The new IP is no longer saving. VPN locks in Russia have moved to the next level

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
464
Reaction score
738
Deposit
0$
On August 31, a new mass wave of VPN failures began in Russia, in which operators faced the inaccessibility of entire groups of servers and the rapid shutdown of backup addresses. Users in different regions complained about connection breaks, huge ping and situations when recently working configurations stopped connecting. According to VPN providers themselves, the new wave differs from the usual point blocking of individual IPs and increasingly affects entire network ranges.

A similar mechanism appeared on August 4, when the mass blocking simultaneously affected several independent commercial VPNs. Then the operators associated failures with the restriction of IP addresses and whole subnets of large foreign hosting. August events have shown that for a massive disruption of VPNs, it is no longer necessary to recognize each service or protocol separately.

One of the affected operators reported that on 31 August almost simultaneously lost the main servers, after which it began to transfer traffic to the backup infrastructure. According to the team, the reserve provided only part of the usual capacity, and later also was blocked. By the morning of September 1, the service came to the conclusion that the new IP bands could remain available for only a few hours. Independent measurements that would confirm the same rate of blocking for the entire industry are not yet available, so we are talking primarily about the observations of the operators themselves.

The rental of one subnet used by the service is estimated at about $100. If the new range really has to be changed every two hours, the cost of such a rotation alone can reach $1200 per day, $8400 per week and approximately $36,000 per month. The calculation refers to the infrastructure of a particular VPN and does not describe the economy of the entire industry, but it shows well why the endless replacement of IP quickly stops working as a strategy.


The problems were independently confirmed by another service. During the new wave of restrictions, the service temporarily lost most of the locations, after which it restored the servers and charged the users two additional weeks of subscription. VPN services already massively raise prices for new customers and associate the solution with blocking.

The main change concerns the scale of filtering. Each server has an IP address, however, hosting and operators get the address space in blocks. For example, the standard IPv4- subnet /24 contains 256 addresses. If you restrict one IP, the VPN operator can transfer the server to the neighboring one. If the filtering falls all /24, one rule can be made inaccessible at once by hundreds of addresses.

Blocking the range is especially painful for a VPN, which keeps many servers from one hosting provider. The team has to search for a new pool of addresses, negotiate with the platform, configure routing and servers, and then transfer new configurations to client applications. If the next range falls under restrictions after a few hours, the usual IP rotation turns into an expensive race.

The Russian system is technically capable of filtering traffic much deeper than a simple IP check. On the networks of operators there are TSPU, technical means of counteraction to threats, which allow to limit connections on domains, addresses and network features. Deep filtering systems can analyze connection characteristics without decrypting the transmitted content, including protocol features, packet sequence, and other metadata.

The filtering of protocols is gradually increasing. In December 2025, SOCKS5, VLESS and L2TP began to fall under restrictions. In January, users reported VPN problems that tried to work through permitted Russian IP, after which SecurityLab disassembled the identification of VPNs masquerading as legal services. By February Roskomnadzor stated that limited access to 469 VPN services.

In parallel, the state expands the technical infrastructure of filtration. In May, Roskomnadzor's documents showed plans to increase the internal efficiency of the VPN's coverage by 2030 to 92%92%. In June, the structure associated with the introduction of sovereign Runet equipment began the purchase of 154 servers worth 1.31 billion rubles. Roskomnadzor also plans to use machine learning to analyze traffic and search for means of bypassing locks.

With the events of August 31, another change in infrastructure policy coincided. The Ministry of Figures asked hosting, CDN and protection services to allocate resources from the state white list to separate subnets. Now the permitted site can share the IP range with other hosting clients, including VPN. The separation of the infrastructure should remove the situation when, together with the permitted resource, access is retained by neighboring services. There is no public evidence of direct connection of such a requirement with the wave of locks on 31 August.

The Ministry of Finance has taken steps before against the infrastructure, which helps VPN hide among ordinary resources. On August 3, it became known about plans to quickly identify and disable the hidden VPN infrastructure from hosting providers. The March requirements for Russian digital platforms also linked the persistence of presence in white lists with restriction of access through VPN.

The blocking of entire network ranges has a side effect. One subnet may have completely unrelated sites and services, so infrastructure filtering can affect conventional web resources, cloud applications and developer tools. Such consequences have already manifested themselves in Russia when IP-band restrictions violated access to Linux-repositories and other foreign technical resources. In the summer, Russian IT companies also complained that the fight against VPNs complicates work with international repositories, libraries and cloud environments

The situation on August 31 does not mean the technical disappearance of VPN from the Russian Internet. Enterprise networks, remote access by employees and many legal systems use tunneling and encrypted connections, so total filtering inevitably creates the risk of side blockages. But the old model, in which the service after another restriction simply gave users a new IP, is becoming less viable. VPN providers have to distribute infrastructure among a large number of networks, change architecture, and look for ways to reduce reliance on fast-blocking address pools.

Mass failures at the same time create a convenient moment for swindlers. The user, who suddenly stopped connecting the usual VPN, more often begins to look for an urgent free replacement. In August, researchers found 737 fake VPN extensions targeting predominantly Russian-speaking audiences. On the same day, it became known about the free VPN manager FirewallFalcon Manager, which turned out to be a backdoor and was associated with more than 650 control servers. The new wave of blockages makes such baits especially dangerous, since the demand for a fast-paced alternative grows sharply during mass failures.
 
Top Bottom