The IP he is in The List after 5 Days.

The CloudCone he is better, 2 Months now. The Upstream he is «mix», how to say, the Asian carriers.

Oui, I agree with The Franck: the Port change is necessary. Also I use The Shadowsocks before The Wireguard, how to say, the «layer».

One Warning: I find The Provider called «RackNerd» in old Forum Post. The Domain he is «racknerd.com» not «racknerd.com». The first one he is Honeypot, I think. The SSL Certificate he is strange and The WHOIS he is privacy but not same as Real RackNerd.

Be careful. The Community here he is good for check.

Voilà.

prix fixe infrastructure: €5/mo

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft