The first casualties of the “protocol-based” blocking were VPN services. In early August and late September, VPNs were massively blocked in Russia using “protocol-based” techniques, made possible by deep packet inspection (DPI). Previously, when Russian users experienced disruptions in their VPN applications, it was usually due to the blocking of specific IP addresses used by the services. One way to bypass those “dumb” blockings was to constantly change the IP addresses the service connected to, a tactic successfully employed by Proton, Red Shield, and other applications, allowing them to resume functioning. Some VPN services, typically less popular and not in the focus of Roskomnadzor, continued to operate uninterrupted. However, in April and June 2023, MegaFon and MTS reportedly attempted to block the most popular protocols — methods of data transmission between users' computers and VPN servers — specifically OpenVPN and WireGuard. In early August, operators suddenly began blocking all traffic going through VPN applications, causing most applications to stop working for users in Russia.
After a few days, the services partially restored their functionality, and the blockings ceased. However, at the end of September, they resumed. Experts believe this was an unprecedented move by Roskomnadzor. “We were living carefree. It wasn't a digital war, but a spreading of mucus on the walls with a crutch. And now, it's war!” wrote Filipp Kulin, who runs the Usher II project for monitoring blockings, in his blog.
Roskomnadzor blocks internet access via VPN protocols in the following manner: traffic filtering equipment is installed on operators' networks, officially referred to as “technical means to counter threats” (TSPU, from Russian «техническое средство противодействия угрозам»). Roskomnadzor directly oversees and controls this equipment. When a decision is made to block something, such as one or more VPN protocols, a command is sent to the device by specialists from Roskomnadzor's subsidiary organization, the Federal State Unitary Enterprise GRChTs, and the blocking occurs. The operator is not directly involved in this process.
During the August blockage, consideration was given to the fact that VPN protocols route traffic to foreign servers – no domestic networks were blocked. For instance, users of the VPN Generator project experienced a loss of approximately 10% of their traffic during the protocol-based blockage — connections to foreign proxy servers simply couldn't be established. VPN Generator uses the WireGuard protocol, but the blocking affected all popular protocols. Commercial services like Trust.Zone and PaperVPN told The Insider that they only lost a small portion of their traffic due to their ability to provide connections through various protocols and use other technical solutions to bypass Roskomnadzor's prohibitions.
According to VPN Generator's customer support, the blockages barely affected home internet users, primarily impacting mobile operators' customers. This implies that Roskomnadzor has not yet implemented TSPUs across all telecommunication operators' networks; the focus has been on mobile operators. The reason is that it's technically easier to achieve; besides, mobile operators have a larger subscriber base.
To block all protocol-based VPNs altogether, a significant amount of computational resources is required, which Roskomnadzor currently lacks. When the internet is being filtered, each packet's protocol and destination address are checked. However, a blanket approach cannot be employed, as VPNs are widely used in Russia for remote connections of offices, ATMs, point of sale terminals, corporate networks, and electricity meters. If traffic is blocked across all protocols, all these services will stop functioning, making it impossible for people to make purchases in stores or withdraw cash from ATMs.