
Roskomnadzor recommended to providers in restricting access to prohibited sites not to try to independently calculate the IP addresses of blocked resources. This was reported on the website of the department.
Providers must filter traffic through DPI equipment (Deep Packet Inspection, deep traffic filtering). This will allow you to block the domain of the prohibited site, and not its IP address.
“In other cases, restrictions on access by operators are carried out in accordance with unloading from the Unified Register of Prohibited Information,” the report said. “It is recommended to limit access to all DNS servers to restrict access to the domestic one by using other software, hardware or software and software.”
In addition, communication operators are recommended to receive and process unloading from the registry at least twice a day.
Also, providers who do not have DPI equipment are allowed to conclude agreements with higher operators on the receipt of already filtered traffic. "The decisions to bring the operator to administrative responsibility in case of non -existent blocking of unlawful information will be taken taking into account the terms of the contracts," Roskomnadzor said.
All these measures are introduced by Roskomnadzor to eliminate vulnerability in the blocking system. In early June, Russian Internet activists posted instructions into open access, which allows you to make any site inaccessible to a significant part of Russian providers.
Vulnerability leads to a site blocking from those providers who limit access to a domain name. Among the blocked domains, many are no longer used. In the instructions, it was proposed to buy free domain names from the registry and connect them with the IP addresses of those resources that need to be blocked.
The instructions that took place began to block the addresses of popular Internet services and state bodies, including Roskomnadzor itself. On June 9, the vulnerability led to a large failure in the work of Russian banks : about 100 technical addresses of the 3DSecure system used to authorize payments were blocked, as a result of which their payment terminals stopped working for a while.
The next day, Roskomnadzor asked the providers to temporarily not block DNS sites .
To rectify the situation, Roskomnadzor compiled and sent a “white list” from more than 2000 domain masks and IP addresses of popular resources that cannot be blocked. The list includes such masks as *.yandex.ru, *.Facebook.com, *.vk.com, *.google. *, *.Twitter.com, *.youtube.com, *.instagram.com. However, this can lead to the reverse situation: any site containing a mask of this type in the address will not be possible to block the decision of the department.
In the organization of unreasonable blocks, Roskomnadzoraccused the employees of the Fund for the fight against corruption of Alexei Navalny Alexander Litreev and Vladislav Zdolnikov. In response, FBK activists themselves complained to the TFR on Roskomnadzor and the Ministry of Communications.